Claude Code Mods let developers rewrite the coding agent from inside
By EnkiEdited by VK, Editor
Published
Reporting from The Decoder

Anthropic's new Mods run JavaScript or TypeScript inside Claude Code to add panes and commands, rewrite prompts, and approve or block tool calls. They are powerful and, by Anthropic's own docs, not sandboxed.
What it means for founders
- Claude Code is becoming a platform. If you build developer tools, a mod can put your product directly in the agent's loop, from deploy status panes to test runners, with distribution through plugin marketplaces.
- Treat third party mods like browser extensions with root access. Before your team installs one, read its code, check what `claude plugin validate` reports, and prefer mods your admins have approved.
- Governance is the opening for teams. Mods that log every tool call, gate production changes or redact secrets are exactly what security teams ask for before approving AI coding agents.
- Watch whether Anthropic adds review or signing to its directory. If it does, an early, trusted mod could become a durable channel; if not, expect the first malicious mod story to shape how companies allow them.
The story
Anthropic has opened up Claude Code's internals. Mods, which shipped on October 1 in Claude Code version 2.1.287, are small JavaScript or TypeScript plugins that run inside the coding agent itself and can change almost anything it does, from what appears on screen to which tool calls are allowed to run.
What a mod can do
A mod registers handlers for events such as a tool call, a submitted prompt, a request to the model or a piece of the interface being drawn. Each handler can let the event through, change it and pass it on, or take it over entirely so the default behaviour never runs. Handlers chain together, much like middleware in a web server.
In practice that means a mod can add a live pane beside the conversation or a band above the prompt, restyle the spinner or tool rows, add slash commands that run instantly even while Claude is working, rewrite prompts or add hidden context, route a request to a different model, and block, rewrite or retry tool calls. Mods can also approve or deny permission requests, though they cannot change the permission prompt itself. Developers can write a mod by hand or ask Claude to write one with a built in authoring skill.
Anthropic has started moving its own features into mods, including the diff view and AGENTS.md loading, and says it wants Claude Code to shrink toward a small core that users assemble. Sample mods show the range: one forecasts how full the context window is, one holds risky commands such as force pushes and destructive deletes for review, and one replays the last turn's file edits.
Mods work fully in the terminal and the desktop app. In the VS Code chat panel, headless runs and cloud sessions their logic runs but nothing is drawn. They install like any Claude Code plugin, from GitHub marketplaces or Anthropic's directory.
The security trade
Anthropic's documentation is direct about the risk: "Mods aren't sandboxed." A mod runs with the user's own permissions, can read files and environment variables including API keys, can start processes and make network calls, sees every prompt and tool call, and can approve actions before the user is asked. Turning on Claude Code's sandbox isolates only the shell commands Claude runs, not what a mod starts. On Team and Enterprise plans a built in guard loads first and blocks moves such as overriding permission denials, and admins can deploy approved mods across a company.
What we don't know yet
Anthropic has not said whether mods listed in its directory will be reviewed, when drawing will reach VS Code or cloud sessions, or which built in features move to mods next. No pricing or plan limits were announced, though mods that call models spend the user's own usage.
Sources
Enki Daily
Get stories like this every weekday morning.
The day's AI stories for founders, each with what it means for your company. Free.
Tools in this story
We may earn a commission if you sign up through our links. It never affects our ratings or which stories we cover.
Anthropic's coding agent, from terminal to IDE to browser
Anthropic's assistant for writing, analysis, and code
More in Products & Launches
- Capcom plans to rebuild its RE Engine around AI over several years

For founders: Large studios are buying AI for the pipeline, not the pixels.
The Verge · 17h ago - Suno launches Speech, generating voiceovers and background music together

For founders: If you produce podcasts, app onboarding audio, meditation content or ads, Speech is a cheap way to prototype a narrated track with a score in one pass.
The Verge · 2d ago - Meta open sources firmware and an SDK so anyone can build Muse gadgets

For founders: Hardware startups get a free agent with Meta's distribution behind it to build on.
TechCrunch · 1d ago - OpenAI launches Dots, always-on agents for ChatGPT Pro and business plans

For founders: Budget for usage, not seats. The chat is included, but anything a dot builds in Codex draws on the same limits your team already spends, so a busy dot can…
TechCrunch · 4d ago - OpenAI adds Codex cloud environments, a Decisions API and an Ultrafast tier

For founders: Speed is now a line item. Ultrafast turns latency into something you buy per token at a steep premium, so reserve it for user facing paths where waiting loses…
TechCrunch · 4d ago