Claude Code Mods Let Developers Program AI Agent Behavior
Anthropic’s new Claude Code Mods let developers rewrite prompts, control tool calls, add UI features, and customize how AI agents behave.

Anthropic has introduced Claude Code Mods, a new extension system that gives developers much deeper control over how Claude Code behaves. Announced on October 1, 2026, Mods are small TypeScript functions that run inside Claude Code and can change how prompts, tool calls, permissions and parts of the interface work.
The important change is that developers are no longer limited to telling an AI agent what to do through prompts or configuration. They can now create a programmable layer between the user, the AI model and the tools the agent uses.
A simplified workflow looks like this:
Prompt → Mod → Claude Code → Tools
A Mod can rewrite a prompt before it reaches the model, block or rewrite a tool call, retry an operation, approve or deny permission requests, or redact sensitive information from tool output before Claude sees it. Mods can also modify parts of the Claude Code interface and add buttons, inputs and other custom functionality.
This opens up several interesting use cases for developers. A team could create a security Mod that requires confirmation before production commands are executed. Another Mod could automatically improve weak prompts before they reach Claude. Developers could also build a secret-filtering Mod that removes API keys or other sensitive information from tool results.
Anthropic has even started using Mods for some built-in Claude Code functionality. The company says the /diff feature now ships as a Mod, showing how the system could eventually make Claude Code more modular and customizable.
Mods are available in the Claude Code CLI and desktop app. Developers can install Mods through plugins or build their own using TypeScript. Anthropic also provides examples such as Token Weather, Blast Radius and Replay Theater to demonstrate what the system can do.
However, there is an important security warning. Mods are not sandboxed. Anthropic says they have the same access to the machine as Claude Code itself. That means users should treat a Mod like any other code they install and only use Mods from sources they trust.
For AI developers, this represents a bigger shift than just another Claude Code feature. AI agents are becoming programmable systems where developers can control not only the model's instructions, but also the rules, safeguards and behavior surrounding the agent.