Anthropic’s new Mods system for Claude Code runs with your permissions and no sandbox. That one detail matters more than anything else in the announcement, and Anthropic itself warns users to install Mods only from trusted sources.
Mods work as middleware that runs directly inside Claude Code. They’re plugins that let developers change how the tool looks and how it works.
What a Mod can touch
Each Mod is a JavaScript or TypeScript function that hooks into specific events. Those events include tool calls, user prompts and UI rendering.
In practice, a developer can add custom panels next to the chat, intercept tool calls or wire up entirely new commands. That’s deep access for an add-on system.
Anthropic is using the system itself. Some built-in features, including the /diff command, are already built as Mods, the company said. A company building its own features on a plugin API suggests that API wasn’t added at the last minute.
The trust problem is yours to manage
No sandbox means a Mod can do whatever you can do on your machine. Sample Mods are on GitHub, which gives you a starting point you can read before running anything.
Companies get a guardrail. Organizations can control which Mods are allowed to load, so an IT team can block an unvetted plugin before it reaches a developer’s terminal.
Support isn’t equal everywhere. Mods work in the CLI and the desktop app but only partly in the VS Code extension. If VS Code is where you spend your day, check what’s supported before you build around a Mod.
The first official Mod watches Claude for you
The first official Mod plugin is called “You Should Know.” It starts a separate agent that watches Claude’s output and sends a “Heads up” message when it spots important information users might have missed.
It’s off by default. To try it, type /plugin enable cc-plugin-you-should-know@builtin and keep in mind that this adds a second agent reading everything Claude produces.
