Developers can now hook into Claude Code's internals with small TypeScript functions, though the same power raises security questions
Anthropic has handed developers a screwdriver and invited them to open up Claude Code. Its AI coding tool now supports mods, small functions that can rewrite how the tool behaves and change what its interface looks like.
The update landed on October 1, 2026.
What mods actually do #
Technically, mods are small, event-driven functions written in TypeScript or JavaScript. They hook into internal events inside Claude Code, which means they fire when specific things happen in the tool.
Once triggered, a mod can alter the prompts Claude receives. It can adjust the tool calls the AI makes, change interface elements, or bolt on entirely new features.
Mods slot into Claude Code’s existing plugin system rather than replacing it. They work in both the command-line version and the desktop app.
Getting them running requires Claude Code v2.1.287 or later. In supported versions, mods are switched on by default, so there is no extra setup flag to flip.
Installation and management run through the existing /plugin command and plugin marketplaces.
Anthropic ate its own cooking #
Several built-in pieces of Claude Code have been converted into mods. That list includes the ‘/diff’ pane, the agents.md , and telemetry features. These now run as customizable modules instead of fixed parts of the tool.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
A quiet rollout, then a fast crowd #
Early access began between September 9 and 15, 2026, through an environment variable that enabled function hooks.
Developers who found the switch got to work quickly. The community built games and context monitors that run alongside Claude Code’s normal functions.
These add-ons reportedly operate at negligible additional token costs.
Claude Code’s plugin infrastructure entered public beta around October 2025, roughly a year before mods arrived.
The security footnote that is not really a footnote #
Mods run with the same level of access as Claude Code itself, which is designed to read files, run commands, and act on a developer’s machine.
During the early access period, the community examined the public mods available at the time. Of 31 public mods, 14 were identified as capable of executing host processes.
In plainer terms, nearly half of the publicly shared mods could launch programs on the user’s own computer.
What this means for developers and the AI coding race #
Because mods are on by default and share Claude Code’s permissions, users effectively need to vet them the way they would vet any code running on their machine. The 14-of-31 figure from early access is a useful reminder that capability and risk tend to arrive together.
For engineering organizations, security teams that approved Claude Code as a single tool may now need policies covering which mods are allowed, who can install them, and which marketplaces are trusted. Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our