← all articles

are claude code mods safe?

as of october 2026, claude code mods are useful and not sandboxed. anthropic announced them on october 1, 2026 and said they run with the same access to your machine as claude code itself. so the short answer to are claude code mods safe is: yes from authors and marketplaces you already trust, no as a casual browse and install habit.

judgement: treat every mod like a package you would install on your laptop. if you would not run that author's code with your shell open, do not load their mod.

what are claude code mods?

mods are small typescript or javascript functions that change how claude code behaves and looks.

anthropic shipped the feature through its claude product surface. the launch post describes a mod as a function that can rewrite a prompt, add new ui, replace a built in feature, or add new functionality. each mod ships inside claude code plugins, so you install and share it like any other plugin. they work in the claude code cli and in the desktop app. see the mods overview for the full event list.

the design sat in public for almost a month before launch. anthropic opened github issue 91870 on september 3, 2026, then confirmed the product name "claude mods" in a september 9, 2026 community update. the same issue marked the feature live on october 1, 2026.

press coverage the same day, including cryptobriefing, mainly repeated the first party claims. for decisions, stick to the launch post and the docs.

are claude code mods sandboxed?

claude code mods are not sandboxed, and anthropic says so in plain language on the launch post.

the launch post's trust line is short: "They aren't sandboxed". the mods overview goes further. once loaded, a mod can act on your machine as you, read secrets from environment variables and settings, see every prompt and tool call, rewrite a prompt or tool call, approve a tool call before you are asked, and spend usage on your plan or api key.

if you turn on bash sandboxing, that sandbox isolates bash commands claude runs. a process a mod starts runs outside it. that is why anthropic tells you to install mods only from authors and marketplaces you trust, the same way you would install any code on your computer.

before you install one, the docs want you to run claude plugin validate on the plugin directory. the output lists hooks: and calls: so you can see which events it handles and what it asks claude code to do, without running it first.

for the broader pattern of agents that can both read and act, see is it safe to let ai see your screen and what is prompt injection.

how do mods differ from hooks?

claude code hooks vs mods is not a rename: settings hooks still matter, and they still cannot do what mods do.

anthropic's own contrast is the cleanest table:

capabilitysettings hookmod
runs whereoutside claude code (shell, http, or prompt)inside claude code as a function
rewrite a prompt or tool calllimitedyes
draw or replace uinoyes
replace a built in featurenoyes
keep shared state across eventsweak (separate processes)yes, in process
install pathsettings fileplugin via /plugin or directory

a mod hooks events such as tool calls, submitted prompts, and interface draws. it can run before, after, instead of, or around the event. when several mods hook the same event, they run in load order. the first mod to load sees the event first and the result last.

some built in features already ship as mods. the built in /diff command is now a mod, so you can turn it off in /plugin or replace it with your own version. anthropic says it plans to move more built in features to mods over time. the public source for several of those, including diff and sec-default, lives under github.com/anthropics/claude-code/tree/main/mods.

if you already use skills or an mcp server, keep them. mods sit beside those tools, not above them. for what an agent is doing in the first place, see what is an ai agent.

what can a team admin control?

team and enterprise plans get the controls that make wide install less scary.

admins can allow or block plugin marketplaces from the admin console. on claude api and third party api plans, admins push managed settings to users' machines instead. on team and enterprise plans, and on any machine with managed settings, the sec-default claude code guard loads first as a built in mod. it stops mods that users install from doing risky things such as overriding your permission deny rules.

you can read what sec-default restricts in the public sec-default source. admins can load their own mods first instead. if they do, anthropic says to add sec-default to that list so its restrictions stay.

team examples anthropic lists:

  • a mod that shows ci status beside the conversation
  • a mod that requires confirmation before a command touches production config
  • an audit mod that loads first and records every call other mods make

docs also say mods need claude code v2.1.287 or later. they are on by default on that build. to stop every installed mod for one session, start with --safe-mode. to stop them in every session, set "disableAllHooks": true in ~/.claude/settings.json (that also stops settings hooks and a custom status line). built in mods such as /diff and sec-default stay loaded under those user facing kill switches, per the overview docs.

should you install a third party mod today?

install your own, or ones from people you already trust. skip the rest until you have reviewed them. that is also the honest answer to should you install claude code mods from a stranger's gist.

addy osmani's october 1, 2026 guide builds a first mod of about 80 lines, then tours three samples anthropic shares for learning: token weather, blast radius, and replay theater.

token weather paints a forecast band with cutoffs at 25%, 50%, 75%, and 90% of the context window, plus a sparkline of the last 12 turns. the guide's own recording shows the band move through 18%, then 67%, then 81% as a session fills a 200k window.

blast radius holds risky bash and shows what it would change. replay theater steps through the last turn's file edits. those samples live in the claude code playground repo as complete plugins. they still run with your permissions. the guide also notes a hook gets 10 seconds of its own time per dispatch, and that time spent waiting inside a $ call does not count against that budget.

a practical checklist before /plugin install:

  1. confirm you are on claude code v2.1.287 or later
  2. prefer first party, org marketplace, or authors you already trust
  3. clone or download the plugin and run claude plugin validate on it
  4. read the hooks: and calls: lines for file, process, network, and permission power
  5. on a work machine, check that sec-default or your admin prepend list is actually loading
  6. disable or uninstall from /plugin the moment behaviour looks wrong

should you install claude code mods on a personal laptop for a toy ui tweak from a stranger? in our view, no. should you install a team owned mod that redacts secrets or gates production commands? yes, that is the point of the feature.

for mac workflows where an agent sits next to your real screen history, see computer use agents on a mac and ai coding agent memory of your work.

verdict: as of october 2026, claude code mods are a real extensibility layer, shipped openly after the september 3, 2026 design thread, and safe only under the same trust rules you already use for plugins and packages. the missing sandbox is the feature, not a bug in the writeup. if a sample mod is reading 90% of your context window and approving bash for you, that is power you granted, not a side effect.

keep your own work context while you mod the harness

mods change the agent harness, not the trail of work you already did on screen.

remynd is a mac app for that trail. it captures the focused window, runs ocr locally with apple vision, and keeps a searchable index on your mac. you can exclude apps and sites, and history is kept for 30 days by default. call transcription runs on device with mlx.

the agent window runs your own claude code or codex cli against that history with read only access. settings accept a custom api endpoint compatible with the openai responses api. when you swap a mod in or out, the archive of your own work does not have to move with it.

download remynd for mac and keep the next plugin install from wiping the context your agent still cannot see.

common questions

are claude code mods safe? +
only if you treat them like code you install yourself. anthropic's october 1, 2026 launch post says mods are not sandboxed and run with the same machine access as claude code, so install them only from sources you trust and review what they hook before you load one.
what is a claude code mod? +
a small typescript or javascript function that runs inside claude code when an event fires. it can rewrite a prompt, change a tool call, draw ui, replace a built in feature, or add new behaviour, and it ships inside a plugin you install with /plugin or from the claude directory.
how are mods different from hooks? +
settings hooks run a shell command, http call, or prompt on a lifecycle event from outside the process. mods run as functions inside claude code, so they can rewrite events, draw interface, and replace features that hooks cannot touch.
can my company block unsafe mods? +
yes on team and enterprise plans. admins can allow or block plugin marketplaces, and a built in mod called sec-default loads first to stop user installed mods from risky overrides of permission deny rules. admins can also load their own mods first.
do i need a new claude code version for mods? +
yes. anthropic's docs say mods need claude code v2.1.287 or later, and they are on by default on that build. that same build ignores the early access env flag `CLAUDE_CODE_ENABLE_FUNCTION_HOOKS`, so setting it to 0 does not keep mods off.