Claude Code now supports Mods: powerful, unsandboxed plugins

A computer screen displaying the WordPress plugin installation page with various software options

Anthropic just shipped Mods for Claude Code, and the first thing worth knowing is what they are not: sandboxed. A Mod runs with your own system permissions, which means a malicious one can do anything you can do on your machine. Anthropic says as much in its own documentation and advises only installing Mods from sources you trust.

What a Mod Actually Is

A Mod is a plugin written in JavaScript or TypeScript. It attaches to specific events inside Claude Code: tool calls, user prompts, and UI rendering. That covers a wide surface area. Developers can add custom panels to the chat interface, intercept tool calls before they execute, or create entirely new commands.

Anthropic already uses the system internally. The /diff command, among other built-in features, runs as a Mod. That is a reasonable signal that the plugin API was designed with real depth, not tacked on.

️ Trust and Access Controls

There is no platform-level sandbox, so trust management falls to you or your organization. On the enterprise side, IT teams can restrict which Mods are allowed to load, blocking unvetted plugins before they reach a developer’s terminal. For individuals, Anthropic has published sample Mods on GitHub so you can read the code before running anything.

Platform support is not uniform. Mods work in the CLI and the desktop app. The VS Code extension only partially supports them. If VS Code is your primary environment, check what is actually available before you build a workflow that depends on a Mod.

The First Official Mod

Anthropic’s first official Mod is called You Should Know. It runs a separate agent in the background that monitors Claude’s output and fires a “Heads up” message when it spots something important you might have missed.

The plugin is off by default. To enable it, run:

/plugin enable cc-plugin-you-should-know@builtin

Worth noting: enabling it adds a second agent that reads everything Claude produces. Factor that into your threat model if you work with sensitive code.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo