2026-10-11 16:36 UTC

Anthropic's ClaudeDevs account announces mods β€” TypeScript event handlers shipped inside plugins that run inside Claude Code, able to redraw its UI, guard or rewrite tool calls and prompts, and even approve permissions and spend usage β€” and whether mods become the adopted deep-extension path for the dominant coding harness, while that enlarged trust surface (self-approving tool calls, secret access, spending) is recognized as a supply-chain risk, resolves the episode.

state: corroboratedheat: mediumuncertainty: mediumconvergesscott: highagent-harnesses claude-code extensibility plugin-supply-chainAnthropic
Surfaced 2026-10-03T21:06:05Z β€” The origin is Anthropic's official docs page for "Mods", published with Claude Code v2.1.287. It defines the feature: "A mod is a plugin tha β€” The xcodebuild log-fix mod is the first third-party exercise of the tool-result rewrite plane on a real harness-input defect, shifting the periphery's center of gravity from UI toys toward genuine middleware utilities (handoff-compact, now this) β€” but it's weakest-tier reception (2 pts, 1 comment), meets none of the four pre-declared re-raise signals, and leaves both unresolved halves open: no adoption at scale, and still no outside voice naming the self-approving/secret/spend surface a supply-chain risk, so Scott's dated-receipts publishing window stays open.

What is this?

Anthropic shipped Claude Code mods in v2.1.287 (Oct 1, 2026) β€” in-process TypeScript event handlers that run inside the coding agent, not beside it. Mods can redraw the TUI/desktop UI, intercept and rewrite tool calls and prompts, pre-approve permission requests, read secrets from tool output, and spend the user's API budget. The first-party docs explicitly enumerate this trust surface and ship mitigations (plugin validation, --safe-mode, disableAllHooks, org admin limits, a protective sec-default mod on Team/Enterprise plans). ~204 hours post-launch, 16+ third-party mods exist but all are weakest-tier reception; the mix has drifted from UI toys toward middleware utilities (handoff-compact, xcodebuild rewrite, usage bands, spec review, guardrails 0.2.0), and established plugin authors (claude-dashboard, statusline-anywhere) plus one established OSS project (Repowise Lens, 7k stars) have migrated β€” yet no mod has real traction. The trust surface is now folk knowledge among casual Pro users, but no outside security voice has named the self-approving/secret/spend surface a supply-chain risk, leaving Scott's dated-receipts publishing window (Breach Doesn't Compose / Agent Provenance Stack) open and aging.

Why it matters to Scott

Anthropic shipped exactly the in-process third-party TypeScript middleware surface Scott's containment canon maps: mods act as the user, pre-approve permission prompts, read secrets from tool output, and spend the user's API budget. This is a consequential other party independently arriving at the trust-surface risk pattern Scott's SiloOS, Agent Provenance Stack, and Manners-vs-Physics frameworks describe β€” the dated-receipts publishing window is open and aging. The hook-guard measurement (448 blocks/76 sessions, bypass via cat/sed) empirically confirms the behavioural-vs-mechanical guarding gap mods address.
ip:framework.siloosip:framework.agent-provenance-stackip:concept.manners-vs-physicsip:concept.architectural-containmentip:concept.runtime-containmentip:concept.guardrail-illusionip:concept.trust-hierarchyip:concept.zero-trust-for-decisionsip:concept.confused-deputy-problemip:concept.capability-tokensdev:concept.padded-cell-agent-architecturedev:concept.privacy-tokenized-agent-boundarydev:concept.guarded-agent-inboxdev:concept.deterministic-agent-control-planedev:concept.single-tenant-ai-appliancedev:project.silo-osradar:abyss-acp-agent-isolationradar:acs-local-skill-risk-catalogradar:agent-chaperone-jev-tool-screeningradar:evoundo-recoverable-agent-self-modificationradar:countinghouse-in-process-mcp-compositionradar:claude-code-skill-load-failuresradar:anthropic-project-glasswingradar:anthropic-project-parkaradar:claude-code-nested-instruction-loadingradar:claude-mem-windows-credential-polling
queries asked of Scott's wikis
  • agent-harness extensibility: in-process middleware vs shell hooks
  • manners-vs-physics containment: mechanical interception vs behavioral guards
  • supply-chain risk: third-party code with self-approval, secret access, spend authority
  • agent provenance stack: attestation, replay, and guardrail tamper-resistance
  • open-weights sovereignty: local inference vs cloud harness extension surfaces
  • claude-code / anthropic: project tracking and prior positions

Measured heat

now 0 pts/hpeak 144 pts/hcomments 0/hpeers p33momentum: steady3 platformsage 266h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion

How the heat travelled

09-30 14:00⭐ origin echo-reconstructedThe origin is Anthropic's official docs page for "Mods", published with Claude Code v2.1.287. It defines the feature: "A mod is a plugin tha
Anthropic on blog (echo) Β· attributed from reddit.post.1wv8glc, hn.story.49925800, hn.story.49926243
β€”
10-01 19:08first on hacker news Β· published Β· +29.1hClaude Code Mods: plugins may now modify deeper behavior
rtuin
β€”
10-01 19:14first on r/ClaudeAI Β· published Β· +29.2hYou can now mod Claude Code: - Change how it behaves - Customize the UI - Swap in your own features Write one with a few lines of TypeScript, or have Claude build it for you. Mods ship inside plugins, so you install them with /plugin in the CLI or desktop app.
GroovyMelodicBliss
β€”
10-01 19:08amplified on hacker newshn.story.49925800
rtuin
peak 3 Β· 0 comments Β· 1% of case engagement
10-01 19:14amplified on r/ClaudeAIreddit.post.1wv8glc
GroovyMelodicBliss
peak 18 Β· 9 comments Β· 4% of case engagement
10-01 19:48amplified on hacker newshn.story.49926243
mfiguiere
peak 3 Β· 0 comments Β· 1% of case engagement
10-01 22:03amplified on hacker newshn.story.49927599
b--l
peak 2 Β· 0 comments Β· 0% of case engagement
10-02 14:38amplified on hacker newshn.story.49934033
FranciscoCarlos
peak 1 Β· 0 comments Β· 0% of case engagement
10-02 14:51amplified on hacker newshn.story.49934165
tzafrir
peak 2 Β· 0 comments Β· 0% of case engagement
27 more amplifiers in ainews.case_chain
10-01 20:20our radar first saw it Β· +30.4hdiscovery anchor: reddit.post.1wv8glcβ€”
10-03 21:02reached heat=high Β· +79.0h Β· via ledgerβ€”β€”
pace: p78 vs 1188 stories at the 168h mark (now 266h old) β€” ahead of nsa-ai-testing-billions (1.0x), behind irregular-agentic-weight-self-modification (1.0x)

Evidence (34) β€” ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 redditYou can now mod Claude Code: - Change how it behaves - Customize the UI - Swap in your own features Write one with a few lines of TypeScript, or have Claude build it for you. Mods ship inside plugins, so you install them with /plugin in the CLI or desktop app.
ClaudeAI
GroovyMelodicBliss189
🟧 hnClaude Code Mods: plugins may now modify deeper behavior
Retrieved article excerpt

Open article Β· Retrieved 2026-10-01T20:35:58.918650+00:00

Mods

# Mods overview

Copy pageCopy page

Add panes, commands, and tool call rules to Claude Code with a mod. See what a mod can do, how to make or install one, and where mods run.

Copy pageCopy page

A mod is a [plugin](https://code.claude.com/docs/en/plugins/overview) that changes how Claude Code looks and behaves. It’s made of JavaScript or TypeScript event handlers: Claude Code calls one when an event happens, such as a tool call, a submitted prompt, or a part of the interface being drawn, and the handler can watch the event, change it, or take it over. Use a mod to add a feature of your own to Claude Code, such as a pane that charts how full your context is after each request. For the files in a mod and a complete example, see [How a mod works](https://code.claude.com/docs/en/plugins/mods/overview#how-a-mod-works).

Claude Code’s existing [hooks](https://code.claude.com/docs/en/hooks) also run on events, as a shell command, HTTP request, or prompt you configure in a settings file. A mod’s handlers are functions that run inside Claude Code instead. Claude Code calls both kinds hooks: on these pages, β€œhook” means a mod’s handler, and the settings-file kind is a β€œsettings hook”.

## [​](https://code.claude.com/docs/en/plugins/mods/overview#what-a-mod-can-do) What a mod can do

Settings hooks, skills, status lines, and MCP servers work from outside Claude Code: each one runs a script, or gives Claude text or tools. A mod runs inside Claude Code, so it can do things they can’t:

- **Draw an interface you can use**: a pane beside the transcript or a band above the prompt, with tabs, buttons, and text fields. See [Draw in the interface](https://code.claude.com/docs/en/plugins/mods/interface).
- **Redraw Claude Code’s own interface**: replace or restyle parts Claude Code draws itself, such as a tool call’s row, the spinner, or the dialog Claude asks questions in. See [Change what Claude Code already draws](https://code.claude.com/docs/en/plugins/mods/interface#change-what-claude-code-already-draws).
- **Step into a tool call or a request**: for example, hold a tool call while you ask the user a question, answer it without running the tool, or send one request to a different model. See [Guard or change a tool call](https://code.claude.com/docs/en/plugins/mods/events#guard-or-change-a-tool-call) and [Follow a turn](https://code.claude.com/docs/en/plugins/mods/events#follow-a-turn).
- **Run your own code on a command**: a `/command` that runs your function at once, with no Claude turn, even while Claude is working. See [Add a command or a tool](https://code.claude.com/docs/en/plugins/mods/api#add-a-command-or-a-tool).
- **Share data between hooks**: a mod’s hooks share the variables in its file, so what one hook records, another can show. For example, one hook can count tool calls while another shows the count beside the spinner, or one can read each request’s token usage while another charts it in a pane. See [React to events](https://code.claude.com/docs/en/plugins/mods/events).

Mods work in the Claude Code CLI and in the Code tab of the Claude Desktop app. See [Where mods run](https://code.claude.com/docs/en/plugins/mods/overview#where-mods-run) to understand how they behave elsewhere, such as in the VS Code extension, `claude -p`, and cloud sessions. If a settings hook, a skill, or an MCP server already does what you need, [compare them](https://code.claude.com/docs/en/plugins/mods/overview#compare-mods-settings-hooks-skills-and-mcp-servers) before you write a mod. To manage mods for an organization, see [Manage mods for your organization](https://code.claude.com/docs/en/plugins/mods/admin).

## [​](https://code.claude.com/docs/en/plugins/mods/overview#get-a-mod) Get a mod

You can start with a mod in one of three ways:

- **Use one you already have**: some of Claude Code’s own features are mods, such as `/diff`. See [Mods built into Claude Code](https://code.claude.com/docs/en/plugins/mods/overview#mods-built-into-claude-code).
- **Make one**: describe what you want in a Claude Code session, and Claude writes the mod. See [Ask Claude for a mod](https://code.claude.com/docs/en/plugins/mods/create#ask-claude-for-a-mod). To learn how a mod’s code works, [write one yourself](https://code.claude.com/docs/en/plugins/mods/create#write-a-mod-yourself).
- **Install one**: see [Install or update a mod](https://code.claude.com/docs/en/plugins/mods/overview#install-or-update-a-mod)

### [​](https://code.claude.com/docs/en/plugins/mods/overview#install-or-update-a-mod) Install or update a mod

A mod is code that runs with your permissions. It can read and write your files, start processes, and make network requests. Install mods only from authors and marketplaces you trust. See [Decide whether to trust a mod](https://code.claude.com/docs/en/plugins/mods/overview#decide-whether-to-trust-a-mod).

A mod installs as a plugin, from a marketplace. Give the plugin’s name, an `@`, and the marketplace’s name. These examples install a plugin named `token-chart` from a marketplace named `your-org`:

- In a Claude Code session, run `/plugin install token-chart@your-org`.
- In your shell, run `claude plugin install token-chart@your-org`.

[Install plugins](https://code.claude.com/docs/en/plugins/install) covers marketplaces, scopes, the VS Code extension and the Desktop app, and [keeping plugins updated](https://code.claude.com/docs/en/plugins/install#keep-plugins-updated), all of which apply to a plugin that contains a mod without changes.
If you install or update a mod from your shell while a session is open, run `/reload-plugins` in that session to load it. Otherwise it loads the next time you start Claude Code.

## [​](https://code.claude.com/docs/en/plugins/mods/overview#decide-whether-to-trust-a-mod) Decide whether to trust a mod

A mod is code that runs with your permissions, inside Claude Code. Install mods only from authors and [marketplaces you trust](https://code.claude.com/docs/en/plugins/security).

### [​](https://code.claude.com/docs/en/plugins/mods/overview#what-a-mod-can-reach) What a mod can reach

A mod runs with your permissions, so before you install one, know what it has access to. Once it loads, a mod can:

- **Act on your machine as you**: read and write files anywhere your user account can, start programs, and make network requests
- **Read your secrets**: environment variables and settings files, including an API key you keep in either
- **See your session**: every prompt you send and every tool call Claude makes
- **Change your session**: rewrite a prompt or a tool call, submit a prompt as if you had typed it, or send a message to another of your sessions
- **Act without asking you**: approve a tool call before you’re asked
- **Spend your usage**: call a model on your plan or API key

A mod that approves tool calls can approve one that an `ask` rule would prompt for, or that one of your own `PreToolUse` hooks blocked. [Extend permissions with hooks](https://code.claude.com/docs/en/permissions#extend-permissions-with-hooks) lists what such a mod can approve, including when it can approve a call that a `deny` rule refuses.
A mod can restyle much of Claude Code’s interface, but not the permission prompt. It can’t change what a prompt shows you.

### [​](https://code.claude.com/docs/en/plugins/mods/overview#list-what-a-mod-does-before-you-install-one) List what a mod does before you install one

Before you install a mod, you can list which events it hooks and what it asks Claude Code to do, such as read a file or make a network request, without running it. Get the plugin’s files first, for example by cloning its repository. Then, in your shell, run `claude plugin validate` on the plugin’s directory:

```
claude plugin validate ./some-mod
```

The `hooks:` and `calls:` lines in the output list the events the mod handles and what it asks Claude Code to do. [Review what a mod can do](https://code.claude.com/docs/en/plugins/mods/admin#review-what-a-mod-can-do) shows the output and which calls to look for.

## [​](https://code.claude.com/docs/en/plugins/mods/overview#turn-mods-on-or-off) Turn mods on or off

Mods require Claude Code v2.1.287 or later, and they’re on by default. In your shell, run `claude --version` to check, and update Claude Code if yours is older.
To turn mods off, choose how many to stop, and for how long. To turn them back on, undo the same change:

- **One mod**: disable or uninstall its plugin from the [**Installed** tab in `/plugin`](https://code.claude.com/docs/en/plugins/install#manage-installed-plugins)
- **Every installed mod, for one session**: start Claude Code with [`--safe-mode`](https://code.claude.com/docs/en/cli-reference#cli-flags), which also leaves out your other customizations
- **Every mod you installed, in every session**: set [`"disableAllHooks": true`](https://code.claude.com/docs/en/settings-reference#disableallhooks) in `~/.claude/settings.json`. Your settings hooks and custom status line stop too. What your organization manages keeps running.

If you use Claude Code through an organization, an administrator can also limit which mods load. Administrators start at [Stop user-installed mods from loading](https://code.claude.com/docs/en/plugins/mods/admin#stop-user-installed-mods-from-loading).
To find out whether mods can load for you, see [Check whether mods can load](https://code.claude.com/docs/en/plugins/mods/troubleshoot#check-whether-mods-can-load).

If you set `CLAUDE_CODE_ENABLE_FUNCTION_HOOKS` during early access, remove it. Claude Code v2.1.287 and later ignores it, so setting it to `0` doesn’t keep mods off.

### [​](https://code.claude.com/docs/en/plugins/mods/overview#see-which-mods-a-session-loaded) See which mods a session loaded

To see which mods a terminal session loaded, run `/plugin` at the Claude Code prompt. A dim line under the tabs gives the count and the names, such as `1 mod active Β· first-mod`. If a mod you installed isn’t named there, see [Find out why a mod does nothing](https://code.claude.com/docs/en/plugins/mods/troubleshoot#find-out-why-a-mod-does-nothing).

## [​](https://code.claude.com/docs/en/plugins/mods/overview#how-a-mod-works) How a mod works

A mod is a [plugin](https://code.claude.com/docs/en/plugins/overview) whose code registers event handlers, called hooks. Claude Code runs a hook when its event happens, such as when Claude calls a tool or when the spinner is drawn. A small mod has three files:

```
first-mod/
β”œβ”€β”€ .claude-plugin/
β”‚   └── plugin.json
└── hooks/
    β”œβ”€β”€ hooks.json
    └── register.js
```

- **`plugin.json`**: the plugin’s [manifest](https://code.claude.com/docs/en/plugins/manifest-reference)
- **`hooks.json`**: [points to your code file](https://code.claude.com/docs/en/plugins/mods/reference#files)
- **`register.js`**: [your code](https://code.claude.com/docs/en/plugins/mods/create#write-a-mod-yourself), called the hooks module. It tells Claude Code which events to run your functions on.

This is a complete `register.js`. It counts the tool calls Claude makes and shows the count beside the spinner while Claude works, as in `Thinking Β· tool calls: 3…`.

hooks/register.js

```
// The count, shared by the two hooks below
let calls = 0

// Claude Code calls this once when the mod loads
export function register(on) {
  // Runs each time Claude is about to use a tool
  on('tool.call', async ($, e, next) => {
    calls += 1
    // Ask Claude Code to draw the interface again, so the new count shows
    $.ui.invalidate('ui.render')
    // Let the tool run as usual
    return next(e)
  })

  // Runs each time Claude Code draws the spinner
  on('ui.render', { component: 'Spinner' }, async ($, e, next) => {
    // Keep Claude Code's spinner, with the count added after its word
    return next({ ...e, props: { ...e.props, suffix: ' Β· tool calls: ' + calls + '…' } })
  })
}
```

The file registers two hooks, and both use the `calls` variable at the top:

- **The [`tool.call`](https://cod
rtuin30
🟧 hnGetting started with Claude Code modsmfiguiere30
🟧 echo.blog ⭐The origin is Anthropic's official docs page for "Mods", published with Claude Code v2.1.287. It defines the feature: "A mod is a plugin thaAnthropicβ€”β€”
🟧 hnPi-autoresearch ported to Claude Code 1:1 using the new mods APIb--l20
🟧 hnShow HN: What's Agent Doing – a Claude Code UI mod that explains each steptzafrir20
🟧 hnMulti-harness delegation Mod for Claude CodeFranciscoCarlos10
🟧 hnShow HN: Status lines in the Claude desktop appnastynate20
🟧 hnGetting started with Claude Code modsalwillis20
🟠 reddithandoff-compact, a mod that does the handoff + /clear routine for you every time autocompact fires
ClaudeAI
speciallight243
🟧 hnCustomize Claude Code with Mods in TypeScriptrbinv10
🟠 redditBuilt a Minecraft Skin for my Claude Code
ClaudeAI
Funny_Language483003
🟠 redditFinally had some time to do something useful with mods
ClaudeAI
cleverhoods12
🟧 hnShow HN: Claude Mods – Minesweepercleverhoods10
🟠 redditI built a Claude Code mod that gives Claude your xcodebuild errors instead of the truncated build log
ClaudeAI
Gary_BBGames21
🟠 redditMods overview - Claude Code Docs
ClaudeAI
TensorTrace31
🟠 redditWhat I learned building a Claude Code mod: a status band above the prompt
ClaudeAI
Troepster11
🟠 redditI made a Mod that shows your 5h/weekly usage live, a reset forecast and context % above the prompt box, with optional auto compact and a manual compact button
ClaudeAI
Antpocalypse_7913
🟠 redditBuilt a Claude mod to help review spec and design documents
ClaudeAI
revelationnow14
🟠 redditDid you know Claude Code has mods? They're awesome
ClaudeAI
Necessary_Abroad66322417
🟠 redditI counted how many times my hooks had to stop Claude in one week. 448 times in 76 sessions
ClaudeAI
Ok-Motor-98126745
🟠 redditWho managed to make mods work ? I get the same bug every time
ClaudeAI
KlausWalz11
🟠 redditI built a live map for Claude Code that shows every file an edit touches
ClaudeAI
Obvious_Gap_576811
🟠 redditClaude Code mods have been one of the best updates so far
ClaudeAI
YareYareDaze00712
🟠 redditI approved an agent’s β€œoc delete β€”all” without reading it, so I built guardrails (and 10 other mods) with Claude Code’s new function hooks
ClaudeAI
Sea-University-7237016
🟠 redditmods are really powerfull
ClaudeAI
adminvasheypomoiki176
🟠 redditMy Claude Code status line now runs as a mod, so I can finally see my limits in the desktop app
ClaudeAI
uppinote02
🟠 redditI gave my Claude Code subagents names (Turing, Magellan, Holmes) and a pane that lists them - named subagents mod
ClaudeAI
midgyrakk01
🟠 redditClaude Code mods are kinda insane
ClaudeAI
ITower__Education17
🟠 redditAre the new Code features about innovation or ecosystem lock-in?
ClaudeAI
EightFolding1925
🟠 reddit394 subagents in ten minutes locked me out of Claude Code, so I built a mod that asks first
ClaudeAI
rbartoli011
🟠 redditI made a claude code mod that uses Haiku 5.5 (or Jev) to pick the best model and effort for your task. (and more...)
ClaudeAI
Intelligent-Crew-57624573
🟧 hnAgent-config&Claude Code modsFunShot21
🟧 hnShow HN: Context Diet – trims tool output before it floods Claude Code's contexthy4hy10

Interpretation history

Decision trace