Claude Code Mods: The Complete Guide + 34 Videos (2026)

30 min readBy Nathan House

On 1 October 2026, Anthropic let anyone rewrite Claude Code from the inside. Claude Code mods can put buttons above the prompt, hold a risky command until you say yes, or swap one of Claude Code's own features for your own. Three days later, one community catalogue listed 1,740 public mods. The guides haven't kept up: many still describe the September preview, and a security report keeps getting retold without its caveats.

So we did the slow version: the official docs, 34 YouTube videos, and our own mods built into HAL, my Claude Code setup. Some worked; one we switched off within a day. Here's what we learned, a copy-paste lab, and every resource compared.

TL;DR: if you've only got 30 seconds

What it is. A small JavaScript or TypeScript file inside a Claude Code plugin that stays loaded all session to watch, change or answer what Claude Code does, and draw on screen. On by default since v2.1.287 (1 Oct 2026).

You don't need to code. Claude writes the mod; you read, validate and test it. Our lab walks you through one.

Use the lightest tool first: an instruction, a setting or status line, a hook, and only then a mod. Hooks can do more than most guides say.

Mods are not sandboxed. A mod runs with your access to files, network and keys, and Anthropic's guard only loads on Team/Enterprise plans or managed machines. Read the code and run claude plugin validate first.

Watch first: Thariq Shihipar (Anthropic) on Latent Space.

How we researched this (3 to 4 Oct 2026)

All ten official docs pages, the changelog and Anthropic's samples; 35 videos transcribed and read (34 about mods); the design thread and the Pluto Security report; 20 community repos checked for licence and calls. Then we built three mods for HAL's daily use. Every figure is as of 4 Oct 2026 unless dated otherwise. On 5 Oct we fact-checked every claim again against the docs and our own captures, and corrected this page.

What Are Claude Code Mods?

Say Claude is about to run rm -rf on a folder. A mod can stop that command, list the files it would delete, and wait for you to press Proceed or Cancel. That's Anthropic's sample mod, blast-radius. Or say Claude has just finished some work: a mod can offer three buttons for the next step. That one's ours.

A mod is a plugin made of small JavaScript or TypeScript functions that run inside Claude Code. (A plugin is the package Claude Code installs: a folder with a small manifest file.) Each function listens for an event, a moment like "Claude wants to run a tool" or "a turn finished" (a turn is one round: you ask, Claude works and answers). When it fires, the mod can let it through, change it first, or answer it itself so the original never runs.

Chase AI has the clearest picture. Take a delete command: a mod can act before it (preview the files), instead of it (send them to the bin), after it (print a receipt) or around it (back up first, so you can undo). His video is in the lab below.

Thariq Shihipar of Anthropic on Latent Space, starting where the mods part begins (34:00; it runs to about 51 minutes). Anthropic hasn't posted its own video about mods (checked 4 Oct 2026), so this is the closest thing: where mods are going, and why forking matters.

What changed on 1 October

Claude Code already had hooks: things it runs at set moments, such as just before a tool runs. A command hook starts, does its job and exits. A mod stays running all session, so it can remember things, keep a live panel on screen, ask you a question with its own options, add slash commands that never call the model, and message other sessions.

But don't over-read it. As Kevin Riedl of wavect put it, "Mods do not invent the ability to stop an action." Hooks could already block. What's new is owning the input and the result in one place, plus the screen.

Anthropic builds its own features this way: /diff, the AGENTS.md loader, a security guard called sec-default and telemetry are built-in mods (an opt-in "You should know" agent is off by default). The built-in plugin-authoring plugin, which teaches Claude to write mods, holds only a skill.

Timeline from 3 September to 3 October 2026 with four dots: the opt-in preview, the 1 October launch in v2.1.287, then 2.1.288 and 2.1.289

From preview to launch: most blogs get the launch date wrong.

Date (2026)What happened
3 to 14 SepPreview. "Function Hooks" shown on X (3 Sep) and usable behind an opt-in flag soon after, renamed "Claude Mods" (9 Sep); "Claude Mods are landing now" (Boris Cherny, 14 Sep).
1 OctLaunch, v2.1.287. @ClaudeDevs: "You can now mod Claude Code" (20.3k likes, 4.3M views by 4 Oct).
2 Octv2.1.288: the first mod fixes, plus $.ui.selection().
3 Octv2.1.289 fixes stale local-marketplace copies, and a mod's approval beating a deny rule on part of a compound command (managed machines).

Not to be confused with

0xDarkMatter/claude-mods (created November 2025), a skills-and-agents kit with session save-and-restore, or posts about AI building mods for video games. A page that predates October 2026 or says to set CLAUDE_CODE_ENABLE_FUNCTION_HOOKS=1 describes the preview or something else.

So when do you actually need a mod? Claude Code already has lighter tools, and picking the right one is most of the skill.

Mods vs Hooks vs Skills vs Plugins

First, the question people search for most: what are hooks in Claude Code? Say you never want Claude to force-push. You write a short script that refuses any command containing --force, and list it in Claude Code's settings file under "before a tool is used". That's a hook. The docs now call it a settings hook (on the mods pages, "hook" means a mod's function), and it can be one of five types: a shell command, an HTTP request, an MCP tool, a prompt to a model, or an agent.

Claude Code hooks are good at a rule that must always hold, checked by a program rather than Claude's judgement. They work unattended, and they have more than a yes or no to give. Before a tool runs, a hook can allow it (skipping the permission prompt, though your own ask and deny rules still apply), deny it, ask you through Claude Code's standard permission prompt, or defer it (that last one works only in a claude -p run driven by another program). It can also rewrite the call before it runs (updatedInput), replace a tool's result, and add context for Claude (additionalContext).

What a hook can't do: draw panes, bands or buttons (it can show text, such as a message or its own spinner text), show you a question with its own choices (its "ask" is the standard permission prompt), or rewrite the text of your prompt. And a command hook starts fresh each time, so it keeps nothing in memory between runs, though it can save state to files.

A wooden crate labelled Plugin holding a skill, a settings hook and a mod, plus commands, agents and MCP servers, while your CLAUDE.md and your status line stand outside it

A plugin is the box that ships skills, settings hooks and mods (plus commands, agents and MCP servers). Your CLAUDE.md and your main status line stay outside it.

Instruction CLAUDE.md, a rule

What it is
Plain words Claude reads
Runs when
Every session, or when called
Shows on screen
No
Costs tokens?
Yes, while in context
Use it when
You want Claude to behave differently
Our example
A rule that ends answers with a summary

Status line

What it is
A script whose output shows under the prompt
Runs when
Every refresh
Shows on screen
One or more lines
Costs tokens?
No
Use it when
Claude Code already hands you the data
Our example
HAL's cache countdown

Settings hook

What it is
A shell command, HTTP request, MCP tool, prompt or agent run at an event
Runs when
Once per event
Shows on screen
Text only: a message or spinner text
Costs tokens?
Prompt and agent hooks, plus any text it adds to Claude's context
Use it when
A rule must always hold; a block or log is enough
Our example
Blocking a force-push

Mod

What it is
JavaScript or TypeScript loaded inside Claude Code
Runs when
Dozens of events, all session
Shows on screen
Bands, panes, buttons, toasts
Costs tokens?
If it calls a model or adds text to Claude's context
Use it when
You need a real exchange, a live display, memory or other sessions
Our example
HAL's next-steps buttons

Skill

What it is
A folder of instructions (SKILL.md)
Runs when
When your request matches, or you call it
Shows on screen
No
Costs tokens?
Its description every turn; the full text once loaded
Use it when
A repeatable process to follow
Our example
Our skill writer

Plugin the box, not a tool

What it is
A package that can ship skills, settings hooks, mods, commands, agents and MCP servers (not a CLAUDE.md or your main status line)
Use it when
You want to share a bundle
Our example
Our private hal-mods plugins

Claude Code plugins vs skills

The short version of Claude Code plugins vs skills: a skill is what Claude should do, in words. A plugin is the box you ship things in, and can hold skills, settings hooks and a mod at once; Anthropic's code-modernization carries shell hooks and a mod in one hooks.json. Mark Kashef's line: "the plugin is the Trojan horse for your specific mod". For skills in depth, see Claude Code Skills: 8 Rules From 17,000 Real Sessions.

Hooks vs mods, side by side

Here's how the two compare, from the docs.

Settings hookMod
Block a commandYesYes
Ask you firstRaises the permission prompt, but anything that answers permission prompts can answer it for youIts own question and options, in Claude Code's question dialog. Rejected in claude -p, and another mod or hook can answer it first
Show you its own choices (e.g. "save as draft")No: its "ask" is the standard permission promptYes
Rewrite a tool call before it runsYes (updatedInput)Yes
Remember things between eventsCommand hooks: no (use files)Yes
Draw, add slash commands, message other sessionsNoYes
If it crashes or times outOn a tool-call guard (PreToolUse): exit 2 is the only exit code that blocks on its own; with valid JSON output the JSON decides (allow, deny, ask). A command, HTTP or MCP-tool hook that crashes without valid JSON, can't start, or times out doesn't block: the call continues through the normal permission flow, where your own ask and deny rules still apply. Other events differ (a timed-out hook on a model switch blocks it).Skipped, so a guard fails open: the call carries on to the next handler and your normal permissions, unless a .catch fallback decides
Unattended runs (claude -p, nobody at the keyboard)Work; "ask" becomes a refusalRun; your fallback decides

The second row matters. A hook's "ask" uses Claude Code's standard permission prompt, so anything set up to answer permission prompts for you, such as an auto-approve hook, can settle it before it reaches you. A mod's question uses Claude Code's question dialog instead. Neither is a guarantee: whatever answers first wins.

The ladder: reach for the lightest tool first

A four-rung ladder labelled from bottom to top: Instruction, Setting or status line, Hook, Mod, with one HAL example beside each rung

Climb only when the rung below can't do the job: words, then a switch Claude Code already has, then a hard rule, then a mod.

We started at the top rung, twice, and the case study has the receipts. But when a mod is the right tool, what does one look like inside?

How a Claude Code Mod Works

A mod is a small folder. Ours looks like this.

next-steps/
├── .claude-plugin/
│   └── plugin.json      name, version, description
├── hooks/
│   ├── hooks.json       {"modules": ["./register.ts"]}  ← this line makes it a mod
│   ├── register.ts      the mod: which events it handles
│   └── verdict.ts       plain helper logic, tested on its own
└── tests/               Anthropic's test kit

The hooks.json line pointing at a module turns a plugin into a mod. No build step, no Node.js. The module exports one function, register(on), built on three ideas.

on(event, …) picks the moment: a tool call, a finished turn, a screen redraw, a slash command. A matcher narrows it, such as only the Bash tool.

next(e) lets Claude Code carry on, changed or not. Mods stack like layers of an onion; calling next passes the event to the next layer. Don't call it, and you've answered the event yourself.

$ is Claude Code's toolbox: draw, ask, save data, set timers, read files, run programs, call a model. Everything goes through $, which is how claude plugin validate lists what a mod touches without running it.

Three nested rings labelled org guard, your mods and Claude Code, with an event arrow passing inward through each ring via next(e) and a green result arrow passing back out

Mods stack like an onion: each layer calls next(e) to pass the event inward, and the result comes back out.

Where a mod can draw

A schematic Claude Code terminal with six labelled surfaces: the band above the prompt, a pane on the right, a toast at the top right, the mod status line under the prompt, the dim suggestion in the typing box, and a restyled spinner

Six places a mod commonly draws (it can also add a log line to the transcript). Name one in your prompt and Claude puts the mod there.

The band (AbovePrompt): the strip above the typing box, shared by every mod.

A pane: docked right in a wide fullscreen terminal, otherwise above the prompt.

A toast: a pop-up at the top right for about 4 seconds.

A mod status line: one line under the prompt, prefixed with the mod's name.

The typing-box suggestion: dim text you accept with Tab ($.prompt.suggest).

Claude Code's own rows: the spinner, tool rows and question dialog can be redrawn. The permission prompt cannot.

lustoykov's tip: name the surface in your prompt ("a cost band", "a pane"), and Claude puts it there.

Real code: our next-steps mod

A simplified excerpt from our register.ts: one hook decides whether a finished turn deserves a check, one draws the buttons.

register.ts
// Simplified from HAL's next-steps mod (hal-mods, 4 Oct 2026)
export function register(on) {
  // 1. A turn finished. Let Claude Code carry on first, then decide.
  on("turn.complete", async ($, e, next) => {
    const result = await next(e);
    // Ask the fork only after the turn has ended.
    if (isWorthChecking(e)) $.clock.after(0, () => check($));
    return result;
  });

  // 2. Draw our buttons ABOVE other mods' rows in the band, never instead of them.
  on("ui.render", { component: "AbovePrompt" }, async ($, e, next) => {
    const below = await next(e); // what the mods after ours drew (Claude Code draws nothing here)
    if (steps.length === 0) return below;
    const { Box, Button } = $.ui.resolve(e);
    const row = Box({ flexDirection: "row", columnGap: 3, children:
      steps.map((s, i) => Button({ label: s.label, hotkey: String(i + 1),
                                   onPress: send($, s.prompt) })) });
    return below ? Box({ flexDirection: "column", children: [row, below] }) : row;
  });
}

The line that matters most is const below = await next(e). Leave it out and your band replaces whatever the mods after yours drew there. Keep a band small, too: our first mod, a dashboard, drew a band that also hid Claude Code's own task list and running agents.

Mr. Cloud Book's walkthrough is the most detailed tour of events, ordering, packaging and the test kit, for readers who want the architecture in 18 minutes.

Drawing and listening are free. The interesting mods also think about what just happened, using a technique hooks don't have. (Settings hooks can call a model, but they can't fork the conversation.)

Forking: The Technique That Makes Mods Smart

Picture a long meeting. You photocopy the minutes and hand the copy to a colleague with one question: "Did we actually agree on a deadline?" They answer, the copy goes in the bin, and the meeting carries on untouched.

That's a fork. In mod code it's one line:

typescript
const reply = await $.model.fork({ prompt: forkPrompt(lastAnswer) });

The fork gets a copy of the whole conversation, answers one question, and disappears without touching the original.

It's cheap because of the cache. Every message re-sends the whole conversation, but while it's fresh in Claude's cache, re-reading it costs far less. On a Claude subscription the main conversation's cache lasts an hour; with an API key, a cloud provider or usage credits, it's five minutes unless you change it. While the cache is warm, a fork pays a reduced cache-read price for the conversation, plus the question and answer. When we read them on 5 Oct, the last next-steps fork in each of four HAL windows had read between about 200,000 and 900,000 tokens from the cache: cheaper, not free.

A meeting table with the original minutes labelled The conversation, a photocopy handed to one person with the speech bubble Did we agree a deadline?, and the copy then dropped into a bin while the original stays on the table

A fork is a photocopy of the conversation: it answers one question, then goes in the bin.

Thariq's examples

Thariq Shihipar, who works on Claude Code at Anthropic, covered forks in a Latent Space interview released two days before launch.

A quiz after each turn. A fork asks "is this task complete?" and, if so, writes quiz questions above the prompt. It costs a little every turn.

A supervisor. Thariq and the host describe a fork that asks what the goal was, whether the work met it, whether corners were cut, and what needs your approval.

Side questions. Claude Code's own "by the way" questions use forks too.

When the host asked whether a per-query model router would burn through a plan, Thariq said someone can share one that doesn't break the prompt cache, and Anthropic wants a mod-writing skill that warns you. (It's at about 38 minutes in the video at the top of this guide. A built-in mod-writing skill, plugin-authoring, now ships with Claude Code.)

The limits of a fork

It can't run tools, and it uses the same model and setup as the main conversation (which keeps the cache valid).

It's cheap only while the cache is warm. If the cache has expired, the fork still runs and pays to read the whole conversation again.

It costs usage. $.model.fork and $.model.complete bill your plan or API key.

A fork is not an adversary. Same model, same conversation, same blind spots. Use it to supervise the process, not instead of a review by a different model.

None of that helps until the mod is running, and that's the step we got wrong first.

How to Install Claude Code Plugins and Mods

There are two ways in: install a mod for every window, or load it into one window while you try it.

Two-lane flow. Every window: add marketplace, /plugin install, /reload-plugins. One window: a new window with claude --plugin-dir, which reloads on every save; or, in a running window, ask Claude for a mod, Claude writes it to dev-mods, Enable for this session, it loads at turn end, and to keep it you copy the folder out

Two ways in. The one-window route is the most common "my mod does nothing" trap.

Before you start

You need Claude Code v2.1.287 or later (claude --version). Mods are on by default; the old CLAUDE_CODE_ENABLE_FUNCTION_HOOKS setting is ignored.

Use a terminal

Mods draw in a terminal (IDE terminals and JetBrains included) and the desktop app's Code tab. In VS Code's chat panel and claude -p they run but draw nothing, Remote Control shows them only in the terminal on your own machine, and desktop WSL sessions don't run them. In a cloud session they run only if the plugin reaches that session, and draw nothing. A few elements are terminal-only. If a working mod looks broken, check where you're running it.

Option 1: install for every window

This is how to install Claude Code plugins in general, and mods are just plugins.

1

Add the marketplace (a list of plugins someone publishes, usually a GitHub repo): /plugin marketplace add owner/repo.

2

Install: /plugin install name@marketplace, or claude plugin install … from your shell, for yourself (user scope) or one project.

3

Reload with /reload-plugins in any session already open, if you installed from the shell.

4

Check: /plugin shows a dim line such as 1 mod active · first-mod.

Updates. The docs say /reload-plugins loads an update; if it says the change is pending (to protect your prompt cache), /reload-plugins --force applies it. Restart only if an update doesn't show. 2.1.289 fixed a bug that left stale copies of local-folder marketplaces.

Option 2: load into one window

claude --plugin-dir ./my-mod loads a mod into one new session and reloads it every time you save.

In a session that's already running, the documented route is to ask Claude for the mod. This is where we tripped up first.

1

Ask Claude for a mod. Claude works from the built-in plugin-authoring skill (or run /plugin-authoring yourself).

2

Claude writes it into a hidden folder, ~/.claude/dev-mods/<session-id>/, asking before each file in default mode.

3

Answer the prompt. Claude Code asks "Enable hot reloading for this session?" Only you can pick Enable for this session. With Not now, nothing loads for now; the mod loads the next time that session starts.

4

Use the next turn. The mod loads when the turn ends.

5

Keep it. A mod Claude wrote loads only in that session. Copy its folder out and load it with --plugin-dir, or add it to a marketplace.

Copying a finished mod into that folder yourself isn't a documented route: when we tried it, it did nothing at first ("Unknown command"). For a mod you already have, use --plugin-dir.

Claude Code's question Enable hot reloading for this session? with the option Enable for this session highlighted; the other options are shown as blank grey bars

The step most guides skip. Simplified illustration.

What breaks live: the gotchas in one place

Each hook gets 10 seconds of its own time (50 ms for prompt.edit). Time waiting inside next and most $ calls doesn't count, but $.clock.sleep does. A .catch handler gets 1 second.

All installed mods share one worker thread (a single lane of work), so a mod that blocks it gets unloaded. If three worker crashes can't be traced to one mod, Claude Code unloads every non-built-in mod until you run /reload-plugins.

Write every call in full ($.ui.ask, never const ui = $.ui), because the validator reads code without running it.

dev-mods folders get cleaned up after a while, so copy out anything you want to keep.

Now you can load anything. The harder question is which mods are worth loading.

The Best Claude Code Plugins and Mods Right Now

Our bias in ranking the best Claude Code plugins: someone running several sessions who cares about cost and deploy safety, with anything that touches less of your machine pushed higher. We checked each repo's licence and the calls it makes, not every line of its code.

Start with Anthropic's three samples

These live in anthropics/claude-code-playground (Apache-2.0). They're "not an official Anthropic product", but each README's "How it was built" section includes what didn't work, which makes them the best learning material available.

blast-radius holds risky commands (rm -r, git reset --hard, force pushes, migrations), shows what they'd affect, and asks Proceed or Cancel, with Cancel focused so Enter refuses.

token-weather is the smallest: one line above the prompt forecasting how full your context is (how much conversation Claude can hold), from ☀ under 25% to ↯ at 90% and over.

replay-theater lets you step through the last turn's file changes with /replay.

All three came from one prompt: Claude listed ten ideas, and the build prompt boiled down to "implement 1, 2, 7".

Community mods, ranked

#Mod (author)What it doesLicenceSafety note
1claude-flightdeck (scasella)Read-only pane: context, cost, permission decisions, subagents (helpers Claude starts)MITNo file, process or network calls
2whats-agent-doing (tzafrir)One box saying what Claude is doing nowMITOnly lists agents
3claude-code-redact (karanb192)Swaps secrets (and personal data, if you turn those rules on) for placeholders before the model reads themMITSees everything; no process or network access
4claude-agent-watch-mod (estruyf)Counts open sessions, warns at a limit, lists ones waiting on youMITReads and writes files and sees every prompt you send; strict mode holds a prompt and puts it back in the box
5nateherkai/claude-code-mods (Nate Herk)Collision Guard (asks before editing a file another chat changed in the last 30 min), Cache Keeper, Goal Meter, Recording ModeMITNo network calls of its own; Cache Keeper's forks spend tokens
6yash-gadodia/claude-mods13 mods, incl. merge-gate (no merge unless you said "merge")MITRuns programs; scope-guard calls a model
7OneWave-AI/claude-code-mods11 mods, incl. launch-codes: a one-time code before vercel --prod, force-push or a database resetMITAsks you; plays sounds
8hamzafer/claude-code-mods17 mods (5 Oct), incl. a merge-gate that waits for CI (automated checks) and a Codex reviewMIT90★ on 5 Oct. Runs programs, calls a model, makes web requests
9cc-pr-tracker (sezaakgun)Pull requests and CI checks above the promptMITRuns the gh tool
10claude-fleet (Dubbus)Every session: busy or waiting, git state, contextMITCalls a model, runs programs, writes files, can submit a prompt
11modsmith (Dan McAteer)A mod-building skill plus seven templates, incl. next-steps-supervisorMITForks; shows each fork's actual token use
12ctx-handoff-mod (cablate)At 80% context (or 600k tokens), writes a handoff, clears the chat, continuesMIT37★ on 5 Oct. Runs /clear and submits prompts: trial only
13intermission (jarrodwatts)A shared Doom deathmatch while you wait on ClaudeMITDownloads a game; hard-coded server. See safety
14Arunjay4213/claude-modsquota-meter, token-ledger, budget-guard, context-lensNo LICENSE file (README says MIT)Check before reusing

Two honest notes. Account-switching mods are only just appearing: as of 4 Oct, Rocha101/claude-code-quickswitch and simplecore-inc/claude-mods both switch Claude accounts. Both are days old: try them in one window first. And I'd rather you build one small mod for your own workflow than install six of these: "the best use case is going to be one that's unique to you", as Chase AI put it.

Plugins that aren't mods

Many Claude Code plugins have no mod code at all. A plugin can add commands, agents, skills, settings hooks, and MCP and LSP servers (connections to outside tools and code services). Claude Code adds Anthropic's official marketplace, claude-plugins-official, the first time you start it in a terminal, so you can install straight away: /plugin install commit-commands@claude-plugins-official adds commands for committing, pushing and opening pull requests. The details pane shows what a plugin will add and, for official ones, an estimate of the tokens it adds to every turn. Browse more at claude.com/marketplace, and vet them like mods: plugins can run hooks and MCP servers too.

Fourteen repos is a start. The full count is over a thousand, so where do they all live, and how do you tell a good one from a risky one?

Where to Find Mods: Catalogues and Marketplaces

People search for "the Claude Code plugins marketplace" as if it were one app store. It isn't: any GitHub repo with a marketplace file is one, and you can add as many as you like. Anthropic runs the official one (home of code-modernization) and takes submissions for its claude.ai directory. For mods, community catalogues are ahead.

CatalogueWhat it isNote
awesome-claude-code-mods (karanb192) · mods.aidojo.si1,740 mods, auto-scanned with claude plugin validate, each with an access badgeThe largest we found. CC0
claudemods.aiAn unofficial, voted catalogue with a mod of the day45 mods
awesome-claude-code-function-hooks (Ray Amjad)The first list, from before the renameSmall; MIT
GitHub topics claude-code-mods, claude-code-modWhere new mods appear firstUnfiltered
Anthropic's playgroundThe three samples, as a local marketplaceApache-2.0
Built-in mod sourcesec-default, diff, telemetry, agents-md, type definitionsLearn the patterns here

That first catalogue also shows what mods ask for. Its 2 Oct scan, quoted in two videos, found 359 mods: 55 only drew and remembered, 75 reached the network, 111 saw every prompt. Its 4 Oct rescan of 1,740 found 215, 212 and 537. So about a third of public mods can see every prompt you type.

How to vet a mod before you install it

A checklist card titled Vet a mod before you install it, with six ticks: get its files and run claude plugin validate, check what it listens to and calls, find out what any program it starts does, try it in one window first, re-check on every update, prove a guard actually blocks

Save this one: six checks before you trust a mod.

1

Get its files and run claude plugin validate ./the-mod. Without running anything, it lists the events the mod handles (the hooks: line) and every $ call it makes (the calls: line).

2

Check what it listens to and calls. Watch for $.fs.read or write, $.process.run or spawn, $.http.fetch, $.env, $.settings.read, $.mcp.call, model calls, $.prompt.submit and $.session.send. In hooks:, tool.call and prompt.submit see every call and prompt, and tool.check can approve or deny tool calls.

3

Find out what any program it starts does. Validate can't see inside a program the mod starts, and network policy doesn't cover one, so treat any $.process.run as possible network access. The Doom mod below downloads its game this way. Read that part of the code, or ask Claude to explain it.

4

Try it in one window first with --plugin-dir.

5

Re-check on every update. A mod you trusted can change in a later version.

6

Prove a guard actually blocks. A failing mod is skipped, so "enabled" isn't "working": Wes Sander's post "The Guard I Installed Was Enabled, Running, and Doing Nothing" describes five preview-era guards that never loaded, because the preview switch was set in only one terminal.

A catalogue tells you what exists. The more useful question is what to build.

Claude Code Mod and Hook Examples

These are the ideas from the 34 videos and the repos, grouped by purpose (mods in the ranked table aren't repeated). If you came for Claude Code hooks examples, the ones marked hook works don't need a mod (a settings hook can do the job), the ones marked status line works could be a status-line segment, and the lab builds one guard both ways.

A grid of small idea cards in seven coloured groups: safety, cost, sessions, visibility, creator, tools and fun, each card with a one-line description

Find your own problem in seconds: mod ideas grouped by purpose.

Safety

  • Secret redactor (Ray Amjad): swaps secrets, emails and IP addresses for placeholders before the model sees them.
  • Dry-run gate (Ray Amjad): no real run before a dry run, with a red PROD banner. Hook works for the block, with the banner in your status line.
  • Account guard (Prompt Engineering): checks which account you're publishing from. Hook works: a hook can ask or deny.
  • Force-push rewrite (Prompt Engineering): turns a force-push into a push to a new branch. Hook works: a settings hook can rewrite a command before it runs.

Cost

  • Cache clock (Chase AI, Nate Herk): counts down to a cold cache. We used the status line instead.
  • Cost band (lustoykov): session cost plus the estimated cost of the next prompt. Status line works.
  • Budget guard (Arunjay4213): warns near a spend limit, then refuses tool calls.
  • Model router (Mark Kashef): forces subagents onto a cheaper model. Hook works: a hook can rewrite the call, or set a default subagent model.

Sessions

  • Auto-handoff (Mark Kashef): a fresh session at a context threshold.
  • Goal tracker (Nate Herk) and Claude Q (Gal Elmalah), which queues your next prompt while Claude works.

Visibility

  • Flight recorder and output tray (Mark Kashef): every request, model and tool; files created this session.
  • Deploy status row (Ray Amjad): Vercel deploy progress in a row at the bottom, next to the status bar, kept for an hour after each deploy. Status line works.
  • Studio status band (Simply AI): read-only, refreshed every 20 seconds, no model calls. They built it after finding 21 of their 246 messages were "status?" checks. Status line works.

Creator

  • Record mode (Nate Herk) masks emails and money on screen while you film (the model still sees them), and Ray Amjad's spoken summary reads each turn aloud.

Tools (all Ray Amjad)

  • Search override, a WebFetch cache, a knowledge-base injector that adds your company docs to the prompt (hook works), and npm to pnpm, which rewrites commands to your package manager (hook works).

Fun

  • Image viewer (Jarrod Watts, per lustoykov's video), Mermaid diagrams (Gal Elmalah), a virtual pet (Mark Kashef), and Mindful Claude (halluton), a breathing exercise while Claude works.

Nate Herk makes a fair point: he doubts many viral visual mods would actually help him. The best fix one specific annoyance. So how do you turn yours into a working mod?

Build Your First Mod: A Copy-Paste Lab

You don't need to code. Claude writes the mod; you say what you want, read what comes back, and prove it works. First a quick win with Anthropic's sample, then a real safety mod that asks before Claude force-pushes, built for our Workshop 22 session.

Seven numbered steps with icons: describe it, read the plan, say go, validate, test, load in one window, prove it refuses

The lab at a glance: the seven steps of our own run.

Warm-up: a first win in one window

Run these in a terminal; they're straight from the playground's README.

$ git clone https://github.com/anthropics/claude-code-playground.git
$ cd claude-code-playground/claude-code/mods
$ claude --plugin-dir ./token-weather

A one-line context forecast appears above the prompt (☀ under 25% full). Close the session and it's gone. To keep it in every window, install it as a local marketplace:

$ claude plugin marketplace add ./
$ claude plugin install token-weather@claude-code-playground-mods --scope user

Step 1: describe it

Make a folder called force-push-guard, open Claude Code in it, and paste this prompt. It's our exact request:

Prompt
Build a Claude Code mod in this folder called force-push-guard. Load the
plugin-authoring skill first. When Claude is about to run a Bash command that
is a `git push` with -f, --force or --force-with-lease, ask me with $.ui.ask
and two options, "Cancel" first and "Push anyway". Only "Push anyway" lets it
run. If I close the question, there's no one to ask, or the mod's own code
fails, block the push (add a .catch that denies). Don't trigger on commands
that only mention a force-push, like echo or rg. Write tests with Anthropic's
test kit for: a normal push, Cancel, Push anyway, a closed question, and no
false alarm. Show me the plan before you write anything.

Step 2: read the plan

In our run, Claude loaded the plugin-authoring skill, wrote nothing yet, showed a plan, and asked us four decisions: where to write the mod, whether to catch other force forms (such as a +main refspec), whether to catch wrapped commands (such as bash -c), and whether to add more tests.

Step 3: say go

We replied "Go", with no extras. Claude wrote four files: plugin.json, hooks.json, register.ts and a test file. Here's the heart of the hooks/register.ts HAL wrote for the version in this guide, comments trimmed. Yours can differ a lot (a rebuild on 5 Oct wrote a 162-line file with different messages), so read it before you trust it.

hooks/register.ts
export function register(on) {
  on("tool.call", { tool: "Bash" }, guard).catch(async () => ({
    deny: "force-push-guard failed, so the push was blocked.",
  }));
}

async function guard($, e, next) {
  const command = String(e.command ?? "");
  if (!isForcePush(command)) return next(e); // not a force-push: run it

  let answer = "Cancel";
  try {
    answer = await $.ui.ask(
      "Force-push? This can overwrite commits on the remote.",
      ["Cancel", "Push anyway"],
    );
  } catch {
    // You closed the question, or nobody can answer (claude -p): stay safe.
  }
  if (answer === "Push anyway") return next(e);
  return { deny: "Force-push cancelled by the user (force-push-guard)." };
}

Two lines do the safety work. The .catch on the registration makes a crash or a timeout block the push: the guard fails closed. And answer starts as "Cancel", so anything but a deliberate "Push anyway" refuses. (isForcePush, not shown, only counts a part of the command that starts with git push.)

Step 4: validate it

$ claude plugin validate ./force-push-guard

Our real output on Claude Code 2.1.289 (paths shortened):

Output
Validating hooks: .../force-push-guard/hooks/hooks.json

  ❯ ./register.ts hooks: tool.call{tool=Bash}
  ❯ ./register.ts calls: $.ui.ask

✔ Validation passed

That's the mod's whole reach: one hook on Bash, one question. If your plugin.json has no author, the last line reads "✔ Validation passed with warnings" instead; that warning is harmless.

Step 5: run the tests

$ cd force-push-guard && claude plugin test

Our five tests, and their real output on 2.1.289:

Output
tests/hooks.test.ts:
(pass) a normal git push runs with no question
(pass) git push --force + Cancel: denied and never ran
(pass) git push -f + Push anyway: it runs
(pass) closing the question blocks the push (fails closed)
(pass) no false alarm on echo or rg that only mention a force-push

 5 pass
 0 fail

The kit doesn't force a failure, so we also called the hook directly with a fake question and next: all five cases matched, and a forced crash and a forced timeout both returned "force-push-guard failed, so the push was blocked."

A real run on Claude Code 2.1.289: validate finds the Bash hook and the $.ui.ask call, and the test kit passes all five tests.

Step 6: load it in one window

$ claude --plugin-dir ./force-push-guard

If Claude wrote the mod into its own session folder instead, answer Enable for this session when asked about hot reloading.

Step 7: prove it refuses

In a throwaway folder, run git init, then start Claude there with the full path to the mod (claude --plugin-dir /full/path/to/force-push-guard) and ask it to run git push --force origin main. With no remote, nothing can be overwritten. The guard's question appears with Cancel listed first. Pick Cancel, and Claude is told the push was cancelled (with our code, "Force-push cancelled by the user (force-push-guard)."; yours will word it its own way). Try again and close the question: that blocks it too.

On 5 Oct we ran the rebuilt guard headless (claude -p, auto mode, Claude Code 2.1.289, loaded with --plugin-dir), so nobody could answer. Claude tried git push --force origin main, the guard denied it, and Claude didn't try another way. That folder had no remote, so the push would have failed anyway; the guard's deny came first. We haven't captured the Cancel click in a live window: Cancel is proven by the test above. If yours behaves differently, tell us.

Flow diagram: a git push --force arrow hits the force-push-guard, which asks Force-push? with Cancel listed first. Cancel leads to Blocked, also blocked on a closed question, crash or timeout; Push anyway leads to Runs

Illustration: the moment your own mod says no. Anything but a deliberate "Push anyway" is blocked.

The hook version, for comparison, adapted from the example in Anthropic's hooks docs. We ran this script on sample input, not inside Claude Code. Add it to .claude/settings.json:

.claude/settings.json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [{
          "type": "command",
          "if": "Bash(git push *)",
          "command": "\"${CLAUDE_PROJECT_DIR}\"/.claude/hooks/no-force-push.sh"
        }]
      }
    ]
  }
}
.claude/hooks/no-force-push.sh
#!/bin/bash
# .claude/hooks/no-force-push.sh  (chmod +x it; needs jq)
command -v jq >/dev/null || {
  echo "jq not found, so the push was blocked" >&2; exit 2
}
COMMAND=$(jq -r '.tool_input.command // ""')
FORCE='[[:space:]](-f|--force|--force-with-lease[^[:space:]]*)([[:space:]]|$)'
# Split at ; & | and check only the parts that start with "git push"
if printf '%s\n' "$COMMAND" | tr ';&|' '\n\n\n' \
   | grep -E '^[[:space:]]*git[[:space:]]+push([[:space:]]|$)' \
   | grep -qE -- "$FORCE"; then
  echo "Force-push blocked by hook" >&2
  exit 2   # exit code 2 = block
fi
exit 0

The hook script run directly, fed the JSON Claude Code sends before a Bash command, trimmed to the one field the script reads. A plain push passes (exit 0), a force-push is blocked (exit 2), and an echo that only mentions one passes.

Know its limits. The script is a simple text match, so some force-pushes get past it: git -C dir push --force, a push wrapped in bash -c '…' or sudo, and a +main refspec aren't caught. It can also false-alarm: echo "note; git push -f later" is blocked, because it splits at the ; even inside quotes. And if its input isn't valid JSON, it lets the push through. Treat it as a seatbelt, not a lock.

It refuses outright: no "Push anyway", and no permission prompt for an auto-approve hook to answer. A hook doesn't have to refuse: it could return "ask" to show Claude Code's own permission prompt, or rewrite the command with updatedInput. We used exit 2 because an auto-approve hook or mode can answer an "ask" prompt. (A mod that approves tool calls can still overrule it, unless the hook is in managed settings.) That's the ladder in one exercise.

Chase AI: the quickest beginner explainer of what a mod can do (before, instead of, after, or around any event), and the source of the "audit your last 30 sessions" tip in the box below.

The general loop for your own mod

Ask Claude to read your last 20 to 30 sessions and suggest five mods (Chase AI, Nate Herk and Prompt Engineering all start here), adding the rule Prompt Engineering picked up on X: "show me the ideas first. Don't build anything until I pick." Check the ladder, name the surface, test the "no" case, build in a self-check, and pair every pane with a slash command for places that don't draw.

Those habits come from problems we hit ourselves. Here's the honest record.

What We Built, and What Went Wrong

HAL is my Claude Code setup: about 2,000 command files, plus hooks and now mods, running much of StationX's day-to-day work. Here are five things we wanted that a mod could do. Only one is a mod today.

We wantedBuilt as a mod?What happened
A dashboard of every sessionYes, then switched offClaude Code's own task list disappeared under it; its guard false-alarmed
A summary after every answerYes, then retiredA short rule did the job; then I didn't want it
A cache countdownNever builtThe status line already had the data
A guard showing me emails before they sendDesigned, not builtRight tool; we chose not to build it
Next steps after each turnYes, on v0.4.2Working, after one bad first version

The dashboard that hid everything

Our first mod, hal-dashboard, showed open sessions, account usage, and a guard holding paid-API calls and deploys for my OK. With its band on, Claude Code's own task list and running agents disappeared. We never pinned down why; we switched it off. My reaction, verbatim: "Where's all the other stuff".

Real screenshot of our hal-dashboard band above the prompt, with Claude Code's own task list and agents not showing, and other sessions' text blurred

Our hal-dashboard band. With it on, Claude Code's own task list and running agents didn't show. Other sessions' text blurred.

The guard was worse. It matched words anywhere in a command, so a read-only search that merely mentioned a paid API's address was held for approval. "It's unusable now. You can't keep prompting and stopping work." We switched it off. Lesson: match the program being run, not words in the command, as the lab's isForcePush does.

The summary block a one-line rule could do

We built status-block to end every answer with a summary, then noticed a rule in HAL's instructions already did it. Soon I found the summary annoying, and we retired both.

The cache countdown that belonged in the status line

I wanted a countdown to the moment Claude's cache goes cold and messages cost more. A mod could do it, but Claude Code already sends its status line (the line or lines under the prompt, drawn by a script of yours): the cache's lifetime, expiry time and how many tokens the next request would re-cache once it's cold. One new segment plus "refreshInterval": 60, and it was done. No mod, no tokens.

HAL's status line in three states: a green 42m countdown, a red 3m countdown with the 310K re-send cost in grey, then an ice-blue snowflake with 310K once the cache is cold

The lighter tool did the job: a cache countdown in the status line, no mod, no tokens.

Next steps: from a "blurge of text" to three buttons

next-steps is the mod we kept. Version 0.1 ran a supervisor fork after each working turn and showed the whole report. I called it "a blurge of text", and it ate the screen.

Version 0.2 shows only the outcome: up to three buttons above the prompt, and the best step as the dim suggestion Tab takes. It forks only after a turn that changed something, made eight or more tool calls, or asked me something, so plain chat costs nothing. The pattern is adapted from Dan McAteer's MIT-licensed next-steps-supervisor; the buttons follow Thariq's next-steps mod as shown in Nate Herk's video.

Side-by-side screenshots: version 0.1's wall of supervisor text against version 0.2's single row of three next-step buttons

Show the decision, not the reasoning: v0.1 against v0.2.

Version 0.3 also checks the work against the HAL procedure being followed (a deploy, an email send); a broken rule becomes button 1. On six test scenarios (two real, four constructed, one run each), it put the right fix first in all five problem cases, with no false alarm on the clean one. Version 0.3.1 saves a status file HAL reads itself, because HAL kept asking me to run a diagnostic ("Why do you keep asking me to do things? I hate that."). Day to day, I use it to click what I might do next.

Version 0.4 came from using it. The five-word labels were often too short to judge an option by, so a fourth button, + (key 4), swaps them for the full sentences, one per line, and each sentence is still the button you press. Option 1 now carries a ★: the fork lists steps most important first, and the star makes that visible. The key is 4 rather than + because a band hotkey has to be a digit to work without first moving focus to the band.

Testing earned its keep. The test kit caught a logging call that would have crashed the error path; only the live test in a second window caught the missing "Enable hot reloading" step.

That's what a mod can do for you. The bigger question is what one can do to you.

Are Claude Code Mods Safe?

Short answer: as safe as the person who wrote it.

A laptop with a mod at the centre and arrows out to everything it can reach: files, programs, network, environment variables and API keys, every prompt and tool call, and other sessions, with a struck-through Sandbox label on the dashed fence around it

"Not sandboxed" made concrete: a mod runs as you.

Mods are not sandboxed

A sandbox is a fenced-off area where a program can't touch the rest of your machine. Mods don't have one; a mod runs as you. Per Anthropic's docs it can reach your files, programs, the network, environment variables and settings (API keys included) and every prompt and tool call, and it can approve tool calls and spend your plan. Claude Code's Bash sandbox doesn't cover programs a mod starts.

There's one important protection, and most people don't get it. Anthropic's built-in guard, sec-default, stops user mods from lifting your deny rules (settings that tell Claude Code never to run or read something). But it only loads with managed settings (set by an organisation) or on a Team or Enterprise plan. Without it, a mod can override your deny rules. Even with the guard, in auto mode a call a mod approves skips the safety classifier: the guard protects only your deny rules and managed hooks. And deny rules never cover a mod's own file reads: "a rule telling Claude not to read your env file doesn't stop a mod", as AI In View put it.

Three more facts. A mod hook that crashes or times out is skipped, so a careless guard fails open (the lab's registration .catch covers both). Mods cannot change the permission prompt. And Anthropic can switch installed mods off remotely, per the docs, which matters for a safety mod.

What Pluto Security found, with the caveats the videos dropped

The report most videos quote is Pluto Security's (22 September). It found four trust gaps, each demonstrated.

FindingWhat they showedThe caveat
1. Silent theftA mod read Claude's credentials file and history and sent them out, with no promptTheir note: shell hooks could already do this
2. Hidden hooksclaude plugin details showed "Hooks (0)" for a mod hooking everythingA disclosure gap; the content scan only runs for the claude.ai channel. No fix listed in the changelog through 2.1.289
3. Spoofed promptsA fake credential prompt above the input; a swapped question dialogDescriptive labels like "Delete everything" blocked the swap; generic Confirm/Cancel didn't
4. Fetch after reviewA mod downloads and runs a script, so behaviour changes with no version bumpnpm packages and curl | sh carry the same risk

The biggest caveat covers all four: Pluto tested version 2.1.274, the pre-release preview. They confirmed the permission prompt can't be hooked, and for findings 1, 3 and 4 the docs now openly describe this access. When Jack Roberts repeated the findings on YouTube, the caveats and version went missing. Read the report, not the retelling.

Case study: multiplayer Doom

intermission by jarrodwatts is delightful. Once Claude has worked for two seconds, a pane drops you into a shared Doom deathmatch with everyone else waiting on Claude, and hands you back when Claude finishes or needs a permission. It's MIT-licensed and open. It also starts a program (curl) to download the game, and the game connects to a fixed server over UDP. claude plugin validate would show you that it runs programs, but not what they do.

So, the workshop question: would you install it on the laptop that holds your production credentials?

A retro game pane in a terminal window, with a label on the left, starts a program that downloads the game, and on the right, the game connects to a fixed server

Fun, and a supply-chain question: a program that downloads the game, plus a fixed server.

How to turn mods off

Want toDo thisNote
Stop one modDisable or uninstall it in /plugin
Run one session with no modsStart Claude Code with --safe-modeAlso turns off your other customisations
Stop every mod you installed"disableAllHooks": true in ~/.claude/settings.jsonAlso stops settings hooks, your status line and a custom file-suggestion command. Mods your organisation manages keep running
Lock it down for a companyallowManagedModsOnly, allowManagedHooksOnly, disableAllHooks in managed settingsSee the admin page

Safe mode, --bare and disableAllHooks don't stop Claude Code's built-in mods. To turn one off, disable it in /plugin: every built-in can be turned off that way except the sec-default guard. For the organisation side, see our guides to AI guardrails and the AI governance framework.

You'll want the sources. Here's everything we read and watched, compared.

Resource Hub: Every Video, Doc and Repo Compared

Start here, by what you need

You want to…Best docBest videoBest repo or read
Understand modsMods overviewThariq (#1)Anthropic's samples
Install oneInstall pluginsCode Nik (#24)The samples, as a local marketplace
Build oneCreate a mod + Test a modMr. Cloud Book (#3)The built-in plugin-authoring skill; modsmith
Stay safeMods overview (trusting a mod)AI In View (#18)Pluto's report; awesome-claude-code-mods access badges
Run a teamManage mods for your organizationNone yetBuilt-in mod source (sec-default)

Official docs (all ten pages)

Mods overview · Create a mod · Draw in the interface · Interface gallery · React to events · Use the mods API · Test a mod · Troubleshoot a mod · Manage mods for your organization · Mods reference. The overview and Create pages are the place to start; the reference lists every event, method and limit.

Anthropic's own posts and repos

Launch posts. The launch post and Addy Osmani's Getting started with Claude Code mods, which builds token-weather (both 1 Oct); the @ClaudeDevs launch and preview posts.

Design thread. Design thread #91870: 242 comments, opened on 3 Sep by poteat, who describes building the first built-in mods. Why everything goes through $ (so admins can audit it), the onion model, fail-closed guards, and whether the code that runs is the code that was reviewed.

Changelog. Changelog: 2.1.287 added mods; 2.1.288 fixed several mod bugs and added $.ui.selection(); 2.1.289 followed.

Source. Built-in mod source and code-modernization, a mod inside a production plugin.

All 34 videos, compared

Watch first (★): Thariq for where mods are going, Mr. Cloud Book for architecture, SimplyExplain for how Anthropic's safety sample works, Chase AI for the quickest overview. PRE-LAUNCH means published during the September preview: setup steps are out of date even when the ideas hold.

YouTube thumbnail: The Future of Claude Code: Mods, Mutable Software, & Multiplayer Agents
1
Latent Space (Thariq Shihipar, Anthropic) ★ Released two days before launch
Anthropic's view; forks for quizzes, next steps
  • Mods customise the whole harness, both what it does and what it shows. Anthropic will keep adding hook points as people ask for them.
  • Walks through how you'd build a quiz mod: after each turn a forked agent (cheap, because it reuses the prompt cache) checks whether the task is done and, if so, shows questions above the prompt.
  • His own mods: a next-steps supervisor, a tool that records each assumption Claude makes, a model router (all in progress), and a mode selector that other plugins register into.
  • Why mods beat shell hooks: they run inside Claude Code with the session in scope, see far more events, can start subagents, and can change the screen.
  • Mods are an early look at mutable software: the core harness (sandbox, permissions, web access) has to be complex and very secure, but how you work with it can change a lot.
YouTube thumbnail: I Had Claude Code Build Its Own Mod in 9 Minutes
Clearest on what validate does and doesn't tell you. Its mod picks come from demos, not from running them
  • Reviews third-party mods using the public scan: of 359, only 55 do nothing beyond drawing and remembering, 75 reach the internet and 111 see every prompt.
  • Covers cc-arcade, Mindful-Claude, context-lens, blast-radius and secret-redactor, which sees every prompt but has no network and no file writes: the combination to look for.
  • Builds a read-only studio status band plus a /studio text command, because mods draw nothing over Remote Control, in VS Code chat or with -p.
  • Build bumps: the safety check held writes to the plugin folder, validate couldn't follow code split across two files, and nothing showed until /reload-plugins.
  • Validate shows what a mod can do; only reading the code shows what it does. A trusted plugin can also change in a later update.
YouTube thumbnail: Claude Code Mods: Plugins, Hooks, Tools & Security Explained
Deepest architecture tour: ordering, packaging, test kit
  • A “guard at the door”: a mod can allow, block or change an event, acting before, after, instead of, or wrapped around it.
  • Failures are forgiving: a broken prompt mod lets the original prompt through, slow hooks are skipped, and a crashed UI replacement falls back to Claude Code's own.
  • Order: managed (organisation) hooks run first and their deny is final; within a plugin, hooks run in the order they were registered.
  • Packaging and tools: plugin.json, hooks/hooks.json, a TypeScript module, the type definitions Claude Code writes into .claude-plugin/types/ for you, --plugin-dir, and a test kit that mocks the clock, the store and the environment.
  • Mods are not sandboxed: they have the same access to your machine as Claude Code, and the API may still change.
YouTube thumbnail: Claude Code Mods Are A Game Changer For AI Safety
Blast radius in detail; how the samples were made
  • Blast radius dry-runs rm, git reset --hard, force-pushes and database migrations. Cancel is the default, and it refuses by itself after 10 minutes.
  • Replay theater: a hint above the prompt, then R to open and N/P to step through the turn's edits on a timeline.
  • How Anthropic made its samples: it asked Claude for 10 mod ideas, picked three, and the build prompt was one line naming the three numbers.
  • Anthropic's examples: add the current git branch whenever you mention a PR, and allow git push except on main.
  • A mod Claude writes lives only in that session, so copy the folder out and load it with --plugin-dir. A mod can restyle almost anything except what the permission prompt shows.
YouTube thumbnail: Claude Mods Is The Biggest Claude Code Upgrade Since Skills
Before/instead/after/wrap. Most-viewed (174k)
  • Mods are the released form of “function hooks”, first teased in early September.
  • The mental model: act before, instead of, after or around any event. A delete can be previewed, sent to the bin instead, receipted, or backed up first.
  • Demos: a next-steps pane with three clickable follow-up prompts, and a cache clock with a compact button.
  • Main tip: ask Claude to audit your last 30 sessions and suggest five mods. Pick one and Claude builds and installs it.
  • Mods run by themselves like hooks, and you can turn one off in plain English.
YouTube thumbnail: Claude Code Mods Are Game Changers. Set Up These 5 NOW.
Cache keeper, record mode, collision guard
  • Cache-keeper: cache countdown, context size, 5-hour and weekly limits and the session's API-price cost, with handoff buttons and a warning 5 minutes before the cache goes cold.
  • Record mode (/record to turn it on, /record off) masks emails and money on screen while he records; the model still sees the real values.
  • A /goal tracker pane: phase, elapsed time, checklist and % complete, across several sessions.
  • A collision guard: before editing a file another chat touched in the last 30 minutes, it asks whether to proceed, move to a worktree or cancel.
  • He started by asking Claude to look through his session logs and suggest the top five mods to build, and didn't take all of its suggestions.
YouTube thumbnail: Claude Code Now Has Mods. Here Are 10 Worth Stealing
Flight recorder, router, auto-handoff; bulk removal
  • A prompt is a one-off request, a skill is reusable instructions, and a mod is code injected into Claude Code, often using no model tokens.
  • “The plugin is the Trojan horse” for a mod. Install scope can be user, project or a shared team project. (The docs' three scopes are user, project, which is shared with the repo, and local: you, in this repo only.)
  • His mods: a theme and footer, a file-eating pet, a repo heatmap, a flight recorder, a model router, an output tray, receipts, bookmarks and auto-handoff at 85% context.
  • He built them by giving Claude the whole mods article first.
  • Clean-up tip: ask Claude for one command that removes every user-scope mod.
YouTube thumbnail: Claude Mods Just Dropped... Lets run it
Repeats Pluto's findings without the caveats
  • Mods are “browser extensions for Claude Code”: they watch, change or block events like session start, turn complete and screen drawing.
  • Demos: a context weather forecast and usage and cache trackers.
  • Community examples: multiplayer Doom while you wait, a custom progress bar and a Modern Warfare 2 lobby.
  • Security points he credits to a third-party review: a mod can read credential files and send them out, show “no hooks” in plugin details, or fetch new code after you reviewed it. (Pluto found these on a pre-release build, 2.1.274.)
  • A long stretch covers his own agentic OS and a Zapier MCP demo, which have little to do with mods.
YouTube thumbnail: Claude Mods - The Biggest Claude Code Upgrade!
Hook vs mod lifetime; when to use each
  • Skills, hooks and MCP sit outside Claude Code; mods run inside it.
  • A handler gets the event, a way to talk back, and next: pass it on, change it and pass it on, or answer it yourself.
  • A hook runs once per event and exits. A mod stays loaded all session, so it can keep state, show live panels, stop and ask, and add slash commands that never call the model. (A settings hook can stop and ask too: its "ask" raises Claude Code's standard permission prompt.)
  • Demos: the docs' tool-tally mod, an rm -rf guard that asks first, a context gauge, and a check on which account he's about to publish from. Reloading resets state, so keep it in the store ($.state also survives a reload).
  • Run claude plugin validate before installing to list a mod's events and calls.
YouTube thumbnail: Anthropic Just Released Claude Code Mods
Middleware model; redactor; search override; deploy row
  • Recorded in early September, when function hooks were behind the CLAUDE_CODE_ENABLE_FUNCTION_HOOKS=1 flag, about four weeks before the mods launch, so the setup steps are out of date.
  • Function hooks are like Express middleware. He says that beyond rewriting a command, shell hooks can't rewrite prompts, inject context, draw, ask their own questions, change tools or remember anything. (In fact, shell hooks can block, rewrite a tool call's input or result, add context and trigger a permission prompt, and can keep state in files. What they can't do is rewrite your prompt text, draw, ask their own multiple-choice questions, or hold state in memory. Function hooks can.)
  • Examples: rewrite npm to pnpm, cache WebFetch results, send WebSearch to Exa with a fallback, route WebFetch through a proxy.
  • A ~300-line transcript redactor swaps secrets for IDs and swaps them back when a tool runs.
  • A Vercel deploy-status row shown only during deploys, and a spoken Haiku summary of each turn.
YouTube thumbnail: Claude Code Just Become FULLY Custom (Claude Mods)
Beginner desktop demo; a pane hard to close
  • A beginner demo in the desktop app: he asked for a live usage pane and accepted “enable hot reload for this session”.
  • Claude's GUI ideas: a session timeline, a project switcher, files touched grouped by folder and a cross-session scratchpad. He added a subagent pane of his own.
  • Built a small Excalidraw-style sketch pane Claude can read. Mouse drawing failed at first, then worked. Earlier, the usage pane was hard to close.
YouTube thumbnail: Claude Code Mods in 5 Minutes (There's a Catch)
The three samples; the catch: no sandbox
  • A fast launch recap. Lydia Hallie called mods “middleware for Claude Code”.
  • Token weather: a band above the prompt with a 12-turn sparkline, from clear below 25% to “compact soon” at 90%+.
  • Blast radius lists the files a risky command would hit; replay theater (/replay) steps through the turn's diffs.
  • Build by describing the mod in a prompt and allowing hot reload; share through a GitHub repo with a marketplace file.
  • Mods aren't sandboxed. Blast radius is “a safety net, not a permission system”, so use permission rules for hard blocks.
YouTube thumbnail: Claude Mods Make Claude Code 10x More Powerful
No npm or React; text Doom; partly an ad
  • Pre-launch: function hooks were behind an environment flag and documented only in a GitHub issue.
  • Shell hooks run as a separate process; mods run inside Claude Code's process, with access to its React UI.
  • Give Claude the built-in mods repo and a cheat sheet as examples. Hot reload works.
  • No npm or React dependencies: a mod can import only its own files and Claude Code's modules, so Claude Code can list everything it does.
  • Demos a Firecrawl credit meter and Doom with a text HUD (the Firecrawl part is an ad).
YouTube thumbnail: Claude Code Mods Explained: How to Install + 10 Mods to Try
14
Claude Mods PRE-LAUNCH; install steps out of date
The ($, event, next) shape; ten catalogue mods
  • Timeline: proposed on 3 Sep in GitHub issue #91870; on 9 Sep the team said it would ship “on the scale of weeks” as Claude mods.
  • The ($, event, next) shape. $ is also where admins can limit what later mods may do; earlier hooks wrap later ones like middleware layers.
  • “Zero tokens” only covers drawing: your session still uses tokens, and a mod that calls a model has its own cost.
  • Walks through ten mods from claudemods.ai (said as “clawdmods.ai”), the catalogue this channel runs, with daily voting and a mod of the day.
  • Pre-launch install steps (an environment variable and a restart); no longer needed.
YouTube thumbnail: Claude Code is Now Fully YOURS (Mods)
Name the surface; a cost band
  • Jarrod Watts' image viewer mod: drag an image in and preview it.
  • Use the docs' surface names in your prompt (pane, toast, status line, band above the prompt); he wrote “band” so the mod would draw above the prompt.
  • Built a cost band: session cost so far plus the estimated cost of the next prompt. The first version assumed a warm cache, so he added a cache state and timer.
  • Built a /checklist toast of tasks finished in the session.
  • After he accepted hot reload, the mod was on for that session only; he had to ask Claude to enable the plugin for all sessions.
YouTube thumbnail: Anthropic Just Opened Up Claude Code: Mods vs Hooks vs Skills vs MCP
Close to Prompt Engineering's; force-push guard first
  • Its explanation is almost line for line the same as Prompt Engineering's video, so little is new.
  • Expects the first badly behaved mod soon after marketplaces take off; copied trending mods will break when Claude Code updates.
  • Best first mod: a force-push guard, because it makes “inside vs outside” click.
YouTube thumbnail: NEW Claude Code Mod Update!
17
Julian Goldie SEO
Token meter, focus-deck pane; a third ads
  • A beginner desktop demo: a token meter, a colour theme, and a /focus deck with a Pomodoro timer, token use and a to-do list.
  • A mod can stay in one chat or be installed for good; asking Claude for ideas produced a deploy guard and a posting log.
  • About a sixth of the video is ads for his paid community.
YouTube thumbnail: Claude Code Mods: Build Your Own Claude (and the Catch)
Day-two scan; deny rules don't stop a mod
  • An engineer asked in one sentence for a secret-hiding plugin; printing his secrets file then showed the keys redacted.
  • The 2 Oct GitHub scan: 359 public mods, 75 reaching the internet and 111 seeing every prompt.
  • You Should Know demo: a side agent warns that payment retries could double-charge, so Claude adds an idempotency key. It's off by default.
  • Pluto Security showed a pre-launch mod reading the Claude login file and sending it out with no warning; a Read(.env) deny rule doesn't stop a mod.
  • Advice: install only from people you trust, run claude plugin validate first, and start Claude Code in safe mode, which turns off every mod for that session. (Safe mode turns off the mods you installed; Claude Code's built-in mods keep running.)
YouTube thumbnail: New Claude Mod Update is Absolutely INSANE!
19
AI News Today / Julian Goldie Podcast
Pet mods; wrongly implies VS Code drawing
  • Prompt-built mods: an aquarium where each subagent hatches a fish, a pixel pet that levels up, /breathe, and an arcade band with snake.
  • Ideas: a terminal browser Claude can drive, and a live tree of subagents with model, run time and result.
  • Shows a community catalogue (heard as “mods.ai dojo”; it's mods.aidojo.si) listing over 359 mods with category filters.
  • Says mods work in VS Code, the SDK, Remote Control and the cloud. They run in all four, but what they draw shows up only over Remote Control, in the terminal on your own machine.
  • Two long ad breaks for his paid community, about a fifth of the video.
YouTube thumbnail: Claude Code Just Got a HUGE Customization Upgrade
20
AI avatar; admins can remove abilities
  • Covers the 3 Sep reveal: TypeScript functions with editor support, hooks that can say no, and plugins that draw.
  • Every side effect goes through one shared object, so Claude Code can track it, and admins can remove abilities for every plugin below them.
  • One hook catches a button press in both the terminal and the desktop app; a listen-to-everything hook becomes an audit log.
  • Anthropic said the demo thumbnails were AI-made but the demos and code were real.
  • About a fifth is ads for his community and a free strategy call.
YouTube thumbnail: You can now mod Claude Code · Claude Code news, Oct 2
Launch reactions; "You should know" needs telemetry
  • Community pushback: if everything can be reworked, why not open-source Claude Code, or let subscriptions work in other front ends?
  • v2.1.287 had 106 changes, including a fix for rm of the home folder losing its permission prompt when output was redirected to ~ or a wildcard path.
  • You Should Know needs telemetry and a direct connection to Anthropic.
  • Use case: a mod that blocks every command touching a customer-data folder.
YouTube thumbnail: Function Hooks: a place to cut into the loop · Claude Code news, Sep 4
The 3 Sep reveal and early questions
  • The 3 Sep reveal: two recordings, 2,000+ likes; feedback went to issue #91870.
  • Open questions then: can a hook change tool arguments, what happens on an error or timeout, and is a restart needed? All answered in today's docs.
  • Example idea: check text against brand rules before a file is written.
YouTube thumbnail: Claude Code Function Hooks: Hide Your Secrets From the AI
23
Credential guard, 20 passing tests, one miss
  • A WordPress credential guard from a four-sentence prompt: four files, and Claude wrote 20 tests that all passed.
  • Two checkpoints: swap the secret for a placeholder in the prompt, then swap it back just before the tool runs.
  • Limit: the username wasn't redacted. Pattern matching catches distinctive formats, not plain words.
  • A CLAUDE.md rule competes with every other instruction and can fade; a hook is deterministic and costs no context.
YouTube thumbnail: Claude Code Mods in 100 Seconds
Progress-bar pane; installing the samples
  • Built a task progress-bar pane with an ETA and a completion sound, plus a status bar showing time and tokens per answer.
  • Install the samples: clone Anthropic's playground repo, add its claude-code/mods folder as a marketplace, then install blast-radius@claude-code-playground-mods.
YouTube thumbnail: Claude Code just got a massive update
25
Token weather "about 80 lines" (the file is ~120); rm in a script gets past blast radius
  • Token weather is about 80 lines. Blast radius listed 9 files (1.1 MB): press 1 to run, 2 to refuse with a reason.
  • Anthropic plans to move more built-in features into mods, so you could strip Claude Code to a small core.
  • A script that calls rm gets past blast radius. Build your own readouts and guards first; skip strangers' mods until you've read the repo.
YouTube thumbnail: Function Hooks for Claude Code: Hooks as TypeScript Functions
The proposal's four ideas
  • The proposal's four ideas: hooks as TypeScript functions, earlier hooks wrapping later ones, hooking how the screen is drawn, and admins revoking abilities.
  • A mod has no file or network access of its own: everything goes through $, and code that goes around it fails validate.

Also covered (short cuts, recaps and trailers):

YouTube thumbnail: Claude Code Mods Are Game Changers. This One Saves Me Money.
  • A cut-down version of the cache-keeper segment from his longer video above.
  • Says the cache lasts 60 minutes; true on a subscription, but with an API key it's five minutes unless you change it.
YouTube thumbnail: What Are Claude Code Mods?
Prompt Engineering Short
  • A short cut of Prompt Engineering's longer video: inside vs outside, and how long a hook lives compared with a mod.
YouTube thumbnail: Claude Code Function Hooks (Guest Post by Ray Amjad)
  • Pre-launch (behind a beta flag): a separate walkthrough by Ray Amjad, posted six days after his own video. It repeats the secret redactor and adds two new demos.
  • A trigger.dev band that appears when a workflow starts and shows queued and running jobs; he asked Claude for several designs and picked one.
  • A bulk-SQL guard: a model judges whether a command touches over 100 rows, then asks and offers a dry run.
  • Session variables last one session; the store survives restarts. (He says it's shared per folder; in fact it's per plugin, shared by every session on the machine.)
YouTube thumbnail: Claude Code Is Now Moddable: Mods Explained (It Builds Them Itself)
  • A short recap: before, after or instead of; mods stack; the three samples; folder, code, validate, test, share; not sandboxed.
YouTube thumbnail: You Can Now Mod Claude Code Like a Video Game
  • A trailer for Drago Agent's longer video.
YouTube thumbnail: Claude Code v2.1.287: Claude Mods and Agent Plugins
Claude Code Changelog Appears auto-generated
  • You Should Know is experimental: /plugin enable cc-plugin-you-should-know@builtin.
  • Other 2.1.287 changes: in VS Code, move running commands or subagents to the background; a filter in the agents view; and Opus 4.7+ and Fable models default to 1M context on Bedrock and Vertex.
YouTube thumbnail: Claude Code Got Mods: Customize It From the Inside
  • A general explainer: watch, change or block; a delete guard, a memory panel, a custom spinner and instant slash commands.
YouTube thumbnail: Claude Code Just Got Mods
Griffin Wooldridge Short
  • Ideas: a context meter, a different code-review panel, and extra confirmation before touching production settings. The API may still change.

Eleven more videos (nine in other languages, two shorts) had no fetchable transcript, so they aren't counted.

Blogs and community threads worth reading

Pluto Security (22 Sep): the four findings above, on a pre-release build.

Wes Sander (17 Sep): the guards that were enabled and doing nothing.

Kevin Riedl, wavect (16 Sep): a risk-and-test table from a documentation and source review. Pre-launch, so ignore its setup steps.

Vanja Petreski: chained mods add delay, and removing file access doesn't sandbox a mod that can run programs.

Reddit launch thread: worries from "ripe for malicious mods" to lock-in.

Hacker News AGENTS.md thread (486 points): AGENTS.md only worked with telemetry on, because the mod sat behind a remote switch.

In our AI-Driven Engineering workshops, this hub is the mods session's reading list; the commands and skills workshop covers the lower rungs of the ladder, and HAL's AI infrastructure shows how it fits together. Still got a question? Try the FAQ.

Frequently Asked Questions

What is a Claude Code mod?

A plugin of small JavaScript or TypeScript functions that run inside Claude Code all session, letting through, changing or answering events like a tool call, and drawing on screen. On by default since v2.1.287.

What are hooks in Claude Code?

A settings hook is something Claude Code runs at a set moment, such as just before a tool runs. There are five types: a shell command, an HTTP request, an MCP tool, a prompt to a model, or an agent. It's ideal for hard rules like refusing a force-push, and it can do more than block: allow, ask you through the standard permission prompt, rewrite the tool call or add context for Claude. It can't draw panes, bands or buttons (it can only show text such as a message or spinner text), and a command hook keeps nothing in memory between runs, though it can save state to a file.

What's the difference between Claude Code plugins and skills?

A skill is written instructions Claude follows when your request matches. A plugin is the package that installs things: it can carry skills, commands, agents, settings hooks, MCP and LSP servers, and mods.

How do I install Claude Code plugins?

Add a marketplace with /plugin marketplace add owner/repo, run /plugin install name@marketplace, and run /reload-plugins after a shell install or an update. To try a mod in one window, use claude --plugin-dir ./my-mod.

Are mods safe?

Only as safe as their author: mods aren't sandboxed, and the sec-default guard only loads with managed settings or on Team and Enterprise plans. Read the code, run claude plugin validate, and re-check on updates.

Do mods cost tokens?

Drawing and listening cost nothing. A mod spends tokens when it calls a model ($.model.fork, $.model.complete or $.model.classify), submits a prompt ($.prompt.submit), or adds text to Claude's requests, and changing text it injects into Claude's instructions can break the prompt cache.

Do mods work in VS Code or the desktop app?

They draw in a terminal (IDE terminals included) and the desktop app's Code tab. In VS Code's chat panel, claude -p and the Agent SDK they run but draw nothing.

How do I turn mods off?

Disable one in /plugin, start a session with --safe-mode, or set "disableAllHooks": true in ~/.claude/settings.json to stop every mod you installed (it also stops settings hooks and your status line; mods your organisation manages keep running). Built-in mods keep running under --safe-mode and disableAllHooks; to stop one, disable it in /plugin (every built-in except the sec-default guard can be turned off there).

Where is the Claude Code plugins marketplace?

There isn't a single one: any GitHub repo with a marketplace file can be added with /plugin marketplace add, and Anthropic's official one is added for you. For mods, the largest catalogue we found is awesome-claude-code-mods (1,740 on 4 Oct 2026).

Methodology: all ten official Claude Code mods docs pages, the changelog and Anthropic's sample mods; 35 YouTube videos transcribed and read in full (34 about mods); the design thread and Pluto Security's report; 20 community repos checked for licence and calls; three mods for HAL's daily use plus the lab's force-push guard, built and tested on HAL (Claude Code 2.1.287 to 2.1.289). Every count, star and view figure is as of 4 October 2026 unless dated otherwise. Fact-checked again and corrected on 5 October 2026.

About the Author

Nathan House

Nathan House, Founder & CEO of StationX

Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.