Skip to main content

Claude Code now accepts mods: what are they for, and what's the risk?


Do you remember the Skyrim or Minecraft mods? Those little additions written by players that change everything in a game, from the textures to the rules? Well, since October 1, Claude Code has its own. Anthropic calls them mods, and frankly, it's the nicest new feature I've seen in this tool in weeks!

A mod is a small function written in TypeScript (JavaScript with types) that plugs itself inside Claude Code and changes what it does. Anthropic sums it up in one sentence: a mod can “rewrite a prompt, add interface, replace an existing function or add a brand-new one”. It works in the terminal AND in the desktop app.

In a garage, a very well-behaved little beige family car is getting a huge rear spoiler, chrome wheels and blue neon lighting under the body, while a mechanic in blue work clothes tightens one last bolt with a big smile

Claude Code straight from the factory, and Claude Code after a trip to the garage

What my hooks couldn't do

I've been tinkering with Claude Code for months using what are called “hooks”, little scripts that trigger at certain moments. I've got one, for example, that forbids the agent from reading my password files. It works very well. But a hook is a bouncer: it can say yes, it can say no, it can add a remark. It can't rewrite what the agent is about to do, it can't draw anything on the screen, and it can't replace a Claude Code function with its own.

A mod can. Every time Claude Code does something, call a tool, ask for permission, display part of the screen, it emits an “event”. And your mod can position itself in four places around this event: before, after, instead, or all around it.

Diagram of the four ways a mod plugs into a Claude Code event: before, it goes first and can modify or block it; after, it acts on the result; instead, it completely replaces the original function; all around, it acts both before and after

Before, after, instead, all around. Hooks only got the first slot

Concretely, Anthropic gives these examples: rewrite a prompt before it goes to the model, block, rewrite or relaunch a tool call, accept or refuse a permission request, and above all hide secrets in what a tool returns before Claude even reads it. That last point is exactly what my hook does halfway. It stops the agent from opening the file. A mod could let the file through by simply replacing the passwords with asterisks.

What it looks like

Based on the first examples published by developers, a mod plugs in with an on function, a bit like “middleware” on a web server, meaning a link that you slide into the chain and that chooses whether or not to let things through. Here's the idea, for a safeguard that refuses any command that touches an .env file:

on("tool.call", { tool: "Bash" }, async ($, e, next) => {
  if (String(e.command ?? "").includes(".env")) {
    return { deny: "Pas touche à mes secrets" };
  }
  return next(e);
});

The $ gives access to files, the network, the interface and processes. The e is the event. And next means “I let it pass to the next one.” If several mods listen to the same event, they run in the order in which they were loaded.

And the funniest thing is that you don't even need to write all that yourself. You can ask Claude Code to create the mod: it writes the TypeScript, installs it and hot-reloads it, without restarting your session. Anthropic has already turned one of its own functions, /diff, into a mod that you can disable or replace with your own, and says that others will follow. Less than 24 hours after the announcement, someone was already playing Tetris in a Claude Code session. Obviously!

What I'm going to do with it

I've already created my own status line, at the bottom of the screen, which constantly displays my remaining quota and what the session is costing me.

My status bar in Claude Code: session quota at 7%, weekly quota at 21%, session cost at 3.61 dollars and six modified files

And my wish list is still long. A mod that hides secrets instead of blocking the entire file. And one that asks me for confirmation before any command that deletes files in bulk, with a summary of what is going to disappear. A developer has actually published one like that, which measures the possible damage of a command before letting it run.

That's where I find the idea really smart. Anthropic is stopping trying to make one perfect tool for everyone. Everyone makes their own. My Claude Code won't look like yours, and that's just fine.

Where to start, if you use Claude Code

Three steps, and you're off.

  • Update Claude Code. According to the first reports from developers, you need at least version 2.1.287, and mods are then enabled by default. The claude --version command tells you where you stand.
  • Type /plugin in a session. That's where you install, enable or disable mods, including the one that manages /diff.
  • Simply ask it for what you want, in French: “create a mod that asks me for confirmation before any command that deletes files”. It writes and installs it. Then read what it wrote before trusting it, you'll see why.

And if you don't code, it still concerns you a little. The developers who make the apps you use will be able to put their own guardrails on the agent that writes their code. For example, stopping it from touching the customer database or sending anything outside the company. An agent kept on a tighter leash means fewer nasty surprises further down the line.

The downside: a mod has the keys to the house

Right, now for the part that gets people annoyed, and Anthropic writes it itself in black and white: mods aren't locked in a sandbox. They run in the same program as Claude Code, with exactly the same rights on your machine. A mod can read your files, run commands, rewrite your prompts and even accept permissions on your behalf.

On the doorstep of a front door, a smiling woman is holding out a huge bunch of keys to an unknown man in a cap and sunglasses whom she clearly does not know, and he is enthusiastically reaching out his hand

Installing a mod from a stranger, that's more or less it

Just yesterday, I was telling you how malicious code had turned programming assistants against their owners to make them rummage through the computer. A malicious mod wouldn't even need that trick: it's already inside. Anthropic's rule is simple, and I sign off on it: only install a mod from a source you trust, exactly like any program. On the business side, the Team and Enterprise plans load a built-in security mod first, which prevents the others from overriding an authorization refusal. For individuals, it's up to you to sort things out.

We've already seen that Claude Code's permissions could have blind spots. With mods, the door becomes even bigger. That's the price of freedom.

I'm going to have fun like a kid, but with my own mods, which I'll have read line by line. And to the clever little guy who has already put Tetris in Claude Code: bravo! And rest assured, a mod runs on your machine and costs nothing by itself, Tetris included. But keep an eye on your quota: as soon as a mod adds text to what gets sent to Claude, or you ask Claude to write it for you, that's when it starts nibbling away at it!

Sources

Article written with the help of Claude Code, proofread and corrected by me.

Join the conversation

You need an account to comment on this article. Creating one is free and takes under a minute.

  • The XMLTV file, free to download every day
  • Comment on articles and reply to other readers
  • Get an e-mail when an article you follow is updated

No comments yet.

Une erreur s'est produite. Cette application peut ne plus répondre jusqu'à ce qu'elle soit rechargée.Veuillez contacter l'auteur. Reload 🗙