Anthropic lets Claude Code mods rewrite prompts and approve tool permissions
Available in Claude Code's CLI and desktop app, the TypeScript extensions can also replace built-in features and run with the agent's full access to your machine.
By Ryan Merket · Published
Primary source: X
Why it matters
Claude Code mods let developers and organizations alter an AI coding agent's prompts, tool calls, permission handling and interface. The same access that makes them powerful also gives installed mods the agent's full access to the user's machine.

Anthropic has opened Claude Code's prompts, interface and permission decisions to developer-written extensions called mods, giving users a way to change how the coding agent behaves without waiting for Anthropic to ship each feature. The extensions run in Claude Code's CLI and desktop app, and are packaged as plugins, according to the company's October 1st announcement and a post from ClaudeDevs.
https://x.com/ClaudeDevs/status/2105721434807083061
The change reaches into the agent's operating logic. A mod can run before, after or in place of an event in Claude Code. Anthropic says mods can rewrite prompts before they reach the model, block or retry tool calls, approve or deny permission requests, and redact secrets from tool output. They can also replace parts of the interface with custom panes, buttons and inputs.
That makes mods a deeper extension point than a bundle of shortcuts or reusable instructions. Anthropic introduced Claude Code plugins in October 2025 to package and share commands, subagents, MCP servers and hooks. Mods now add the ability to intercept events and replace built-in behavior within that existing plugin system. Anthropic says hooks offered some customization already, but could not rewrite events, draw new interface elements or replace features.
The sample mods show the range. Token Weather displays context-window usage and a sparkline of the previous 12 turns. Blast Radius pauses potentially destructive shell commands, including rm -rf, hard Git resets and force pushes, and shows what they would affect before the user proceeds. Replay Theater records file edits in a turn and lets users step through the diffs. Anthropic's mod-building guide walks through examples and shows how developers can distribute a mod through a plugin marketplace.
Anthropic says developers can also ask Claude Code to write a mod, install it and reload it during a session. The company has already moved its built-in /diff feature into the mod system, where users can disable it or substitute their own version. That is a notable change in product boundaries: Anthropic is making some of Claude Code's own features replaceable by the same extension mechanism available to outside developers.
The access that makes this possible is also the main risk. Anthropic says mods are not sandboxed and have the same access to a user's machine as Claude Code. A mod can affect permission requests and tool calls, so installing one amounts to running code from its publisher with the agent's privileges. The company advises users to install only mods from sources they trust.
Anthropic describes additional controls for business deployments. Team and Enterprise administrators can allow or block plugin marketplaces. On those plans, and on machines using managed settings, Anthropic says a built-in mod called sec-default loads first and blocks risky behavior such as overriding permission-deny rules. Administrators can load their own mods first, but Anthropic says they should also include sec-default to retain those restrictions.
The feature is available through the Claude directory or the /plugin command in the CLI, according to Anthropic. Mods can target the terminal, desktop app or both, and can be stacked; Anthropic says they run in the order they load. That flexibility gives teams a route to encode local workflows and controls directly into a coding agent. It also means the practical security boundary will depend partly on which mods users install and how administrators configure them.