Anthropic Launches Claude Code Mods for Custom Agent Workflows
Claude Code mods are now available as TypeScript extensions that can change how Anthropic’s coding agent behaves and what its interface displays. Anthropic launched the system on October 1 for the Claude Code command-line interface and desktop app, giving developers control over events inside an active coding session.
The flexibility goes beyond ordinary settings or shell hooks. A mod can rewrite a prompt, intercept a tool call, approve or deny a permission request, replace a built-in feature or draw a new pane. Anthropic also warns that installed mods inherit Claude Code’s access to the user’s machine.
The launch establishes four practical facts:
- Mods are JavaScript or TypeScript functions packaged as plugins.
- They can observe, rewrite or replace Claude Code events.
- Claude Code 2.1.287 or later enables the system by default.
- Users should install mods only from trusted publishers.
Anthropic Launches Claude Code Mods
Claude Code already supports settings, permission rules, slash commands, skills and conventional hooks. Mods add a deeper extension layer: they remain loaded for the session, keep state, call back into Claude Code and render interface elements that update as the agent works.
A mod ships inside the same plugin structure developers already use. Its manifest identifies the package, a hooks file names the module, and the module registers functions for selected events. Distribution follows the plugin system, including organization marketplaces and Anthropic’s Claude directory.
Anthropic says developers can write a mod directly or ask Claude Code to generate one. Hot reloading allows a session to adopt code changes without a full restart, shortening the loop between describing a workflow, testing it and refining how the extension behaves.
Function Hooks Can Rewrite Claude Code Events
Claude Code emits events when it receives a prompt, calls a tool, requests permission, starts or completes a turn and draws its interface. A mod registers a handler before, after, instead of or around that event, creating a middleware chain between the user’s request and Claude Code’s default behavior.
A handler can take three basic approaches:
- Observe an event and record what happened.
- Rewrite the event before passing it onward.
- Return its own answer without invoking the default behavior.
Those options let a mod redact a secret before tool output reaches the model, change an unsafe shell command, block an operation or retry it under different conditions. It can also add inputs, buttons and side panes in the terminal or desktop interface.
Load order matters when several mods target the same event. The first extension loaded sees the event first and receives the final result last, so behavior can depend on how independently written modules are stacked. Teams will need a deliberate order for auditing, policy enforcement and user-interface changes.
Unsandboxed Access Creates a Plugin Supply-Chain Risk
Anthropic’s security warning is direct: mods run with the same machine access as Claude Code and are not a safe boundary against malicious code. The module interface routes files, processes, network calls and other capabilities through the mods API, but an installed publisher can still exercise the authority the host agent exposes.
That makes a mod closer to a development package than a cosmetic theme. A compromised marketplace, malicious update or lightly reviewed extension could inspect files, launch processes or influence permission decisions. Developers should review the repository and update path before installation, then restrict Claude Code’s underlying privileges.
Team and Enterprise administrators can allow or block plugin marketplaces. Managed environments also load a built-in security mod called sec-default before user-installed mods. Anthropic says it prevents extensions from overriding high-risk controls such as permission-deny rules, while administrators can load their own policy modules first.
Sec-default does not make every third-party mod trustworthy. Organizations still need provenance checks, version pinning, review of requested capabilities and monitoring for unexpected process or network activity. The most important control remains limiting what the Claude Code session can reach in the first place.
Built-In Mods Add Review and Safety Tools
Anthropic has converted some Claude Code features into mods, including its side-by-side diff pane and AGENTS.md instruction support. Publishing those implementations with tests gives developers working examples and signals that more features may move out of the core application over time.
The launch guide demonstrates Blast Radius, which pauses selected destructive shell commands and shows the files or data they could affect before presenting Proceed and Cancel controls. Anthropic cautions that it is a review aid rather than a permission system because aliases, scripts and command substitutions can evade simple text classification.
A second example, Replay Theater, records file edits during a turn and lets a developer step through the resulting diffs. Token Weather shows a simpler monitoring use: it displays how much of the context window a session has consumed and updates the indicator after every turn.
These examples frame mods as both customization and governance infrastructure. The system can make Claude Code more personal, but its larger impact may come from organization-specific review panels, production safeguards, CI status, audit logs and policy checks that sit directly inside an agent session.
Adoption will depend on whether Anthropic can grow the extension ecosystem without recreating familiar package-manager risks inside a tool that already has broad local authority. For developers, the immediate opportunity is powerful; the safe starting point is a small, auditable mod from a known source with tightly scoped host permissions.
Related Research