Claude Code Mods: Anthropic lets developers rewrite how its coding agent behaves

Illustration: an event pipeline with small modules hooking in before, after and around each step

Anthropic announced on 1 October a feature called Mods for Claude Code, its command-line and desktop coding agent. Mods are small TypeScript functions, shipped inside Claude Code plugins, that let developers change what the agent does and what it looks like.

What a mod can do

Mods work by hooking into events that Claude Code emits as it runs. A mod can run before an event, after it, or instead of it, and a single mod can wrap an event to run code on both sides. In practice, Anthropic says mods can:

  • rewrite a prompt before it reaches the model;
  • block, rewrite or retry a tool call;
  • approve or deny a permission request;
  • redact secrets from tool output;
  • edit or replace parts of the interface, and add buttons and inputs.

Mods are installed and shared through the same plugin system Claude Code already uses, in both the CLI and the desktop app.

Why teams will want this

Until now, shaping a coding agent’s behaviour mostly meant writing instructions and hoping the model followed them. Mods move that control into code that runs every time. A team could strip credentials from anything the agent reads, require a specific test command before any commit, refuse tool calls that touch production configuration, or add a one-click button for a house workflow. These are rules that matter precisely because a model following a prompt will sometimes not follow it.

It also turns Claude Code into something closer to a platform, in the way editors such as VS Code became platforms through extensions. Whoever builds the most useful mods will shape how a lot of developers work with the tool.

The security trade-off

Anthropic is unusually direct about the risk. Mods “run with the same access to your machine as Claude Code itself” and “aren’t sandboxed”, and the company’s advice is to “only install mods from sources you trust, the same way you’d install any code on your computer.”

That matters because a mod sits in exactly the places an attacker would want to be: between the user and the model, and on the path where permissions are granted. A malicious or compromised mod could quietly approve actions the user would have refused, or alter what the agent is told. Plugin ecosystems for editors and browsers have repeatedly been used to distribute malware, and there is no reason to think coding agents will be different.

For organisations, Anthropic has added one guard rail. On Team and Enterprise plans, a built-in mod called sec-default loads first so that user-installed mods cannot bypass security restrictions set by administrators. Individual users get no equivalent; for them, trust in the source is the whole security model.

Why it matters: coding agents are moving from tools you prompt to platforms you program. That makes them far more useful for teams with real workflows, and it means the plugin supply chain for AI agents is now a security surface worth watching.

Source: Anthropic’s announcement.


Related