Claude Code Can Now Rewrite Itself — v2.1.287's "Mods" Pull Extensions From "Bolt-On" to "Inside the Core"
Claude Code v2.1.287 introduces "Mods," running JS/TS handlers inside the core process so they can replace everything from tool calls to screen rendering. They're on by default, but they run with the same privileges as Claude Code itself — making it essential to vet your distribution sources.
From "Bolt-On Extensions" to "Rewriting the Internals"
On October 1, Anthropic introduced "Mods" in Claude Code v2.1.287. Until now, extending Claude Code meant adding instructions with skills, adding tools with MCP servers, or slotting in external scripts via configuration hooks — all of which add behavior from outside Claude Code. Mods run handlers written in JavaScript/TypeScript inside the Claude Code process itself. Every time an internal event occurs — a tool call, a prompt being sent, a turn advancing, a command, or the screen rendering — your function gets called.
This feature is enabled by default as of v2.1.287. The environment variable CLAUDE_CODE_ENABLE_FUNCTION_HOOKS used during the early-access period is now ignored, so you can no longer use it to turn Mods off.
Observe, Rewrite, or Take Over Events
A Mod's handler (the official docs call this a hook) is invoked before an event is actually processed, and it can choose from three behaviors:
- Observe: Record what happened and let it pass through unchanged. Example: count the number of tool calls.
- Rewrite: Modify the event, then let it through. Example: append the tool-call count to the spinner display.
- Answer: Skip the original processing entirely and let the hook respond itself. Example: intercept and block a dangerous command, or route a single request to a different model.
Mods can also touch the screen. They can show a pane beside the conversation, display a banner above the prompt, or draw a status line or toast — and on top of that, they can replace or restyle the parts Claude Code draws itself, such as the spinner, tool-call lines, and the dialogs where Claude asks questions. However, only the permission prompt cannot be rewritten. The design deliberately prevents tampering with the confirmation screen shown to the user.
How Mods Differ From the Existing "Four-Piece Extension Set"
Mods don't replace the existing ways of extending Claude Code; they cover a different scope. Here are the key points, reorganized from the official documentation.
| Mechanism | Where it runs | What it can change | Language |
|---|---|---|---|
| Mod | Inside the Claude Code process | Tool calls, prompts, commands, turns, screen rendering | JavaScript / TypeScript |
| Config hooks | Outside the core (shell / HTTP / prompt) | Whether execution proceeds, tool arguments and results, added context | Scripts + settings.json |
| Skills | Instruction files Claude reads | Claude's knowledge and behavior | Markdown |
| MCP servers | External process / service | The tools available to Claude | Any language |
Only a Mod can draw on the screen; none of the other three can render anything. You can also bundle a Mod, a skill, and an MCP server together in a single plugin.
Some Built-In Features Already Run as Mods
Several of Claude Code's own features have already been reimplemented as Mods. You can check them under "Built-in" in the Installed tab of /plugin.
cc-plugin-diff: Handles the pane rendering for/diff. If you disable it,/diffitself remains and the built-in legacy version responds.cc-plugin-agents-md: LoadsAGENTS.mdas project instructions.cc-plugin-you-should-know: A side agent that keeps watch during longer tasks, flagging things you might overlook above the prompt (disabled by default).cc-plugin-telemetry/cc-plugin-sec-default: Send analytics records and act as a "checkpoint" that protects organization-managed settings from user-installed Mods.
Anthropic has also published samples such as token-weather (shows a forecast of remaining context above the prompt), blast-radius (intercepts rm -rf or force pushes and shows the blast radius), and replay-theater (reviews the edits from the previous turn via /replay). You don't even have to write the code yourself — describe what you want in conversation and Claude will write the Mod for you.
The "Same Keys," Handed Over Behind the Convenience
Mods are code that runs with your full privileges, and they are not sandboxed. The official documentation spells out that a Mod can:
- Read and write files, launch processes, and make network connections "as you"
- Read environment variables and configuration files — including any API keys you've stored there
- See and rewrite every prompt you send and every tool call Claude makes
- Approve a tool call before you're asked (even calls that an
askrule or your ownPreToolUsehook should have stopped) - Incur charges on your plan or API key
In other words, the more freedom you gain in extending Claude Code, the more the potential damage from installing an untrusted Mod widens — all the way up to "the same as Claude Code itself." These risks have actually been pointed out, and Anthropic warns that you should "only install from trusted authors and marketplaces." Before installing, claude plugin validate lets you list the events a Mod handles and the operations it requests (file reads, network access, and so on). For organizational deployments, administrators can restrict which Mods can be loaded with settings like allowManagedModsOnly, and --safe-mode or disableAllHooks can temporarily turn them off.
What Changes for Development Teams
UI and behavior that previously left you with only two options — "put up with the annoyance" or "wait for a core update" — can now be swapped out by teams themselves. Being able to bake your team's practices into the tooling — visualizing remaining context, adding a confirmation gate for dangerous commands, a diff view for reviews — pays off in real-world operation. At the same time, because Mods dig into the core internals in a way that skills and config hooks don't, it's safest to treat installing one less as "adding an extension" and more as "handing the agent your own privileges." Start with the official samples and a pre-install check via plugin validate, and for organizations, set a default line in your managed settings.
References: Claude Code Docs — Mods overview / Releasebot — Claude Code 2.1.287 / Crypto Briefing — Anthropic opens Claude Code to mods / GIGAZINE — A modding feature has been added to customize Claude Code


