Anthropic lets Claude Code mods rewrite prompts and approve tool permissions Anthropic announced on October 1st that Claude Code now supports developer-written "mods" that can rewrite prompts before they reach the model, block or retry tool calls, approve or deny permission requests, and replace interface elements in the CLI and desktop app. The TypeScript extensions, packaged as plugins, are not sandboxed and run with the same access to a user's machine as Claude Code, so Anthropic advises installing only mods from trusted sources; Team and Enterprise administrators can allow or block plugin marketplaces, and a built-in `sec-default` mod loads first on managed machines to block risky behavior such as overriding permission-deny rules. Anthropic has already moved its built-in `/diff` feature into the mod system, making it replaceable by outside developers. Anthropic lets Claude Code mods rewrite prompts and approve tool permissions Available in Claude Code's CLI and desktop app, the TypeScript extensions can also replace built-in features and run with the agent's full access to your machine. By Ryan Merket https://runtimewire.com/author/ryan-merket ยท Published Primary source: X https://x.com/ClaudeDevs/status/2105721434807083061 Why it matters Claude Code mods let developers and organizations alter an AI coding agent's prompts, tool calls, permission handling and interface. The same access that makes them powerful also gives installed mods the agent's full access to the user's machine. Anthropic has opened Claude Code's prompts, interface and permission decisions to developer-written extensions called mods, giving users a way to change how the coding agent behaves without waiting for Anthropic to ship each feature. The extensions run in Claude Code's CLI and desktop app, and are packaged as plugins, according to the company's October 1st announcement https://claude.com/blog/claude-code-mods and a post from ClaudeDevs https://x.com/ClaudeDevs/status/2105721434807083061 . https://x.com/ClaudeDevs/status/2105721434807083061 https://x.com/ClaudeDevs/status/2105721434807083061 The change reaches into the agent's operating logic. A mod can run before, after or in place of an event in Claude Code. Anthropic says mods can rewrite prompts before they reach the model, block or retry tool calls, approve or deny permission requests, and redact https://runtimewire.com/models/huggingface/desert-ant-labs-redact-ea7fc9e653089714 secrets from tool output. They can also replace parts of the interface with custom panes, buttons and inputs. That makes mods a deeper extension point than a bundle of shortcuts or reusable instructions. Anthropic introduced Claude Code plugins in October 2025 to package and share commands, subagents, MCP servers and hooks. Mods now add the ability to intercept events and replace built-in behavior within that existing plugin system. Anthropic says hooks offered some customization already, but could not rewrite events, draw new interface elements or replace features. The sample mods show the range. Token Weather displays context-window usage and a sparkline of the previous 12 turns. Blast Radius pauses potentially destructive shell commands, including rm -rf , hard Git resets and force pushes, and shows what they would affect before the user proceeds. Replay Theater records file edits in a turn and lets users step through the diffs. Anthropic's mod-building guide https://claude.dev/blog/getting-started-with-claude-code-mods/ walks through examples and shows how developers can distribute a mod through a plugin marketplace. Anthropic says developers can also ask Claude Code to write a mod, install it and reload it during a session. The company has already moved its built-in /diff feature into the mod system, where users can disable it or substitute their own version. That is a notable change in product boundaries: Anthropic is making some of Claude Code's own features replaceable by the same extension mechanism available to outside developers. The access that makes this possible is also the main risk. Anthropic says mods are not sandboxed and have the same access to a user's machine as Claude Code. A mod can affect permission requests and tool calls, so installing one amounts to running code from its publisher with the agent's privileges. The company advises users to install only mods from sources they trust. Anthropic describes additional controls for business deployments. Team and Enterprise administrators can allow or block plugin marketplaces. On those plans, and on machines using managed settings, Anthropic says a built-in mod called sec-default loads first and blocks risky behavior such as overriding permission-deny rules. Administrators can load their own mods first, but Anthropic says they should also include sec-default to retain those restrictions. The feature is available through the Claude directory or the /plugin command in the CLI, according to Anthropic. Mods can target the terminal, desktop app or both, and can be stacked; Anthropic says they run in the order they load. That flexibility gives teams a route to encode local workflows and controls directly into a coding agent. It also means the practical security boundary will depend partly on which mods users install and how administrators configure them.