
Claude Code's new Mods system lets developers rewrite the AI coding tool from the inside
Anthropic has added Mods to Claude Code, a system of JavaScript and TypeScript functions that lets developers change the coding assistant's behavior and interface. The Mods run unsandboxed, so users should install only trusted ones.
Anthropic has released Mods for Claude Code, a plugin-based system that lets developers change how the AI coding assistant looks and behaves. Mods are JavaScript or TypeScript functions that hook into events inside the tool, from tool calls and user prompts to interface rendering, and they are enabled by default in Claude Code 2.1.287 and later. They work in the command-line interface, the desktop app, and partly in the VS Code extension.
Until now developers could customize Claude Code through settings, CLAUDE.md instructions, hooks and MCP servers, but those mechanisms could not change the tool's own features or interface. A Mod can rewrite a prompt before it reaches the model, block or rewrite a tool call, handle permission requests, replace parts of the interface, or add new functionality. Anthropic says some built-in features, including the /diff command and AGENTS.md support, are already implemented as Mods.
What developers are building
In a technical blog post accompanying the launch, Anthropic staff member Addy Osmani walked through a roughly 80-line Mod called Token Weather. It tracks how much of Claude's context window has been consumed and displays the result in a band above the prompt: at 18% of a 200,000-token window it shows “Clear”, at 67% “Showers”, at 81% “Storm”. Within hours of the announcement a developer had already built a Mod that passes credentials to Claude without leaving the secret in the conversation history.
The first official Mod plugin is “You Should Know”, which spins up a separate agent that watches Claude's output and sends a “Heads up” message when it spots information users might have missed. It can be enabled with the command /plugin enable cc-plugin-you-should-know@builtin. Claude Code creator Boris Cherny described the thinking behind the feature on X: “Each person works differently, so there's no reason why everyone should have an identical Claude experience.”
The security caveat
Mods are distributed as plugins and run with the user's permissions, unsandboxed, so their code executes locally with access to the developer's machine. Anthropic advises users to inspect the source and install only from trusted publishers. Organizations can control which Mods are allowed to load; for Team and Enterprise users, Anthropic's sec-default guard loads ahead of user-installed Mods and by default stops them from overriding permission-deny rules. Outside those guarded environments, Mods can still override some permission decisions.
Anthropic first floated the idea on GitHub on September 3, still under the name “function hooks”. Six days later the company said it would ship the feature as “Claude Mods”. Mods are available now in the CLI and desktop app and can be shared through plugin marketplaces, including GitHub repositories.
Sources: The Decoder · The New Stack
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.