Anthropic has shipped Mods, a new extension mechanism for Claude Code that lets developers change how the coding agent behaves with just a few lines of TypeScript. A mod can rewrite a prompt before it reaches the model, block, rewrite or retry a tool call, approve or deny a permission request, or redact secrets from tool output before Claude reads it. Mods can also change what users see: editing or replacing part of the interface, adding buttons and inputs that other mods can respond to.
The company framed Mods as the answer to a long-standing gap. Hooks, Anthropic's earlier customization layer, gave users partial control but could not rewrite events, draw new UI, or replace features. Mods can do all three, and Anthropic describes them as functions that hook into the events Claude Code emits every time it does something - calling a tool, asking for permission, or drawing part of the screen - running before, after, or instead of the event, or wrapping it entirely.
Mods ship inside plugins and install through the same /plugin command in the Claude Code CLI and desktop app, and can be shared through the Claude directory. When several mods hook the same event, they run in the order they load, letting developers stack mods from different authors. Anthropic also revealed that some built-in features now ship as mods themselves: the built-in /diff feature is now a mod that can be disabled or replaced, and AGENTS.md support was built with the same mechanism. The company says it plans to move more built-in features to mods over time so users can pare Claude Code down to a small core.
The design was shared on GitHub for developer feedback before launch, and Anthropic says users can also ask Claude Code to write a mod for them - the agent can produce the TypeScript, install it, and hot-reload it in the session. Community reaction was immediate, with developers demonstrating mods that suggest next steps mid-task, and Anthropic engineer Lydia Hallie describing the mechanism as "middleware for Claude Code."
For teams and enterprises, Anthropic added governance controls. Admins can allow or block plugin marketplaces, and on Team and Enterprise plans a built-in mod called sec-default ("security default") always loads first, stopping user-installed mods from doing risky things such as overriding permission deny rules. Its source code is viewable, and organizations can load their own mods first for audit logging or production safeguards, such as requiring confirmation before any command touches production config.
There is a blunt security caveat: Mods run with the same access to your machine as Claude Code itself, are not sandboxed, and Anthropic says users should only install mods from sources they trust, "the same way you'd install any code on your computer." That trade-off - maximal extensibility against full machine access - mirrors the broader tension in agentic coding tools as they become platforms in their own right.
With Mods, Anthropic is betting that the future coding agent is malleable software: a small core that third parties reshape, rather than a fixed product that waits for the vendor's roadmap. If the plugin ecosystem takes off, Claude Code stops being just an assistant and becomes a substrate - which is exactly the kind of lock-in every AI lab now wants to own.
Comments (0)
Log in to join the discussion
Log InNo comments yet