Correction and source note (4 October 2026): This article has been revised to remove claims that were not supported by Anthropic’s announcement. Anthropic announced Claude Code mods on 1 October 2026, not 4 October. The first-party source is Anthropic’s product announcement. The product details below are attributed to Anthropic; they are not an independent test of the feature or its security.

What Anthropic announced

Anthropic introduced mods for Claude Code on 1 October 2026. The company describes a mod as a small TypeScript function that changes how Claude Code behaves or looks. Mods can rewrite a prompt, add interface elements, replace a built-in feature, or add functionality. They are packaged inside Claude Code plugins and work in the command-line interface and desktop app, according to the company.

Anthropic says Claude Code emits events when it calls a tool, asks for permission, or draws part of the screen. A mod can run before, after, instead of, or around an event. Anthropic’s examples include changing prompts, blocking or retrying tool calls, redacting secrets from tool output, and adding buttons or inputs to the interface. These are capabilities Anthropic describes; whether a particular third-party mod behaves safely depends on its code and configuration.

Built-in features and security limits

Anthropic says its built-in /diff feature now ships as a mod, so users can turn it off or replace it with another version. The company says it plans to move more built-in features to mods over time. Its announcement does not say that the AGENTS.md instruction parser is a mod, so the earlier claim to that effect has been removed.

Mods run with the same access to a machine as Claude Code itself. Anthropic says they are not sandboxed and advises users to install them only from trusted sources. A mod may affect permission decisions, which makes review of its code and provenance important. The company’s announcement says organizations can use existing plugin controls to allow or block marketplaces. On Team and Enterprise plans, and on machines with managed settings, a built-in security mod called sec-default loads first and restricts risky behavior by user-installed mods. Administrators can load their own mods first, but Anthropic advises retaining sec-default in the list.

The earlier version of this article named a plugin-validation scanner, a --safe-mode launch flag, a specific package identifier for a “You Should Know” mod, and an AGENTS.md parser mod as though Anthropic had confirmed them. We could not verify those specifics in the company’s announcement, and have removed them. We have also removed an unsupported claim about an engineer’s demonstration and an unattributed estimate of India’s developer workforce.

Why this matters for development teams

For teams considering Claude Code mods, the immediate decision is whether the extra control over tool calls and interface behavior is worth running additional code with the same machine access as the coding assistant. Teams can start with Anthropic’s mods documentation and plugin policies, then review a mod’s source, publisher, and permissions before deployment. Anthropic’s announcement establishes the feature’s availability, but it does not establish that any particular mod will meet a company’s security, privacy, or compliance requirements.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.