Skip to content

Anthropic launches Claude Code Mods: TypeScript hooks that reprogram the coding agent from the inside

Anthropic's new mods let developers hook Claude Code's internal events with TypeScript, rewriting prompts, intercepting tool calls and replacing built-in features.

By VibecodedThis 2 min read
Screenshot of Anthropic's ClaudeDevs announcement post introducing mods for Claude Code
Screenshot of Anthropic's ClaudeDevs announcement, via RuntimeWire

Anthropic opened up the internals of Claude Code on October 1 with a new extension type called mods: small TypeScript functions that hook into the agent's internal events and change what it does mid-session. A mod can rewrite a prompt before it reaches the model, block or retry a tool call, approve or deny a permission request, redact secrets from tool output, or replace parts of the interface with custom panes and buttons, according to the company's launch announcement.

The mechanism reaches deeper than the plugin system Anthropic introduced in October 2025, which packaged commands, subagents, MCP servers and hooks. Hooks could already react to events, but Anthropic says they could not rewrite events, draw new interface elements or replace built-in behavior. Mods run before, after or in place of an event, and when several mods hook the same event they run in load order, with the first mod to load seeing the event first and the result last.

To make the point, Anthropic moved some of its own features into the mod system. The /diff pane now ships as a mod, which users can disable or swap for their own version, and AGENTS.md project-instruction support was rebuilt the same way. The company published the source of its four built-in mods (sec-default, diff, telemetry and agents-md) in the claude-code GitHub repo. Anthropic's pitch for getting started: write a mod yourself, "or ask Claude Code to write one for you."

The sample mods in the announcement show the range. Token Weather draws a sparkline of context-window usage over the last 12 turns. Blast Radius pauses potentially destructive shell commands like rm -rf and force pushes and shows what they would hit before the user proceeds. Replay Theater records file edits during a turn so they can be stepped through later.

The catch is access. Anthropic is blunt: mods run with the same access to your machine as Claude Code itself, they are not sandboxed, and you should only install mods from sources you trust, the same way you would install any code on your computer. For organizations, Team and Enterprise plans load a built-in mod called sec-default first, intended to block risky behavior such as overriding permission denials. A second built-in mod, "You should know," adds a side agent that watches the session and flags things you or Claude might miss; it is off by default and enabled with a /plugin command for first-party sessions with telemetry on.

Mods ship inside plugins, install through the /plugin command, and work in both the CLI and the desktop app. They landed in Claude Code 2.1.287, released the same day, alongside 106 other CLI changes. Coverage of the launch notes this is Anthropic's steady drumbeat of Claude Code releases continuing into the fall, and the security posture will depend on which mod sources teams sanction before any marketplace matures.