Anthropic introduced mods on October 1, letting developers customize Claude Code with JavaScript or TypeScript functions packaged inside plugins. The documentation requires Claude Code version 2.1.287 or later and says mods are enabled by default. Unlike external Model Context Protocol (MCP) servers or static Markdown-based Skills, mods run directly inside the active Claude Code process. Handlers can execute before, after, or instead of internal events, or wrap them entirely. Anthropic has already converted internal commands such as /diff into the mod architecture, with plans to migrate additional built-in features over time.

The company describes uses such as displaying CI status, redacting secrets from tool output and adding production confirmation steps. Existing settings hooks can already alter tool arguments and results; mods add functions running inside Claude Code and controls drawn in its interface.

Execution Model and Security Boundaries

Mods are not sandboxed. Anthropic’s documentation says they can read and write files available to the user, access environment secrets, make network requests and start processes. Processes a mod starts run outside Claude Code’s Bash sandbox even when that sandbox is enabled. Mods can also approve tool calls before the user is asked.

On Team and Enterprise plans and machines with managed settings, sec-default loads first by default to restrict user-installed mods, including attempts to override managed permission denials. Administrators who supply their own loading order must retain that guard to keep its restrictions. These guards apply to Claude’s tool calls, not a mod’s own file or process API calls. Existing plugin marketplace controls also apply.

Before loading a mod, claude plugin validate ./some-mod lists the events it handles and calls it makes without running it. This inspection is not a guarantee that the code is safe.

Supported Interfaces and Practical Constraints

Mod handlers run in sessions that load the plugin, but custom visual elements appear only in the terminal and the desktop app’s Code tab. The VS Code chat panel, print mode, Agent SDK and cloud sessions do not display them. Desktop WSL sessions do not support plugins or mods. Mods cannot restyle the permission prompt.

Anthropic advises developers to evaluate simpler existing mechanisms before building or installing mods. Standard Markdown Skills remain appropriate for natural-language behavioral guidance, while the Model Context Protocol remains the recommended path for exposing external tools and remote data services. A mod is useful when the task requires an interface element or an event change those existing tools cannot provide.