Anthropic Adds Claude Code Mods That Can Rewrite Prompts and Replace Built-In Features
The extensions go beyond existing hooks, reaching permission decisions and interface changes. They also inherit Claude Code’s access to the user’s machine.
Loading page…
The extensions go beyond existing hooks, reaching permission decisions and interface changes. They also inherit Claude Code’s access to the user’s machine.
Listen to this story
Anthropic introduced Claude Code Mods on Oct. 1, 2026, creating an extension layer that can replace built-in behavior, not just respond to events. Anthropic has already shifted /diff into the system, while its plan to move more features could let users assemble a smaller, customized core. The added control comes with a security tradeoff: mods inherit Claude Code’s machine access, though organization marketplace restrictions remain and managed installations load a protective sec-default mod first.
Mods are small TypeScript functions that can run before, after, instead of, or around tool calls, permission requests, and screen-rendering events.
They can rewrite or retry tool calls, approve or deny permission requests, remove secrets from tool output, and add interface controls.
The built-in /diff feature is the first moved into mods; users can disable it through /plugin or substitute their own version.
Developers can now change what Claude Code does before a prompt reaches the model or a tool call runs. Anthropic introduced Mods on October 1, 2026, letting extensions rewrite agent behavior and replace interface features. The tradeoff is substantial: mods inherit Claude Code’s machine access rather than running in an isolated sandbox.
The difference from existing hooks is not simply more customization options. Anthropic says hooks could not rewrite events, draw new interface elements or replace features. Mods can do all three, giving developers a way to change the coding agent without waiting for Anthropic to build each requested feature.
A mod is a small TypeScript function, a piece of code that attaches to events inside Claude Code. Those events include tool calls, permission requests and screen rendering. The function can run before an event, after it, instead of it, or around it—with code executing both before and after.
That lets a developer block, rewrite or retry a tool call, approve or deny a permission request, or remove secrets from tool output before Claude reads it. Interface changes can reach a displayed tool result or a question from Claude, with added buttons and inputs that other mods can respond to.
Anthropic has already moved the built-in /diff feature into the mod system. Users can disable it through /plugin or substitute their own version. The company plans to move more built-in features into mods over time, allowing users to keep a smaller core and add back only what they want.
Mods use the existing plugin packaging and sharing workflow and are available in the command-line interface and desktop app. Users can find plugins containing mods in the Claude directory or through /plugin. Claude Code can also write a mod, install it and reload it into an ongoing session.
The release followed a public design discussion opened on September 3. A September 9 update said developer feedback had materially shaped the design. In an example reported by The Decoder on October 3, the official You Should Know plugin uses a separate agent to flag important information users may have missed in Claude’s output.
Anthropic advises installing mods only from trusted sources, as with other code installed on a computer. For organizations, existing plugin controls still apply: administrators can allow or block marketplaces. Team and Enterprise owners manage that in the admin console; Claude API and third-party API administrators push managed settings to users’ machines.
Load order matters. When several mods attach to one event, the first loaded sees the event first and the result last. On Team and Enterprise plans and managed machines, a built-in sec-default mod loads first. Anthropic says it blocks risky actions such as overriding permission-deny rules. Administrators can put their own mods first, but must retain sec-default in their list to keep its restrictions.
Loading discussion...
Join the conversation
Explain what would make an extension trustworthy enough.
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.