Skip to content
Rush Commerce
Software & Dev3 min read

Claude Code mods run unsandboxed: set the policy first

Claude Code mods are TypeScript plugins that can rewrite prompts and approve tool calls, with no sandbox. Here is the managed setting that limits them.

Your coding agent now takes plugins that can rewrite it from the inside. Anthropic shipped Claude Code mods in v2.1.287 on October 1: JavaScript or TypeScript functions that run inside Claude Code, see every prompt and tool call, and can change them. They are on by default. They are not sandboxed.

What actually happened

Per Anthropic's mods overview, a mod is a plugin with a register(on) function that attaches handlers to events like tool.call, prompt.submit and ui.render. A handler can watch an event, rewrite it, or answer it so the normal behavior never runs. Mods can draw panes in the terminal and the Desktop app's Code tab, add /commands that run without a Claude turn, and call a model on your plan or API key.

Anthropic is direct about the risk. The docs say a mod runs "with your permissions": it can read and write files, read environment variables that hold API keys, start processes, make network requests, and approve a tool call before you see a prompt. Turning on the Bash sandbox does not contain a process a mod starts.

Anthropic already ships some of its own features as mods, including /diff and AGENTS.md loading. The plugin system is now a core part of the product, not a side project.

Why it matters for your business

A mod is the strongest extension point Claude Code has ever had. We like it. A mod that blocks rm -rf, logs every tool call, or charts token spend is a real control. The same hook that approves a safe call can approve a bad one.

Decide the policy before someone installs a mod. The admin guide gives you one managed setting, allowManagedModsOnly, set under pluginConfigs for cc-plugin-sec-default@builtin. With it, only mods your organization deploys will load. Add disableSideloadFlags to block --plugin-dir as well.

Know what the built-in guard covers. On Team or Enterprise plans, or on any machine with managed settings, a built-in guard loads first. It keeps user mods from overriding your deny rules and managed hooks. It does not stop a mod from reading .env directly with its own file API.

Read a mod before you run it. claude plugin validate ./some-mod lists the events a mod handles and the API calls it makes, without running it. Look for $.process.run, $.http.fetch and $.env.get.

Key takeaways

  • Claude Code mods shipped in v2.1.287 on October 1 and are on by default
  • Mods can rewrite prompts, approve tool calls and read secrets; they are not sandboxed
  • Set allowManagedModsOnly in managed settings to load only your organization's mods
  • The built-in guard keeps deny rules and managed hooks in front, but not a mod's own file reads
  • Run claude plugin validate on any mod before you install it

Rolling Claude Code out to a team? We set up managed settings, policy mods and audit logs so your coding agents work inside rules you wrote. See what we build, or tell us about your setup.

Sources: Claude Code Docs: Mods overview, Claude Code Docs: Manage mods for your organization.

  • #claude-code
  • #claude-code-mods
  • #ai-coding-agents
  • #managed-settings
  • #developer-security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.