Build2 publishers3 min readPublished
Claude Code mods let unsandboxed plugin code answer the agent's permission requests
Anthropic's Claude Code mods, on by default from 2.1.287, let JavaScript or TypeScript code rewrite prompts, block tool calls and approve permission requests. For teams, the governance question moves from what the agent is told to which code it runs.
The Engineer · Build desk

What happened
- Anthropic says mods are not sandboxed and get the same access to the user's machine as Claude Code itself, and it advises installing only mods from trusted sources.
- On Team and Enterprise plans and on managed machines, a built-in mod called sec-default loads first and blocks risky behaviour such as overriding permission-deny rules.
- Administrators may load their own mods ahead of sec-default, but Anthropic says they should bundle it to keep its restrictions in force.
- Team and Enterprise administrators can allow or block the plugin marketplaces through which mods are distributed.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure Every installed mod is its publisher's code running with the agent's privileges, so reviewing a plugin now means reviewing code that can approve the agent's permission requests.
- constraint Since mods run in the order they load, an organisation-wide mod placed first sits ahead of every guard, and mod ordering now needs the same change review as the permission rules.
- precedent With /diff already swappable, Claude Code's built-in features sit in the same replaceable layer as third-party code, so a team's agent can drift from the stock build one feature at a time.
A CLAUDE.md file holds persistent instructions. Settings, hooks and MCP servers could already shape those instructions, Claude's permissions and its tools [21]. None of them could change Claude Code's own features or the rest of its interface [21]. A mod is code on the event path: it runs before, after or in place of an event [10]. It stays loaded for the whole session, so it can carry state from one event to the next [12]. Anthropic says its earlier hooks could not rewrite events or draw new interface elements [11].
The API first appeared on GitHub on September 3 as a proposal for "function hooks". Six days later Anthropic said it would ship under the name Claude Mods and keep function hooks as the mechanism underneath, so the main change that week was the label [13].
Anthropic pitched the launch at individuals [14]. "Each person works differently, so there's no reason why everyone should have an identical Claude experience," Boris Cherny, who created Claude Code, wrote on X [14]. Addy Osmani, a member of Anthropic's technical staff, wrote in the launch post: "That makes mods a way to fit Claude Code to how you work." [15]
The team guard shows what the API allows. Anthropic wrote sec-default to stop mods overriding permission-deny rules [4]. That job exists only because a mod can approve or deny permission requests in the first place [10]. I think shipping the guard as a mod, inside the same system as the code it polices, is a reasonable first design.
Anthropic also says developers can ask Claude Code to write a mod, install it and reload it during a session [18]. Put that next to the permission hooks and the agent can draft the code that later answers its own permission requests [c10, c18]. The sources describe sec-default only for Team and Enterprise plans and for machines with managed settings [4].
Mods can also redact secrets from tool output [10]. A team would put its own controls in those same hooks. Anthropic's Blast Radius sample pauses rm -rf, hard Git resets and force pushes, then shows what they would affect before the user goes ahead [16]. Within hours of the launch, one developer had built a mod that passes credentials to Claude without leaving the secret in the conversation history [17]. Token Weather, about 80 lines long, reports context use as a forecast. It reaches "Storm" at 81% of a 200,000-token window, or 162,000 tokens [c19, d1].
The choice I would defend is that Anthropic builds its own features on the API. AGENTS.md support already runs as a mod, and the source for Anthropic's mod-built features is published in the Claude Code repository [9].
What to watch
- Whether Anthropic extends sec-default, or an equivalent guard, to individual plans and to machines without managed settings.
- Any move to sandbox mods or give them narrower access than Claude Code itself has.
- Which built-in features Anthropic moves into the mod layer after /diff and AGENTS.md support.