Skip to content

Anthropic Opens Claude Code to TypeScript Mods That Are Not Sandboxed

Anthropic launched Claude Code mods on 1 Oct 2026: TypeScript plugins that can rewrite prompts, tool calls, and UI. They are not sandboxed and ship inside plugins for CLI and desktop.

Anthropic illustration for Claude Code mods: a hand placing a block onto a modular stack

Anthropic has opened Claude Code to third-party TypeScript extensions. On 1 October 2026 the company published an official Claude blog post introducing mods: small TypeScript functions that can rewrite prompts, change tool calls, add UI, or replace built-in features inside the Claude Code CLI and desktop app.

Mods ship inside plugins. You install them the same way you install any Claude Code plugin, and Anthropic says you can also ask Claude Code to write a mod for you and hot-reload it in the same session. That is a real product change, not a blog tease. The catch is security: Anthropic is explicit that mods are not sandboxed and run with the same machine access as Claude Code itself.

For teams already deep into Claude Code, this is the most material UX change since hooks. For everyone else, it is another sign that coding agents are turning into platforms, with the same plugin trust problems that browsers and IDEs already know well.

What Anthropic Actually Shipped

According to the Claude blog post, a mod hooks Claude Code events such as tool calls, permission prompts, and UI draws. A mod can run before an event, after it, instead of it, or wrap it. Concrete examples Anthropic lists include:

  • Rewriting a prompt before it reaches the model
  • Blocking, rewriting, or retrying a tool call
  • Approving or denying a permission request
  • Redacting secrets from tool output before Claude reads it
  • Editing or replacing parts of the terminal or desktop UI, including buttons and inputs

Some built-in features now ship as mods themselves. Anthropic says the built-in /diff feature is now a mod, so users can turn it off in /plugin or replace it. The company says it plans to move more built-ins to mods over time so teams can strip Claude Code down and add back only what they want.

A companion guide published the same day by Addy Osmani on claude.dev dates the launch to 1 Oct 2026 and says mods need Claude Code 2.1.287 or later, with mods on by default. That guide walks through a sample “Token Weather” mod and larger examples such as Blast Radius and Replay Theater.

How Mods Differ From Hooks

Claude Code already had hooks. Anthropic’s own post says hooks were not enough: they could not rewrite events, draw new UI, or replace features. Mods can.

Osmani’s guide frames the technical difference clearly. A settings hook runs a shell command per event and passes JSON over stdin and stdout. A mod loads once, stays in the session, can keep state, draw updating UI, and call back into Claude Code to open panes, run processes, or register slash commands and tools.

When several mods hook the same event, Anthropic says they run in load order. The first mod to load sees the event first and the result last, which lets users stack mods from different authors.

Capability Hooks (prior) Mods (new)
Observe events Yes Yes
Rewrite event data Limited Yes
Replace built-in features No Yes
Custom terminal / desktop UI No Yes
Session state across hot reload No (shell process) Yes ($.state)
Sandboxed from host machine Shell still privileged No; same access as Claude Code

Trust and Enterprise Controls

Anthropic puts the risk up front: “Mods run with the same access to your machine as Claude Code itself. They aren’t sandboxed, and you should only install mods from sources you trust.”

That matters because Claude Code already has broad local power: files, shell, and whatever connectors a team has enabled. A malicious or sloppy mod can rewrite tool calls, approve permissions, or inject UI that looks native. Anthropic’s answer is process and admin policy, not a hard sandbox.

On Team and Enterprise plans, and on machines with managed settings, a built-in mod called sec-default (“security default”) loads first. Anthropic says it stops user-installed mods from doing risky things such as overriding permission deny rules, and that admins can view its source. Admins can also allow or block plugin marketplaces from the admin console. On Claude API and third-party API plans, Anthropic says admins push managed settings to users’ machines.

Enterprise examples Anthropic lists include a CI/CD status pane beside the conversation, a production-config confirmation gate, and an audit-log mod that records every call other mods make.

This sits beside a wider agent-security story. In late September, Glow Labs reported AI coding agents leaking more than 13,000 internal screenshots to public GitHub, including Claude Code workflows. Mods do not create that class of risk by themselves, but they expand the attack surface for anyone who installs untrusted plugin code.

What Developers Can Do Today

Anthropic says mods are available now in the Claude Code CLI and desktop app. Install path: plugins that include mods from the Claude directory, or /plugin in the CLI. To share a mod, package it in a plugin and submit it to the directory.

Osmani’s guide shows the practical floor:

  • A plugin folder with .claude-plugin/plugin.json
  • hooks/hooks.json pointing at one module under modules
  • A module that exports register(on, options) and uses on(event, matcher?, hook)
  • Validation with claude plugin validate and tests with claude plugin test

There is no separate public USD list price for mods themselves. Access tracks whatever Claude Code plan and model usage the developer already pays for. Anthropic’s recent model posts still list Claude Opus 5.5 around US$4 per million input tokens and US$20 per million output tokens (see our Opus 5.5 developer breakdown), and Sonnet 5.5 at US$2 / US$10. Mods do not change those token rates; they change how much local code sits between you and the model.

What It Means for Indian Developers

Claude Code is already common in Indian product and services teams that bill in USD against Anthropic API or Team seats. Mods lower the bar for internal tooling: a Bangalore team can ship a production kubectl guard, a rupee-cost meter on context usage, or a company-specific prompt rewriter without waiting on Anthropic’s roadmap.

The flip side is procurement and security review. Unsandboxed TypeScript that rides inside the coding agent will not pass many enterprise SOC reviews if it comes from a random marketplace. Expect Indian IT services firms and captive GCCs to whitelist private marketplaces, require sec-default plus custom audit mods, and ban public plugin installs on laptops that hold client code. That is workable, but it is not “clone a repo and go.”

Pricing remains USD-first. There is no India-specific mods SKU in the launch posts. Teams should model cost as existing Claude seats plus whatever extra tokens mods cause through longer sessions, more tool loops, or side agents.

What Remains Unclear

Anthropic’s posts do not publish independent security audits of the mods runtime, a CVE process for malicious directory plugins, or performance benchmarks for stacked mods. Claims about how far built-ins will migrate to mods are forward-looking. The sample mods in Osmani’s guide (Token Weather, Blast Radius, Replay Theater) are teaching examples, not shipping guarantees of quality in the public directory.

Also worth separating: this is not a new Claude model release. It is a Claude Code platform feature. Model quality still sits with Opus 5.5, Sonnet 5.5, and whatever Anthropic ships next. For the broader Anthropic enterprise push, see Claude Frontier Academy’s US$100 million training commitment.

Rival agent harnesses are moving too. NVIDIA’s OpenShell and related agent safety work (covered in our OpenShell availability piece) take a different bet: isolate the agent rather than invite more in-process code. Mods go the other way. Both can be right for different threat models.

Frequently Asked Questions

When did Claude Code mods launch?

Anthropic’s Claude blog post introducing mods went live with a 1 October 2026 companion guide on claude.dev. Mods require Claude Code 2.1.287 or later and are on by default, according to that guide.

Are Claude Code mods sandboxed?

No. Anthropic states that mods run with the same access to your machine as Claude Code itself and are not sandboxed. Install only from sources you trust.

Do mods cost extra in USD?

Anthropic has not listed a separate mods price. You pay for the Claude Code / Claude plan and model tokens you already use. Token list prices for recent Claude models remain in USD (for example Opus 5.5 at US$4 / US$20 per million tokens).

How do enterprise admins control mods?

Anthropic says Team and Enterprise owners can allow or block plugin marketplaces in the admin console. A built-in sec-default mod loads first on managed plans to limit risky overrides. API plans use managed settings pushed to machines.

Can Claude Code write its own mods?

Yes, according to Anthropic. You can ask Claude Code to create a mod; it can write the TypeScript, install it, and hot-reload it in the session. That convenience is also why trust controls matter.

Share this article

3 comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Loading the next article…

Continue reading