Anthropic has opened Claude Code to "mods": small JavaScript or TypeScript functions that can change how the coding agent behaves, shipped inside plugins and installed with the same /plugin flow developers already use.

Earlier customisation in Claude Code came through hooks, which could react to events. Mods go further. According to Anthropic's documentation, a mod can rewrite prompts before they reach the model, block or retry tool calls, decide permissions, redact secrets, add or replace interface elements, and even replace built-in features. A mod's hooks run in every kind of session that loads the plugin — it is not an opt-in per task.

In effect, Claude Code stops being only a tool you configure and becomes a runtime you program. Teams can enforce policy inside the agent loop: stripping credentials before they leave the machine, refusing risky shell commands, forcing a review step before a write, or reshaping the interface so it matches their own workflow.

The same capability is a new attack surface. Mods ship inside plugins, and a plugin's hooks execute with the session's privileges — so reviewing third-party mods before installing them is now a security requirement, not a nicety. Anthropic's reference notes that hooks and mods API calls run under time and size limits: an over-long hook is skipped and an oversized call rejected. Developers can also build custom UI and pin commands.

The move fits a broader pattern in agent tooling this year, where vendors compete on how much of the agent's control loop they let customers rewire. It also raises an uncomfortable question for enterprises: if anyone can publish a plugin that silently rewrites prompts or reroutes tool calls, who is auditing the marketplace?