{"slug": "claude-code-mods-what-they-are-how-to-install-one-and-whether-theyre-safe", "title": "Claude Code mods: what they are, how to install one, and whether they’re safe", "summary": "Anthropic shipped Claude Code mods in version 2.1.287 on October 1, 2026, plugins written in JavaScript or TypeScript that run inside Claude Code to draw panes, add slash commands, or block risky commands before they execute. Anthropic warns that a mod \"runs with your permissions\" and is not sandboxed, and mods are enabled by default; they install via `/plugin install name@marketplace` and work on Pro, Max, Team and Enterprise plans or with an API key. Anthropic built several Claude Code features as mods, including the `/diff` pane and the optional side agent \"You should know,\" and shares three unsupported samples — token-weather, blast-radius and replay-theater — in its claude-code-playground GitHub repository.", "body_md": "The Claude Code logo. Image: Anthropic\n\nClaude Code mods are plugins that change how Claude Code looks and behaves from the inside: they can add a pane beside your conversation, a band above the prompt, a new `/command`, or a rule that stops a risky command before it runs. You install one like any other plugin, with `/plugin install name@marketplace`, or you can simply ask Claude to write one for you. Mods arrived in [Claude Code version 2.1.287](https://code.claude.com/docs/en/plugins/mods/overview) on October 1, 2026, are switched on by default, and come with one big warning from Anthropic: a mod “runs with your permissions” and isn’t sandboxed. Here’s what they do, where to find them and how to stay safe.\n\n**Jump to:**\n\n[What are mods](#what)\n\n[Mod examples](#examples)\n\n[How to install a mod](#install)\n\n[Marketplace and GitHub](#marketplace)\n\n[Make your own](#make)\n\n[Are mods safe?](#safe)\n\n[Turn mods off](#off)\n\n[Mod not working](#fix)\n\n[Where mods work](#where)\n\n[FAQ](#faq)\n\n## What are Claude Code mods?\n\nA mod is a [Claude Code plugin](https://code.claude.com/docs/en/plugins/overview) that contains JavaScript or TypeScript code. Claude Code calls that code whenever something happens, such as Claude reaching for a tool, you sending a prompt, or part of the screen being drawn, and the mod can watch the event, change it, or take it over completely.\n\nThat makes mods different from the ways you could already customise Claude Code. Settings hooks, skills, status lines and MCP servers all work from outside. A mod runs inside Claude Code, so it can do things they can’t:\n\n|  | Mod | Settings hook | Skill | MCP server | \n|---|---|---|---|---|\n| What it is | Code inside a plugin that runs in Claude Code itself | A shell command, web request or prompt run on an event | A `SKILL.md` file of instructions | An outside service that gives Claude tools | \n| Can draw on screen | Yes | No | No | No | \n| Written in | JavaScript or TypeScript | Any script | Markdown | Any language | \n| Pick it for | A pane, a custom command, rewriting an event | Blocking or logging an event with a script | Instructions you keep repeating | Reaching an outside system | \n\nBased on Anthropic’s comparison in the [mods overview](https://code.claude.com/docs/en/plugins/mods/overview).\n\nMods aren’t a separate product or subscription. They are part of Claude Code, so they work wherever you already use it, on a Pro, Max, Team or Enterprise plan or with an API key, in every country where [Claude is available](https://madrobot.blog/2026/09/29/is-claude-available-in-my-country-supported-countries-not-available-fix/).\n\n## Claude Code mod examples\n\nYou may already be running some. Anthropic built several of Claude Code’s own features as mods: the pane behind `/diff`, the loader that reads `AGENTS.md` files, and an optional side agent called **You should know**, which watches longer tasks and puts a note above the prompt when it spots something you might miss. It is off by default, and you turn it on with `/plugin enable cc-plugin-you-should-know@builtin`. To see the built-in mods, run `/plugin` and open the **Installed** tab, where they are listed under **Built-in**.\n\nAnthropic also shares three sample mods in its [claude-code-playground repository on GitHub](https://github.com/anthropics/claude-code-playground/tree/main/claude-code/mods), as they are and without support:\n\n- **token-weather:** draws a “forecast” of how full your context window is above the prompt.\n- **blast-radius:** holds a risky shell command, such as`rm -rf` ,`git reset --hard` or a force push, shows what it would delete or overwrite, and gives you**Proceed** and**Cancel** buttons.\n- **replay-theater:** adds a`/replay` command that steps through the file edits Claude made in the last turn.\n\nBlast Radius is the kind of guard that might have helped the developer who said [Claude Code wiped his C: drive](https://madrobot.blog/2026/10/07/claude-opus-5-5-deleted-c-drive-claude-code-auto-mode-boris-cherny/). For more ideas, Anthropic’s documentation suggests a pane that charts your token use after each request, a count of tool calls beside the spinner, and a mod that sends certain requests to a different model.\n\n## How to install a Claude Code mod\n\nA mod installs as a plugin, from a marketplace. You type the plugin’s name, an `@`, then the marketplace’s name:\n\n1. **Check your version.** In your shell, run`claude --version` . You need 2.1.287 or later in the terminal; the Code tab of the Claude Desktop app supports mods from 2.1.286 (type`/status` there to check).\n2. **Add the marketplace** if it isn’t Anthropic’s official one:`/plugin marketplace add owner/repo` for a GitHub repository, or a full git URL or local folder.\n3. **Install the mod:** in a session,`/plugin install name@marketplace` ; from your shell,`claude plugin install name@marketplace` .\n4. **Load it.** If you installed from the shell while a session was open, run`/reload-plugins` in that session. Otherwise it loads next time you start Claude Code.\n5. **Confirm it’s running.** Run`/plugin` . A dim line under the tabs reads something like`1 mod active · first-mod` .\n\nTo try a mod for one session without installing it, download its folder (for example with `git clone`) and start Claude Code with `claude --plugin-dir ./that-mod`.\n\n## Is there a Claude Code mods marketplace?\n\nThere is no separate store just for mods. Mods use the same [plugin marketplaces](https://code.claude.com/docs/en/plugins/anthropic-marketplaces) as every other Claude Code plugin, and a marketplace is simply a GitHub repository (or other git repository) with a catalogue file in it. Anthropic runs three general ones:\n\n| Marketplace | Name after @ | How you get it | \n|---|---|---|\n| Official | `claude-plugins-official` | Added automatically the first time you open Claude Code in a terminal | \n| Community | `claude-community` | `/plugin marketplace add anthropics/claude-plugins-community` | \n| Demo | `claude-code-plugins` | `/plugin marketplace add anthropics/claude-code` | \n\nYou can browse the official catalogue in the **Discover** tab of `/plugin` or on the web at [Claude Marketplace](https://claude.com/marketplace/plugins), which shows install counts and marks some plugins “Anthropic verified”. Mods on GitHub from other people install the same way once you add their repository as a marketplace, but they haven’t been checked by Anthropic, which is why the next two sections matter.\n\n## How to make your own Claude Code mod\n\nYou don’t need to write code. Describe what you want in a normal Claude Code session, for example “make a mod that shows the current git branch above the prompt”, and Claude writes it using a built-in skill called `plugin-authoring` (you can also load it yourself with `/plugin-authoring`). [Anthropic’s guide](https://code.claude.com/docs/en/plugins/mods/create) sets out what happens next:\n\n- Claude saves the mod in `~/.claude/dev-mods/` , in a folder named after the session. Claude Code may ask you to approve each file, because`~/.claude` is a protected folder.\n- Claude Code then asks whether to enable hot reloading. Choose **Enable for this session** and the mod loads at the end of the turn, and reloads each time Claude changes it.\n- A mod Claude writes only loads in that session and is eventually cleaned up. To keep it, copy its folder somewhere of your own, such as `~/mods/git-branch` , and start Claude Code with`--plugin-dir` pointing at it, or add it to a marketplace to share it.\n\nIf you’d rather write one by hand, a basic mod is three files: a `plugin.json` manifest, a `hooks.json` file, and a `register.js` or `.ts` file with your code. There is no build step, and `claude plugin validate ./my-mod` checks it without starting a session.\n\n## Are Claude Code mods safe?\n\nOnly as safe as the person who wrote them. Anthropic’s documentation is blunt that a mod “is code that runs with your permissions” and tells you to install mods “only from authors and marketplaces you trust”. Once loaded, a mod can:\n\n- read and write files anywhere your account can, start programs and make network requests;\n- read your secrets, including API keys in environment variables or settings files;\n- see every prompt you send and every tool call Claude makes, and rewrite them;\n- approve a tool call before you are asked;\n- spend your usage by calling a model on your plan or API key.\n\nMods aren’t sandboxed, even if you turn on Claude Code’s sandbox. Two limits do hold: a mod can restyle much of the interface but not the permission prompt, and on Team and Enterprise plans, or any machine with managed settings, a built-in guard stops a mod overriding your `deny` rules or your organisation’s managed hooks. Watch your usage too, since a mod that calls a model draws from the same limits covered in our guide to [making Claude Code usage last](https://madrobot.blog/2026/10/07/claude-code-burning-through-usage-tokens-how-to-make-limits-last/).\n\nBefore installing someone else’s mod, clone it and run `claude plugin validate` on the folder. Its `hooks:` and `calls:` lines list the events the mod handles and what it asks Claude Code to do, such as reading files or reaching the network, without running any of it.\n\n## How to turn Claude Code mods off\n\n- **One mod:** disable or uninstall it in the**Installed** tab of`/plugin` .\n- **Every installed mod, for one session:** start with`claude --safe-mode` , which also switches off your other customisations.\n- **Every installed mod, permanently:** set`\"disableAllHooks\": true` in`~/.claude/settings.json` . This also stops your settings hooks and custom status line.\n\nNone of these stop the built-in mods, which have their own switches in `/plugin`. At work, administrators can block user-installed mods or allow only the organisation’s own with the `allowManagedModsOnly` setting, much as they can [switch off Claude subscription access](https://madrobot.blog/2026/09/30/claude-code-your-organization-has-disabled-claude-subscription-access-fix/).\n\n## Claude Code mod not working?\n\nWork through these, from Anthropic’s [troubleshooting page](https://code.claude.com/docs/en/plugins/mods/troubleshoot):\n\n- **Old version:** update Claude Code to 2.1.287 or later.\n- **Not named in /plugin:** if the`mods active` line doesn’t list it, it didn’t load. Start Claude Code with`claude --debug` and look for a line ending`not loaded:` with the reason.\n- **Check mods can load at all:** run`claude plugin test` in your shell from a folder with no mod in it. “no hooks module to load” means mods work; “hooks modules are turned off here” means`disableAllHooks` or your organisation is blocking them; “the rollout switch served off” means Anthropic has turned installed mods off remotely.\n- **Refused by your organisation:** a message mentioning`allowManagedModsOnly` means only your company’s mods may run.\n- **A typo in the mod:**`claude plugin validate` catches a misspelt event or a broken manifest.\n- **Nothing appears on screen:** check where you are running it (below).\n\n## Where Claude Code mods work\n\n| Where you run Claude Code | Mod code runs | Panes and drawings show | \n|---|---|---|\n| Terminal (including JetBrains) | Yes | Yes | \n| Claude Desktop, Code tab | Yes | Mostly | \n| Claude Desktop, WSL session | No | No | \n| VS Code extension chat panel | Yes | No | \n| `claude -p` and the Agent SDK | Yes | No | \n| Cloud sessions | If the plugin reaches the session | No | \n\nFrom Anthropic’s mods overview. Remote Control runs mods on your own machine and shows drawings in its terminal.\n\nSo a mod that guards commands works almost everywhere, while one that draws a pane needs the terminal or the Desktop app. Our guide to [cloud sessions versus local](https://madrobot.blog/2026/09/27/claude-code-cloud-session-pricing-cost-vs-local/) explains the difference between the two.\n\n*Last checked: October 9, 2026, against Claude Code 2.1.296 and Anthropic’s mods documentation.*\n\n## Frequently asked questions\n\n### What are Claude Code mods?\n\nMods are Claude Code plugins containing JavaScript or TypeScript code that runs inside Claude Code. They can add panes, buttons and commands, change how the interface looks, and watch, rewrite or block tool calls and prompts. They arrived in Claude Code 2.1.287 on October 1, 2026.\n\n### How do I install a Claude Code mod?\n\nAdd the mod’s marketplace if needed with /plugin marketplace add owner/repo, then run /plugin install name@marketplace in a session, or claude plugin install name@marketplace in your shell. Run /reload-plugins if a session was already open.\n\n### Is there a Claude Code mods marketplace?\n\nNot a separate one. Mods are plugins, so they come from the same plugin marketplaces: Anthropic’s official one (claude-plugins-official), its community one (claude-community), or any GitHub repository set up as a marketplace.\n\n### Where can I download Claude Code mods from GitHub?\n\nAnthropic’s three sample mods, token-weather, blast-radius and replay-theater, are in the claude-code/mods folder of its claude-code-playground repository. Clone it and run claude --plugin-dir with a mod’s folder to try one for a session.\n\n### Are Claude Code mods safe?\n\nOnly if you trust the author. Mods run with your permissions and aren’t sandboxed, so they can read your files and API keys, see your prompts and approve tool calls. Run claude plugin validate on a mod’s folder first to see what it does.\n\n### Do Claude Code mods cost anything?\n\nMods are part of Claude Code and don’t cost extra, but a mod that calls a model uses your plan’s usage or your API key, just as Claude does.\n\n### Do mods work in VS Code?\n\nPartly. In the VS Code extension’s chat panel a mod’s code runs, but anything it draws, such as a pane, doesn’t appear. Drawings show in the terminal, including VS Code’s integrated terminal, and in the Claude Desktop app’s Code tab.\n\n### How do I turn off Claude Code mods?\n\nDisable one in the Installed tab of /plugin, start a session with claude --safe-mode to skip all installed mods, or set \"disableAllHooks\": true in ~/.claude/settings.json to stop them every time.\n\n### Why is my Claude Code mod not working?\n\nCheck you are on Claude Code 2.1.287 or later, that /plugin names the mod as active, and run claude plugin test to see whether a setting, your organisation or Anthropic has turned mods off. claude --debug shows the reason a mod didn’t load.\n\n*Sources: Anthropic’s Claude Code documentation ([mods overview](https://code.claude.com/docs/en/plugins/mods/overview), [create a mod](https://code.claude.com/docs/en/plugins/mods/create), [troubleshoot a mod](https://code.claude.com/docs/en/plugins/mods/troubleshoot), [manage mods for your organization](https://code.claude.com/docs/en/plugins/mods/admin), [Anthropic’s marketplaces](https://code.claude.com/docs/en/plugins/anthropic-marketplaces)), [Claude Code changelog](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md), [Anthropic sample mods](https://github.com/anthropics/claude-code-playground/tree/main/claude-code/mods).*", "url": "https://wpnews.pro/news/claude-code-mods-what-they-are-how-to-install-one-and-whether-theyre-safe", "canonical_source": "https://madrobot.blog/2026/10/09/claude-code-mods-what-are-they-how-to-install/", "published_at": "2026-10-09 20:45:00+00:00", "updated_at": "2026-10-09 20:54:12.797303+00:00", "lang": "en", "topics": ["ai-tools", "ai-products", "developer-tools", "ai-agents"], "entities": ["Anthropic", "Claude Code", "Claude Code mods", "claude-code-playground", "You should know", "blast-radius", "token-weather", "replay-theater"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/claude-code-mods-what-they-are-how-to-install-one-and-whether-theyre-safe", "markdown": "https://wpnews.pro/news/claude-code-mods-what-they-are-how-to-install-one-and-whether-theyre-safe.md", "text": "https://wpnews.pro/news/claude-code-mods-what-they-are-how-to-install-one-and-whether-theyre-safe.txt", "jsonld": "https://wpnews.pro/news/claude-code-mods-what-they-are-how-to-install-one-and-whether-theyre-safe.jsonld"}}