Functions that run inside the agent, not beside it

Anthropic has opened Claude Code to mods: JavaScript or TypeScript functions that run inside the tool’s own process and can watch, rewrite or take over what it does. The company published the documentation and a getting-started guide on 1 October.

A mod registers handlers, which Anthropic calls hooks, against events in the agent loop. When Claude Code is about to use a tool, submit a prompt, draw part of its interface or finish a turn, it calls the handler first, and the handler decides what happens next. It can observe and pass the event along, rewrite it, or answer it itself so the usual behaviour never runs.

That is a different thing from what Claude Code already had. Settings hooks run a shell command, an HTTP request or a prompt from outside. Skills give the model instructions. MCP servers give it tools. A mod runs in the same process as the agent, which is why it can draw a pane beside the transcript, replace the row Claude Code draws for a tool call, or hold a command while it asks the user a question.

Socket wrench bits arranged in rows inside a tool case
A mod can observe an event, rewrite it, or answer it so the usual behaviour never runs. Illustration. Erik Mclean · pexels · Pexels License

What a mod can reach

Anthropic is direct about the trade. Mods are not sandboxed. The documentation’s own warning is that a mod “is code that runs with your permissions”, and the list that follows is not short: it can read and write any file the user’s account can, start programs, make network requests, read environment variables and settings files including an API key, see every prompt and every tool call, rewrite a prompt or submit one as if the user had typed it, approve a tool call before the user is asked, and spend the user’s plan or API key on model calls.

If sandboxing is on, it isolates the Bash commands Claude runs — a process a mod starts runs outside it. A mod that approves tool calls can approve one that an ask rule would have prompted for. The one thing it cannot restyle is the permission prompt itself.

Anthropic’s answer is inspection rather than isolation. Running claude plugin validate on a plugin directory prints which events the mod handles and what it asks Claude Code to do, without running it.

Where this lands

Mods ship as plugins and install from a marketplace, work in the CLI and the Desktop app’s Code tab, and run their hooks in headless and cloud sessions without drawing. They require Claude Code v2.1.287 or later and are on by default; --safe-mode stops them for a session and disableAllHooks stops every installed one.

Cables plugged into the numbered input channels of an audio mixing console
Mods ship as plugins and install from a marketplace. Illustration. 將將 王 · pexels · Pexels License

Some of Claude Code’s own features are already mods, including /diff, and their source is public in the product’s repository. Anthropic also publishes samples: one draws a forecast of context-window use above the prompt, one holds a risky shell command such as rm -rf and shows what it would change, and one steps through the file edits from the last turn.

For organisations, administrators can limit which mods load through managed settings, and a built-in guard protects what the organisation manages from mods a user installs.

The thing to watch is the marketplace. Unsandboxed third-party code with full access to a developer’s machine and session is the same distribution problem browser extensions and npm have had for years, and the answer so far is a validate command and a warning in the docs.