Anthropic just shipped Mods for Claude Code, and the first thing worth knowing is what they are not: sandboxed. A Mod runs with your own system permissions, which means a malicious one can do anything you can do on your machine. Anthropic says as much in its own documentation and advises only installing Mods from sources you trust.
What a Mod Actually Is
A Mod is a plugin written in JavaScript or TypeScript. It attaches to specific events inside Claude Code: tool calls, user prompts, and UI rendering. That covers a wide surface area. Developers can add custom panels to the chat interface, intercept tool calls before they execute, or create entirely new commands.
Anthropic already uses the system internally. The /diff command, among other built-in features, runs as a Mod. That is a reasonable signal that the plugin API was designed with real depth, not tacked on.
️ Trust and Access Controls
There is no platform-level sandbox, so trust management falls to you or your organization. On the enterprise side, IT teams can restrict which Mods are allowed to load, blocking unvetted plugins before they reach a developer’s terminal. For individuals, Anthropic has published sample Mods on GitHub so you can read the code before running anything.
Platform support is not uniform. Mods work in the CLI and the desktop app. The VS Code extension only partially supports them. If VS Code is your primary environment, check what is actually available before you build a workflow that depends on a Mod.
The First Official Mod
Anthropic’s first official Mod is called You Should Know. It runs a separate agent in the background that monitors Claude’s output and fires a “Heads up” message when it spots something important you might have missed.
The plugin is off by default. To enable it, run:
/plugin enable cc-plugin-you-should-know@builtinWorth noting: enabling it adds a second agent that reads everything Claude produces. Factor that into your threat model if you work with sensitive code.
