Claude Code mods: what they are and how to use them
2026-10-02 · 4 min read
Claude Code mods are small JavaScript or TypeScript functions that run inside Claude Code and change how it behaves, what it shows on screen, or which features it has. You install one with /plugin in the terminal or the desktop app, or you describe the mod you want and Claude writes it for you.
Anthropic's developer account, @ClaudeDevs, announced the feature on October 1 with a short list: "Change how it behaves," customize the UI, and "Swap in your own features." The post had passed 3.6 million views by Friday. In a follow-up, @ClaudeDevs said the team already builds some of its own features this way, including /diff and AGENTS.md support.
What a mod actually is
Anthropic's documentation describes a mod as a plugin made of event handlers. When something happens inside Claude Code, like a tool call, a submitted prompt, or part of the screen being drawn, the mod's function runs first. It can watch the event, change it, or handle it so the normal behavior never runs.
Claude Code already had settings hooks, skills, and MCP servers, but all of those work from outside the program. A mod runs inside it. That means it can draw a pane next to the conversation, restyle the spinner, pause a tool call to ask you a question, or send one request to a different model. Anthropic's examples include a small mod that counts tool calls and shows the running total next to the spinner.
Claude Code lead @bcherny called mods "absolutely insane" and argued there's no reason everyone should get an identical Claude. Anthropic engineer @trq212 framed it bigger: "all software is becoming malleable," and Claude Code should be built for that.
How to use Claude Code mods
You need Claude Code version 2.1.287 or later, where mods are on by default. Run claude --version to check. Then pick a starting point:
- Try a sample. Anthropic's
claude-code-playgroundrepository on GitHub has three.token-weathershows a forecast of how full your context window is.blast-radiusstops a risky command likerm -rfor a force push and shows what it would change before you hit proceed.replay-theateradds a/replaycommand that walks through the edits from the last turn. - Ask Claude for one. Describe the mod in a normal session and Claude writes it, using a plugin-authoring skill that ships with Claude Code.
- Install one from a plugin marketplace:
/plugin install name@marketplaceinside a session, orclaude plugin installfrom your shell.
Run /plugin to see which mods are active. If something starts acting strangely, claude --safe-mode starts a session with every installed mod turned off.
The catch: mods aren't sandboxed
Anthropic's docs are blunt about this: "A mod is code that runs with your permissions." Once a mod loads, it can read and write any file your account can reach, start programs, and make network requests. It can also read environment variables and settings files, which includes any API key stored in them. It sees every prompt and tool call, can approve a tool call before you're asked, and can spend your plan's usage.
Turning on Claude Code's sandbox doesn't change any of that. The sandbox only isolates the Bash commands Claude itself runs, and anything a mod starts runs outside it. The one thing a mod can't touch is the permission prompt: it can't change what that prompt shows you.
There is a decent safety check, though. claude plugin validate ./some-mod lists the events a mod listens for and the API calls it makes, without running it. If a mod that only draws a status bar is asking for $.http.fetch and $.env.get, don't install it.
For companies, admins on Team and Enterprise plans get a built-in guard that runs before any user's mod. With the allowManagedModsOnly setting in managed settings, only the organization's own mods load.
My read
I like this one. AI tools usually come as a fixed product, and here you can rewrite the agent's own screen just by asking. I also appreciate that Anthropic didn't pretend these are harmless widgets. The warning is right there on the install page. And the best sample, blast-radius, is a guardrail you can watch work before anything breaks, which says a lot about what mods are good for.
What it means for your business
If a developer, contractor, or in-house tinkerer uses Claude Code on a machine that touches your customer data, add mods to the list of things you ask about. Which ones are installed, where did they come from, and does the account have keys sitting in an environment file? That same "hooks into every step" design also lets you build approval checks into AI workflows, which is usually what a small team needs before letting an agent near real work.
If you want help working out where AI agents fit in your operation and where they need a human checkpoint, New Face Design offers a free process audit for Fox Valley businesses.