cd /news/ai-agents/claude-code-mods-write-typescript-pl… · home › topics › ai-agents › article
[ARTICLE · art-144793] src=byteiota.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Claude Code Mods: Write TypeScript Plugins That Rewrite the Agent

Anthropic shipped Claude Code Mods on October 1, a TypeScript extensibility layer that runs inside the agent's execution pipeline and can intercept tool calls, rewrite the system prompt, redraw the terminal UI, and replace built-in features. Anthropic converted three of its own features — the diff pane, the agents.md loader, and telemetry — into mods and open-sourced them in the main repository, while Pluto Security researchers found that the privileged `$` engine interface's `$.fs.read` is not project-scoped, allowing a mod to read Claude Code's OAuth credentials and full prompt history from `history.jsonl`. Mods run unsandboxed with the same machine access as Claude Code, though a built-in `sec-default` mod loads first on Team and Enterprise plans to stop installed mods from overriding permission deny rules.

read4 min views1 publishedOct 4, 2026
Claude Code Mods: Write TypeScript Plugins That Rewrite the Agent
Image: Byteiota (auto-discovered)

Claude Code can now be rewritten from the inside. On October 1, Anthropic shipped Mods — small TypeScript modules that live inside the agent’s execution pipeline, intercept tool calls, redraw the terminal UI, and replace built-in features entirely. This is not prompt engineering. It is code running inside Claude Code itself, with the same machine access the agent has.

To make that concrete: the diff pane you see in Claude Code is now a mod. The agents.md is a mod. Telemetry is a mod. Anthropic converted three of its own features on launch day and open-sourced them in the main repository. These are not experimental hooks — they are the new extensibility layer.

Mods vs. Settings Hooks: What Changed #

Before Mods, Claude Code had settings hooks: shell scripts that fired when something happened and could allow or block an action. They ran outside the Claude Code process, could not rewrite events, and had no access to the UI.

Mods change all of that. They run inside the session and can:

  • Rewrite a tool call’s input before it executes
  • Deny a tool call entirely with a custom reason
  • Rewrite the system prompt before it sends
  • Draw side panes, status bars, and buttons in the terminal UI
  • Add /slash-commands that run without a model turn
  • Replace a built-in feature with your own implementation

If settings hooks are .gitconfig entries, mods are VS Code extensions. Same agent, entirely different level of control.

The Three-File Structure #

A mod ships inside a plugin. The minimum to get one running is three files:

.claude-plugin/
  plugin.json        # name, version, description
hooks/
  hooks.json         # { "modules": ["./register.tsx"] }
  register.tsx       # your mod logic

hooks/register.tsx exports a single function:

export function register(on) {
  on('tool.call', { tool: 'Bash' }, async (event, next) => {
    // intercept, rewrite, or deny — then call next() to continue
    return next(event);
  });
}

The four events that matter: tool.call (any tool the agent invokes), prompt.submit (fires before the prompt sends), prompt.compose (rewrite the system prompt), and ui.render (redraw any UI component). Install with /plugin install path/to/your/plugin in the CLI or desktop app.

Build Your First Useful Mod: Destructive Command Guard #

The most practical first mod is a guard that intercepts destructive Bash commands before they execute. The community shipped this within hours of launch, and engineering teams are already adopting it for governance.

// hooks/register.tsx
export function register(on) {
  on('tool.call', { tool: 'Bash' }, async (event, next) => {
    const cmd = event.input.command ?? '';
    const dangerous = /rm\s+-rf|DROP\s+TABLE|git\s+push\s+--force/.test(cmd);

    if (dangerous) {
      return {
        deny: true,
        reason: `Destructive command detected: "${cmd}". Confirm manually.`,
      };
    }

    return next(event);
  });
}

That is 15 lines. It blocks every rm -rf, force push, and DROP TABLE the agent tries to run and surfaces the command with a reason. Start here. One mod that solves a real problem beats ten experimental ones.

Security: Not Sandboxed #

Mods run with the same access to your machine as Claude Code itself — no sandboxing. The privileged engine interface ($) exposes file reads, shell commands, and network calls. Researchers at Pluto Security found that $.fs.read is not project-scoped: in testing, a mod could read Claude Code’s OAuth credentials and the full prompt history from history.jsonl.

The rule is simple: only install mods from sources you trust, the same way you’d treat any code you run on your machine. On Team and Enterprise plans, a built-in sec-default mod loads first and prevents installed mods from overriding permission deny rules.

What the Community Already Shipped #

Three days after launch: over 40 GitHub repositories, a community catalogue on GitHub, and 50+ MIT-licensed mods with tests. The range is wide — token usage charts, CI status overlays, a “You should know” callout injector for flagging key output details, and a playable Tetris game running in a session pane.

The governance end is more durable. Mods that require confirmation before destructive operations, enforce commit message formats, or surface test failures inline — these are the ones that will stay installed. Browse ExplainX’s curated list of 50 open-source mods to find ones worth adopting now.

Where to Start #

Read the official Anthropic announcement for the canonical architecture overview, then work through the getting started guide on claude.dev for a hands-on walkthrough. The three-file structure takes about five minutes to scaffold, and Claude Code can write the mod for you if you describe what you want — which is a somewhat recursive experience worth having.

Pick one workflow pain point — a command you never want the agent to run unsupervised, a UI element that should surface differently, a tool call you want to log — and build the mod for that. The ecosystem is three days old and already moving fast. The engineering teams that figure out their internal mod stack now will have a real productivity edge within months.

── more in #ai-agents 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/claude-code-mods-wri…] indexed:0 read:4min 2026-10-04 · —