Claude Code mods: change Claude Code's rules with TypeScript
Claude Code mods are TypeScript functions that change how Claude Code works. What they can do and the warning: they don't run in a sandbox.
Claude Code mods are small TypeScript functions that change how Claude Code works. Anthropic launched them on October 1, 2026, and they're available in the CLI and the desktop app. They're installed from plugins. The key warning: they don't run in a sandbox and have the same access to your machine as Claude Code.
What Claude Code mods are
A mod is a TypeScript function that hooks into Claude Code and changes its behavior. The core idea: an agent you can't modify is governed by someone else. With mods, instead of waiting for Anthropic, you change the tool yourself.

What a mod can do
According to Anthropic, a mod can:
- Rewrite a prompt before it reaches the model.
- Block, rewrite or retry a tool call before it runs.
- Approve or deny a permission for you.
- Redact secrets from a tool's output before Claude reads it.
- Replace built-in functions and even the interface.
The warning: they aren't isolated
Mods don't run in a sandbox and have the same access to your machine as Claude Code. Install only ones from trusted sources. Anthropic doesn't talk about recommended "official" mods or present them as safe by default; it only recommends installing from trusted sources.
On Team and Enterprise, a mod called sec-default loads first, so user mods can't skip security rules.
How to apply it in your business?
Think of a rule you repeat by hand today: don't delete certain folders, never send keys to the model, ask for confirmation before touching production. That rule can be a mod. Start with a small one, read it fully before installing, and test it on a project with no sensitive data. If your team is on Team or Enterprise, check how it interacts with sec-default. For another Anthropic change in how Claude is used, read the full breakdown of Claude Sonnet 5.5.
Frequently asked questions
What are Claude Code mods?
Small TypeScript functions that change how Claude Code works, launched by Anthropic on October 1, 2026.
Where can I use them?
In the Claude Code CLI and desktop app. They're installed from plugins.
Are mods safe?
They aren't isolated: they don't run in a sandbox and have the same access to your machine as Claude Code. Install only ones from trusted sources.
Can a mod hide my secrets?
According to Anthropic, it can redact secrets from a tool's output before Claude reads it.
What is sec-default?
On Team and Enterprise, a mod that loads first so user mods can't skip security rules.
Conclusion
Claude Code mods give you control over your agent's rules, at the cost that they run without a sandbox. Use them with the same caution as any code you install on your machine.