In brief

Anthropic added Claude Mods to its coding agent Claude Code in version 2.1.287 on October 1. Mods are small JavaScript or TypeScript functions, shipped in plugins, that react to events inside the agent. Anthropic’s documentation says they run with the user’s permissions and are not sandboxed.

New to this? Read it in simple words
  • Claude Code is an AI agent from Anthropic that writes and runs code.
  • Since October 1, small add-ons called mods can change how it works and looks.
  • Mods run with the user’s own permissions and are not sandboxed.
  • Anthropic says to install mods only from authors you trust.
Words to know
Plugin
An add-on package that gives a program new features.
Sandbox
A closed space where code runs without reaching the rest of the computer.
Tool call
When an AI agent asks to run an action, such as a command or a file edit.

What a mod is

A mod is a small JavaScript or TypeScript function shipped inside a plugin. Claude Code calls it when something happens, such as a tool call, a submitted prompt or a part of the screen being drawn.

A mod can rewrite a prompt before it reaches the model, block or change a tool call, or add new commands, The New Stack reports. It can also redraw parts of the interface, for example with a live panel beside the chat.

Mods are on by default in version 2.1.287 and later, Anthropic says. Some built-in features, such as the /diff panel, are already built as mods, and Anthropic has published sample mods on GitHub.

Sources1234

WHAT A MOD CAN TOUCH 01
Almost everything, except the prompt.

From Anthropic’s changelog and documentation, as quoted by The New Stack and Mixed.

The security trade-off

“A mod is code that runs with your permissions,” Anthropic’s documentation says, as Mixed reports. It can read and write files, start processes and make network requests.

Mods are not sandboxed, and the documentation says they can read secrets such as an API key kept in a settings file. Anthropic tells users to install mods only from authors they trust.

Some limits remain. A mod cannot change what the permission prompt shows, Mixed reports. On Team and Enterprise plans, a guard from Anthropic stops user-installed mods from overriding rules that deny actions, according to The New Stack.

Sources23

First uses

Anthropic’s first official mod, called You should know, runs a side agent that flags things the user or Claude might miss. It works in sessions with telemetry turned on, the changelog says.

Boris Cherny, who created Claude Code, wrote on X that users can now shape Claude “by just prompting it”. Within hours, one developer built a mod that passes secrets to Claude without leaving them in the chat history, The New Stack reports.

Sources124

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
    Primary source · October 1, 2026Claude Code changelog: version 2.1.287 Anthropic
  2. 2
  3. 3
  4. 4
How we checked this story

The features and the safety limits come from Anthropic’s own changelog and documentation, and we found no outside security test of this version. Anthropic makes the Claude models that write this site.

Mood: 6 out of 10 · Neutral

Developers get a new way to customize a coding tool now, but Anthropic itself warns that mods are not sandboxed and can read secrets. How we rate the mood