AI News technology

Are Claude Code Mods Sandboxed? What They Can Access

Claude Code mods can alter prompts, tool calls, permissions, and the interface. They are not sandboxed, so install them only from trusted sources.

Claude Code mods can alter prompts, tool calls, permissions, and the interface. They are not sandboxed, so install them only from trusted sources.

0 Comments

Oct. 1, 2026Announced
CLI, DesktopWorks in
NoSandboxed
v2.1.287Needs

The short version

  • Claude Code mods are event handlers distributed through plugins.
  • They can alter prompts, tool calls, permission decisions, tool output, and the interface.
  • They run without a sandbox and have access to your machine through your account.
  • A built-in security mod limits user-installed mods on Team and Enterprise plans and machines with managed settings.

Anthropic introduced Claude Code mods on October 1, 2026, for people using Claude Code in the terminal or desktop app, as described in its mods announcement. A mod can change what happens during a session and what you see on screen. Installing one means trusting code that runs with your permissions.

What are Claude Code mods and how do they work?

A mod is a small TypeScript function attached to an event in Claude Code. Those events include sending a prompt, calling a tool, requesting permission, and drawing an interface element. Mods are packaged as plugins.

The function can act before an event, after it, in place of it, or on both sides of it. When multiple mods handle one event, load order determines the sequence: the first mod receives the event first and its final result last.

What can Claude Code mods change?

Mods can make the following changes:

  • Alter a prompt before the model receives it.
  • Stop a tool call, change its arguments, or try it again.
  • Grant or refuse a permission request.
  • Remove secrets from a tool result before Claude reads it.
  • Change or replace an interface element, including a tool result or question dialog.
  • Put buttons and input fields on screen for users and other mods to interact with.

A mod can also supply a command that runs its own function, or take the place of a feature supplied with Claude Code.

How are Claude Code mods different from settings hooks?

Settings hooks are handlers configured for points in Claude Code’s lifecycle. They can run shell commands, contact HTTP endpoints, call MCP tools, or use prompts and subagents. A mod’s handlers are functions running inside Claude Code.

What each can change

Capability Settings hook Mod
Respond to events Yes Yes
Block or change certain tool calls Yes Yes
Draw panes, buttons, or text fields No Yes
Replace Claude Code interface elements or features No Yes
Share variables among handlers in the same file No Yes

Settings hooks remain useful for actions such as checking or logging an event. Mods can also create interactive controls and take over parts of Claude Code’s behavior.

Are Claude Code mods sandboxed, and what can they access?

No. A mod runs with the access Claude Code has on your machine. Once loaded, it can:

  • Open or change files your account can access.
  • Launch programs and contact services over the network.
  • Read environment variables and settings files that may contain secrets.
  • Observe your prompts and Claude’s tool calls.
  • Alter prompts or tool calls, send a prompt on your behalf, or message another session.
  • Approve a tool call without waiting for you to answer.
  • Make model calls charged to your plan or API key.

A mod may approve a call that an ask rule would have sent to you, or one blocked by your own PreToolUse hook. It can change much of the interface, but it cannot alter the contents of a permission prompt. Install mods only from authors and marketplaces you trust.

On Team and Enterprise plans, and wherever managed settings apply, the built-in sec-default mod loads first. It limits actions by user-installed mods, including attempts to override permission deny rules. Administrators can place their own mods first; they must include sec-default in that list to retain its restrictions. Because mods arrive through plugins, marketplace controls apply to them too.

Where do Claude Code mods run, and where does their interface appear?

Mods are available in the Claude Code CLI and the Code tab of the desktop app. Event handlers can run in other sessions that load the plugin, although a mod’s visual elements appear only in certain interfaces.

Handlers and visuals by session

Session Handlers run Visual elements appear
Terminal, including an editor terminal or JetBrains plugin Yes Yes
Desktop app Code tab Yes Yes, apart from terminal-only elements
Desktop app WSL session No; plugins are unavailable No
VS Code extension chat panel Yes No
claude -p or Agent SDK Yes No
Remote Control through claude.ai or mobile Yes, on your machine In your machine’s terminal
Cloud session Yes, if the plugin reaches it No

Where a visual element cannot appear, a mod can instead provide text in the transcript or a command response.

What to do now

Check the author and marketplace before installing a mod. If you have its plugin files, run claude plugin validate on the plugin directory to inspect the events it handles and the operations it requests without running it. Anthropic’s getting-started documentation covers creating a mod.

FAQs

Is Claude Code’s /diff feature a mod?

Yes. The built-in cc-plugin-diff mod handles /diff and draws its pane in interactive terminal sessions. Disabling that mod in /plugin leaves the command available through Claude Code’s built-in implementation.

Which Claude Code version supports mods?

Mods are enabled by default in Claude Code v2.1.287 and later. Run claude –version to check your installed version.

How do I install a Claude Code mod?

  1. Find a plugin containing the mod in the Claude directory or a marketplace you trust.
  2. In a Claude Code session, run /plugin install token-chart@your-org, replacing the example plugin and marketplace names with yours. From a shell, use claude plugin install token-chart@your-org instead.
  3. If you installed or updated it from a shell while a session was open, run /reload-plugins in that session. Otherwise, the mod loads the next time you start Claude Code.

How do I check which Claude Code mods are loaded?

Run /plugin at the Claude Code prompt. The dim line beneath the tabs names and counts active installed mods. Built-in mods are excluded from that line; find them under Built-in on the Installed tab.

How do I turn off one Claude Code mod?

In /plugin, disable or uninstall the mod’s plugin from the Installed tab. Built-in mods cannot be uninstalled, though you can disable one there when its entry permits it.

Do Team and Enterprise plans restrict user-installed Claude Code mods?

Yes. Their sec-default mod limits user-installed mods. Team and Enterprise owners can also allow or block plugin marketplaces in the admin console. For Claude API and third-party API plans, administrators distribute managed settings to users’ machines.

Leave a Reply

Your email address will not be published. Required fields are marked *