Your Editor, Rewritten at Runtime: Anthropic Opens Claude Code Itself With TypeScript Mods
Anthropic's new mods turn Claude Code inside out — small TypeScript functions can now rewrite prompts, block tool calls, redact secrets, and redraw the UI, with built-in features like /diff already converted to mods.
For two years, the implicit bargain of AI coding agents was simple: the company owns the harness, and you own the prompt. You could configure, you could nudge, and — if you were ambitious — you could wire up hooks that fired on lifecycle events, but the actual machine that assembled context, routed tools, and drew the terminal interface remained a black box you rented rather than owned.
That bargain just changed. On October 1, 2026, Anthropic introduced mods for Claude Code: small TypeScript functions that change how the agent works at runtime. A mod can rewrite a prompt before it reaches the model, block or retry a tool call, approve or deny a permission request, redact secrets from tool output before Claude ever reads them, or outright replace a built-in feature. Mods can also redraw the interface itself — editing tool results, injecting buttons and inputs, and responding when users press them. They ship inside plugins, install through the existing /plugin flow, and work in both the Claude Code CLI and the desktop app.
What mods actually are
The mechanics are deceptively simple. Every time Claude Code does something — call a tool, ask for permission, draw part of the screen — it emits an event. A mod is a function that hooks into one of these events, and it can run before the event, after it, instead of it, or wrap it entirely, executing code on both sides of the call.
That last distinction is where the power lives. In one function, a mod can:
- Rewrite a prompt before it reaches the model — injecting style guides, stripping ambient context, or enforcing output contracts
- Block, rewrite, or retry a tool call — say, forcing every
rmthrough a dry-run first - Approve or deny a permission request programmatically — implementing company policy instead of clicking “yes” for the hundredth time
- Redact secrets from tool output before Claude reads them — so a leaked
.envnever enters the model’s context window at all
When several mods hook the same event, they run in the order they load: the first mod loaded sees the event first and the result last. That ordering is what makes mod stacking compositional — a security mod from your platform team can load ahead of a convenience mod from an open-source author, and the security boundary holds.
The UI dimension is equally unusual. A mod can edit or replace parts of the interface Claude Code draws — a tool result, a question from Claude — and add buttons and inputs that other mods can respond to. Today a mod can target the terminal, the desktop app, or both. That is a level of malleability rarely offered outside genuinely open-source editors.
The kernel shrinks
Perhaps the most consequential detail is buried mid-announcement: some built-in features of Claude Code now ship as mods themselves. The /diff feature is the first example — it is now a mod, which means you can turn it off in /plugin or replace it with your own implementation. Anthropic says it plans to move more built-in features to mods over time, “so you can pare Claude Code down to a small core and add back only what you want.”
This is a quiet architectural statement. The product is being refactored toward a small kernel plus an ecosystem of replaceable parts — closer in spirit to Emacs or Neovim than to a sealed SaaS console. For a company whose coding agent is reportedly a multi-billion-dollar revenue line, choosing to make the harness user-programmable rather than merely user-configurable is a notable strategic bet: the moat shifts from controlling the interface to running the best model underneath it.
“Not sandboxed” — the honest caveat
Anthropic is unusually direct about the risk model: “Mods run with the same access to your machine as Claude Code itself. They aren’t sandboxed, and you should only install mods from sources you trust, the same way you’d install any code on your computer.”
That candor is warranted. A plugin ecosystem for an agent that can execute shell commands is a supply-chain attack surface with a fresh topology — a malicious mod doesn’t need to exploit anything, because hooking the right event is the exploit. The enterprise story addresses this: admins can allow or block plugin marketplaces from the admin console on Team and Enterprise plans, or push managed settings to users’ machines on API plans. A built-in mod called sec-default (“security default”) loads first on managed machines and stops user-installed mods from doing risky things like overriding permission deny rules — and Anthropic has published its source so admins can see exactly what it restricts.
The reference team use cases read like an answer to the obvious “what would a platform team actually do with this” question: a mod that shows CI/CD pipeline status in a pane beside the conversation, a mod that requires confirmation before any command touches production config, and an audit-logging mod that loads first and records every call every other mod makes.
From hooks to mods
Context matters here. Anthropic’s hooks — user-defined shell commands triggered by lifecycle events — gave developers a taste of deterministic control, and the community built extensively on them: marketplaces of ready-made hook plugins, guides to all 23 hook types, auto-formatting pipelines. But hooks, as Anthropic now acknowledges, “can’t rewrite events, draw new UI, or replace features. Mods can.”
The through-line is visible in the product’s own documentation, which notes that existing hooks “keep working alongside mods” — this is an extension of the extensibility model, not a replacement of it. Notably, Anthropic says it shared the mods design on GitHub before launch to gather developer feedback, an open-design gesture more common in foundation projects than in commercial agent harnesses.
There’s also a self-referential flourish that doubles as a productivity claim: you can use Claude Code to mod Claude Code. Ask the agent to create a mod and it will write the TypeScript, install it, and hot-reload it into your live session — the tool building improvements to itself while you watch.
Why it matters
The coding-agent market has converged on a familiar stack: a strong frontier model, a harness with agentic scaffolding, connectors, and permission systems. Differentiation at the model layer is expensive and cyclical; differentiation at the harness layer has mostly been feature-checklist warfare. Mods move the competition somewhere else entirely — toward whose agent can become the best platform.
If the bet pays off, the consequences compound: an ecosystem of team-specific mods becomes switching cost in reverse (your extensions are portable TypeScript, not proprietary config), the community audits and hardens the harness for free, and Anthropic learns from thousands of bespoke reimplementations of /diff which features deserve to be pulled back into the core. If it doesn’t, mods remain a power-user niche while the sealed-harness competitors iterate faster on defaults.
Either way, the announcement redraws a line that had seemed fixed. The harness is no longer off-limits — it’s an API. For developers who have spent two years working around their tools rather than inside them, that is the actual news: Claude Code is now, in a meaningful sense, yours to rewrite.