On October 1, 2026, Anthropic shipped Claude Code mods with version 2.1.287. If you have used plugins and hooks, this is the first release where a plugin can change how Claude Code itself behaves, not just what it can do. Claude Code mods are small TypeScript functions, packaged inside plugins, that hook into the events Claude Code emits while it works. Anthropic's own description: a mod can rewrite a prompt, add new UI, replace a built-in feature, or add entirely new functionality.
This guide explains what changed compared to hooks and plugins, what a mod can actually do, how the trust decision works, and what it means for product teams. Everything here comes from Anthropic's launch post and the Claude Code 2.1.287 release notes.
Key Takeaways
- Claude Code mods, shipped in version 2.1.287, are TypeScript functions inside plugins that run inside Claude Code itself, so a plugin can now change how it behaves.
- Unlike hooks that react from the outside, mods can act before, after, instead of, or around an event, such as rewriting prompts, blocking tool calls or redacting output.
- Mods are not sandboxed and have the same machine access as Claude Code, so treat third-party mods like dependencies: check the author and read the code first.
- On Team and Enterprise plans, the built-in sec-default mod loads first, so user-installed mods cannot bypass your organization's permission denials.
- For product teams, ask Claude to write a CI status band, a confirmation step before risky commands, or a customer data redaction mod, then set who reviews and owns approved mods.
Learn this hands-on
Become a 10x PM by learning how to use Claude Code in your daily work as a Product Manager, through 3 highly efficient live sessions of 1h30. Join the Claude Code for PMs live cohort.
What are Claude Code mods?
A mod is a TypeScript function that lives inside a plugin and listens to the events Claude Code emits as it works: a prompt being submitted, a tool being called, a permission being requested, output coming back. Because the mod runs inside Claude Code itself, it can act before an event, after it, instead of it, or wrap it with code on both sides.
Mods also hot reload in the same session. You change the behavior, and it applies without restarting. Anthropic's framing is that you can pare Claude Code down to a small core and add back only what you want.
The timing is not accidental. The release train from 2.1.280 to 2.1.287 (September 22 to October 1) also made Opus 5.5 the default Opus, Sonnet 5.5 the default Sonnet, and turned ultracode into its own toggle. Mods are the structural change in the same stretch: the product is becoming a platform you configure.
Mods vs hooks vs plugins vs skills
The confusion is understandable, because mods reuse the plugin packaging you already know. The difference is where the code runs and how much control it has.
| What it supplies | Where it runs | Control over the flow | |
|---|---|---|---|
| Skills and commands | Instructions Claude follows | Inside the model's context | None, Claude decides whether to follow them |
| Plugins (before mods) | Instructions, commands, external tools | Alongside Claude Code | Adds capabilities, does not change behavior |
| Hooks | Shell scripts that react to events | Outside Claude Code | Mostly after the fact |
| Mods | TypeScript functions inside a plugin | Inside Claude Code | Before, after, instead of, or around an event |
If you want the background on the first three, start with our guides to Claude Code plugins and the complete guide to Claude Code hooks. The short version: hooks reacted from the outside, while mods sit in the middle of the machinery.
What can a mod do?
Anthropic lists the capabilities by area. Grouped so you can think in terms of outcomes:
Prompts
- Rewrite a prompt before it reaches the model, for example to add house rules or expand a shorthand.
Tool calls
- Block a tool call outright.
- Rewrite a tool call before it runs.
- Retry a tool call.
Permissions
- Approve or deny a permission request automatically, based on your own logic.
Output
- Redact sensitive information from tool output before it goes any further.
Interface
- Edit or replace interface elements.
- Add buttons and interactive inputs, including live panes, bands, a status line and toasts.
One detail matters for teams. When several mods target the same event, they run in load order, so mods from different authors stack. A mod from your platform team and a mod from an individual developer can both apply to the same prompt or tool call.
Built-in features are becoming mods
The most interesting design choice is that some built-in features now ship as mods. Anthropic's example is /diff, which can be disabled or replaced through plugin settings. If you do not like how a built-in behaves, you no longer have to live with it.
Version 2.1.287 also adds a built-in mod called "You should know". A side agent watches your session and flags things you or Claude might miss. You turn it on with:
/plugin enable cc-plugin-you-should-know@builtin
It is available for first-party sessions with telemetry on. It is a good first mod to try, because it shows the model at work: something observing the session and speaking up at the right moment, without you writing a line of code.
How to install a mod or have Claude write one
Mods ship inside plugins, so installation uses the same /plugin flow and the Claude plugin directory you already know. Developers who want to distribute a mod package it as a plugin and submit it.
The more surprising path is writing one. Claude Code can write a mod on request: you describe the behavior, Claude generates the TypeScript, installs it and hot reloads it. A request could be as simple as:
Add a mod that shows a toast whenever a tool call is blocked, and tell me which tool it was.
You do not need to be a TypeScript developer to try this (our first-week guide for non-coding PMs is a good warm-up), but you do need to read what Claude generated before you rely on it, which brings us to trust.
The trust decision
Anthropic is direct about the risk: mods are not sandboxed. They run with the same machine access as Claude Code, so installing a mod is a trust decision, in the same category as installing any software that can read your files and run commands.
Practical consequences:
- Treat a third-party mod like a dependency. Check who wrote it and read the code before you enable it.
- A mod that can rewrite prompts and tool calls can change what Claude does without you seeing it in the conversation.
- Stacking cuts both ways. Mods from different authors run in load order, so the order matters.
On Team and Enterprise plans, there is a guardrail. A built-in security mod named sec-default loads first on managed machines, so user-installed mods cannot bypass permission denials (see also how safe Claude Code auto mode is). If your organization denies a permission, a mod cannot quietly grant it. Anthropic also suggests team mods for CI/CD status displays and confirmation steps, which is the shared, reviewed use case rather than the personal one.
Claude Code mods for product managers
You do not need to write TypeScript to benefit, because Claude can write the mod and your engineers can review it. Three team mods worth asking for:
- A CI status band. A live status line or band that shows whether the build is green while Claude works, so nobody keeps shipping into a red pipeline. Anthropic names CI/CD status displays as a team use case.
- A confirmation step before destructive commands. A mod that pauses and asks for confirmation before certain tool calls run. Anthropic also names confirmation steps as a team use case. This is the guardrail that lets less technical teammates use Claude Code with more confidence.
- A redaction mod for customer data. Since a mod can redact sensitive information from tool output, a product team working near support tickets or analytics exports can keep customer details out of the session. Have security review it, because redaction rules need to be tested, not assumed.
The governance question for Team and Enterprise plans is the real PM work. Who approves a mod before it reaches a shared machine? Who owns it when Claude Code updates? Which behaviors do you want standard across the team, and which stay personal? sec-default protects your permission denials, but it does not decide for you which mods are worth installing.
Product manager and want to work like this? This is exactly what we teach in Claude Code for PMs, our live cohort for product teams: 3 live sessions of 90 minutes over 2 weeks. Every PM ships a real feature, builds their own agent, and gets personalized written feedback.
What to do this week
Start small and keep the blast radius low. If you want the full foundations first, our Claude Code course covers them step by step:
- Update to version 2.1.287 or later and enable "You should know" to see a mod at work.
- Ask Claude to write one tiny, harmless mod, such as a toast or a status line, and read the code it generates.
- Decide, before your team installs anything, who reviews mods and where approved ones live.
Hooks gave you a way to react to Claude Code. Mods give you a way to shape it, and subagents give you a way to delegate to it, so it is worth reading how Claude Code agents and subagents fit alongside. Used with care, mods turn Claude Code from a tool you adopt into a tool your team configures.