Skip to content
Home » Claude Code Mods: What Changed, Who It Affects, How to…

Claude Code Mods: What Changed, Who It Affects, How to…

Anthropic moved the extension point inside the model loop

Classic shell hooks sit outside the agent. They intercept a command, run a script, and hand control back. Mods do something structurally different. A mod is a TypeScript plugin that registers event handlers — called hooks — directly inside the Claude Code harness: the software layer that assembles context, calls tools, and renders sessions. That in-process position is the change worth understanding.

Anthropic shipped four built-in mods in the public repository as of September 14, 2026: an agents.md loader, a diff panel, a telemetry mod, and an organization security mod called sec-default. Custom mods remain early access, gated behind the environment variable CLAUDE_CODE_ENABLE_FUNCTION_HOOKS=1.

Why Anthropic built a new extension layer

Classic hooks already execute configured logic at supported lifecycle events and can make decisions before applicable actions. The difference Mods introduce is composition. As the Wavect editorial team explains: “Mods use function-based composition around engine events and supported UI surfaces. Prefer a classic hook when it already satisfies the requirement.”

Classic hooks are conditionals. Mods are wrappers. A mod can intercept tool output before it reaches the model, mutate the prompt, update a side panel in real time, or maintain persistent state across a session — a wider surface area, and a wider risk profile.

The agents.md support that landed in Claude Code version 2.1.277 on September 18, 2026 illustrates the difference concretely. According to the MindStudio editorial team, the mod “changes interface components and filters tool output before it ever reaches the model.” That filtering step — between tool call and model response — is not available to a classic hook. agents.md support is not yet available on Bedrock, Vertex, or Foundry.

Who this affects right now

Team and Enterprise administrators should review the sec-default mod. It seats itself outermost on machines with managed settings unless prependPlugins specifies otherwise — per the README published September 14, 2026. When allowManagedHooksOnly is set to true, user, project, and local hooks — plus hooks from non-force-enabled plugins and hooks declared in agent frontmatter — are all blocked. That is a meaningful control lever for regulated environments, but it requires deliberate configuration; it does not activate automatically.

Platform engineers building on Claude Code need to understand execution order. On any given event, managed settings hooks run first, then mods, then remaining settings hooks. A deny from a managed hook stops the call before any mod runs. When several mods hook the same operation, they nest in registration order, with managed plugins an administrator prepends on the outside.

Security teams need to treat a mod as a first-class threat surface. A mod sits in-process on the path between user intent, model decisions, and host execution, with persistent state and broad access to tools, files, processes, prompts, and UI. Dash Security’s analysis frames this directly: the attack surface is built in, not bolted on.

What a mod can and cannot do today

A mod has three components: a .claude-plugin/plugin.json manifest, a hooks/hooks.json file naming the module, and TypeScript source under hooks/, typed against declarations in types/. Load it from source with claude --plugin-dir mods/diff. The diff mod provides a /diff command that displays uncommitted session changes in a pane beside the transcript, refreshed as Claude edits files and runs commands.

The maturity floor matters more than the capability ceiling here. As noted by Vox on X: “Mods are still in early access, and their APIs may change.” Custom mod development requires the feature flag. The built-ins are stable; the extension surface is not yet committed.

That distinction is consequential for production tooling. The four built-in mods are reasonable to depend on today. A custom mod that wraps a critical tool call or filters sensitive output is an early-access dependency — treat it accordingly in your change management process, which means versioning it, documenting the flag dependency, and planning for API changes.

Classic hooks are still the right default

Not every team needs Mods. If your requirement is “run this script before a tool executes,” a classic hook satisfies it without the in-process surface area. The Wavect guidance is worth taking at face value: prefer a classic hook when it already satisfies the requirement. Mods earn their complexity when you need to filter model-bound data, maintain session state, or extend the UI — not for simple pre/post execution logic. Teams that reach for Mods unnecessarily take on early-access API risk and a broader attack surface for no functional gain.

For teams running Claude Code at scale, the practical sequence is: audit which hooks are currently in use, confirm whether any developer has already enabled CLAUDE_CODE_ENABLE_FUNCTION_HOOKS=1, and decide whether sec-default belongs in managed settings before custom mods proliferate. The flag spreads faster than policy.


Eagentix helps growth-focused enterprises redesign and automate manual business processes. We combine executive strategy, implementation support, and managed services to build dependable operations across Southeast Asia.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *