Anthropic moved the extension point inside the model loop
Classic shell hooks sit outside the agent. They intercept a command, run a script, and hand control back. Mods do something structurally different. A mod is a TypeScript plugin that registers event handlers — called hooks — directly inside the Claude Code harness: the software layer that assembles context, calls tools, and renders sessions. That in-process position is the change worth understanding.
Anthropic shipped four built-in mods in the public repository as of September 14, 2026: an agents.md loader, a diff panel, a telemetry mod, and an organization security mod called sec-default. Custom mods remain early access, gated behind the environment variable CLAUDE_CODE_ENABLE_FUNCTION_HOOKS=1.
Why Anthropic built a new extension layer
Classic hooks already execute configured logic at supported lifecycle events and can make decisions before applicable actions. The difference Mods introduce is composition. As the Wavect editorial team explains: “Mods use function-based composition around engine events and supported UI surfaces. Prefer a classic hook when it already satisfies the requirement.”
Classic hooks are conditionals. Mods are wrappers. A mod can intercept tool output before it reaches the model, mutate the prompt, update a side panel in real time, or maintain persistent state across a session — a wider surface area, and a wider risk profile.
The agents.md support that landed in Claude Code version 2.1.277 on September 18, 2026 illustrates the difference concretely. According to the MindStudio editorial team, the mod “changes interface components and filters tool output before it ever reaches the model.” That filtering step — between tool call and model response — is not available to a classic hook. agents.md support is not yet available on Bedrock, Vertex, or Foundry.
Who this affects right now
Team and Enterprise administrators should review the sec-default mod. It seats itself outermost on machines with managed settings unless prependPlugins specifies otherwise — per the README published September 14, 2026. When allowManagedHooksOnly is set to true, user, project, and local hooks — plus hooks from non-force-enabled plugins and hooks declared in agent frontmatter — are all blocked. That is a meaningful control lever for regulated environments, but it requires deliberate configuration; it does not activate automatically.
Platform engineers building on Claude Code need to understand execution order. On any given event, managed settings hooks run first, then mods, then remaining settings hooks. A deny from a managed hook stops the call before any mod runs. When several mods hook the same operation, they nest in registration order, with managed plugins an administrator prepends on the outside.
Security teams need to treat a mod as a first-class threat surface. A mod sits in-process on the path between user intent, model decisions, and host execution, with persistent state and broad access to tools, files, processes, prompts, and UI. Dash Security’s analysis frames this directly: the attack surface is built in, not bolted on.
What a mod can and cannot do today
A mod has three components: a .claude-plugin/plugin.json manifest, a hooks/hooks.json file naming the module, and TypeScript source under hooks/, typed against declarations in types/. Load it from source with claude --plugin-dir mods/diff. The diff mod provides a /diff command that displays uncommitted session changes in a pane beside the transcript, refreshed as Claude edits files and runs commands.
The maturity floor matters more than the capability ceiling here. As noted by Vox on X: “Mods are still in early access, and their APIs may change.” Custom mod development requires the feature flag. The built-ins are stable; the extension surface is not yet committed.
That distinction is consequential for production tooling. The four built-in mods are reasonable to depend on today. A custom mod that wraps a critical tool call or filters sensitive output is an early-access dependency — treat it accordingly in your change management process, which means versioning it, documenting the flag dependency, and planning for API changes.
Classic hooks are still the right default
Not every team needs Mods. If your requirement is “run this script before a tool executes,” a classic hook satisfies it without the in-process surface area. The Wavect guidance is worth taking at face value: prefer a classic hook when it already satisfies the requirement. Mods earn their complexity when you need to filter model-bound data, maintain session state, or extend the UI — not for simple pre/post execution logic. Teams that reach for Mods unnecessarily take on early-access API risk and a broader attack surface for no functional gain.
For teams running Claude Code at scale, the practical sequence is: audit which hooks are currently in use, confirm whether any developer has already enabled CLAUDE_CODE_ENABLE_FUNCTION_HOOKS=1, and decide whether sec-default belongs in managed settings before custom mods proliferate. The flag spreads faster than policy.
Eagentix helps growth-focused enterprises redesign and automate manual business processes. We combine executive strategy, implementation support, and managed services to build dependable operations across Southeast Asia.
Sources
- – claude-code/mods/README.md at main · anthropics/claude-code · GitHub
- – Claude Mods: the new attack surface built in
- – Claude Code 3.0 (New Mods Feature): Anthropic has…
- – Claude Mods: Setup, Function Hooks and Security | Wavect
- – Claude Code Mods and agents.md: What’s New and Why It Matters | MindStudio
- – Vox on X: “Claude Code is rolling out Mods, so you can ask Claude to add features to itself. A Mod is a plugin that customizes Claude Code’s interface and behavior. Say you’re recording a demo and don’t want sensitive information showing up on screen. Anthropic demonstrated a Mod in Claude Code De… / X
- – All settings – Claude Code Docs
- – Claude Code 3.0 (New Mods Feature): Anthropic has SILENTLY dropped their BIGGEST NEW Feature!
- – Making Mods with Claude Code [FNV] : r/FalloutMods
- – Claude Code Mods for Lawyers: 5 Practical Workflows
- – Mods overview – Claude Code Docs
- – Claude Code Mods Security: 4 Function Hook Risks | Pluto Security
- – Anthropic’s Claude Code Mods Let Developers Rewrite the Agent From Inside | AlphaSignal
- – Getting Claude Code Mods Running in 5 Minutes, and Diagnosing Failures in 1 Minute
- – Morgan Lunt’s Post
- – React to events with a mod – Claude Code Docs
- – Claude Mods | Vanja Petreski
- – Plugins overview – Claude Code Docs
- – Loop Engineering with Claude Code Mods and Plugins
- – Claude Code Changelog on X: “Claude Code CLI 2.1.287 changelog: New features: • Added Claude Mods: plugins may now modify deeper behavior • Added You should know, an opt-in plugin where a side agent watches your back and flags things you or Claude might miss. Turn it on with /plugin enable cc-plug… / X
- – Components of A Coding Agent – by Sebastian Raschka, PhD
- – Deputy Director Strategic Partnering – Civil Service Jobs …
