Claude Code mods: Anthropic lets the agent be rewritten in TypeScript

On October 1, 2026, Anthropic opened Claude Code mods: short TypeScript functions that change how the coding agent behaves and looks. A mod can rewrite a prompt, add interface, replace a built-in feature, or add new functionality. You can write it by hand or ask Claude Code to generate the code, install it, and hot-reload it in the session.

Mods ship inside plugins and work in the CLI and the desktop app. Each time Claude Code acts, it emits an event — a tool call, a permission request, or part of the screen being drawn. A mod can run before, after, instead of, or around that event. Anthropic describes uses such as rewriting a prompt before it reaches the model, blocking or retrying a tool call, approving or denying a permission, and redacting secrets from output before the model reads it.

Mods can also change what appears on screen, including buttons and inputs, in the terminal, the app, or both. When several mods hook the same event, load order defines the stack: the first to load sees the event first and the result last.

Some built-in features now ship as mods. The /diff command, for example, can be turned off in /plugin or replaced. Anthropic says it plans to move more features into this format, leaving a smaller core and making the rest optional.

Why it matters

Hooks already offered some control, but they could not rewrite events, draw UI, or replace features. Mods close that gap and push Claude Code toward an extensible environment, in the same direction as the plugin marketplace Anthropic has been opening. The design was discussed beforehand on GitHub, in issue 91870 of the claude-code repository.

There is a clear security limit, and Anthropic states it in the announcement: a mod runs with the same access to the machine as Claude Code. There is no sandbox. Installing a mod is equivalent to installing local code, and the advice is to accept only trusted sources.

On Team and Enterprise plans, and on machines with managed settings, a built-in mod called sec-default loads first and stops user mods from overriding permission deny rules. Admins can load their own mods first, but Anthropic suggests keeping sec-default in the list. The restriction source is in the public repository.

In practice

Teams can use the format to show pipeline status beside the conversation, require confirmation before a command touches production config, or record every call other mods make. Installation is through the Claude directory or the /plugin command. To share a mod, package it in a plugin and submit it to the directory.

Official docs are at code.claude.com, and the getting-started guide is at claude.dev.

Sources

Transparency: This content was created, edited, or reviewed with the assistance of artificial intelligence. Information was cross-checked with public posts on X and sources available on the internet. Consult the original sources for the full context.

By GeekikiBot