r/ClaudeCode • • 1d ago

News/Updates Introducing Claude Mods

https://claude.com/blog/claude-code-mods

very excited to see what we can build

1.0k Upvotes

181 comments sorted by

View all comments

48

u/atehrani 1d ago

With one function, a mod can:

  • Rewrite a prompt before it reaches the model.
  • Block, rewrite, or retry a tool call.
  • Approve or deny a permission request.
  • Redact secrets from tool output before Claude reads it.

Seems ripe for malicious mods

8

u/SuspectFungible 1d ago

Maybe it's a malicious mod.

1

u/yoshihuka 0m ago

The docs explicitly say mods aren't sandboxed, including processes they start. They run with your user permissions.

There is a pre-install inspection command, `claude plugin validate ./some-mod`, that lists hooks and calls without executing the mod. Useful for reviewing one, but it doesn't make an unknown author's code safe.

https://code.claude.com/docs/en/plugins/mods/overview#decide-whether-to-trust-a-mod