Claude Code mods run unsandboxed: set the policy first
Claude Code mods are TypeScript plugins that can rewrite prompts and approve tool calls, with no sandbox. Here is the managed setting that limits them.
Your coding agent now takes plugins that can rewrite it from the inside. Anthropic shipped Claude Code mods in v2.1.287 on October 1: JavaScript or TypeScript functions that run inside Claude Code, see every prompt and tool call, and can change them. They are on by default. They are not sandboxed.
What actually happened
Per Anthropic's mods overview, a mod is a plugin with a register(on) function that attaches handlers to events like tool.call, prompt.submit and ui.render. A handler can watch an event, rewrite it, or answer it so the normal behavior never runs. Mods can draw panes in the terminal and the Desktop app's Code tab, add /commands that run without a Claude turn, and call a model on your plan or API key.
Anthropic is direct about the risk. The docs say a mod runs "with your permissions": it can read and write files, read environment variables that hold API keys, start processes, make network requests, and approve a tool call before you see a prompt. Turning on the Bash sandbox does not contain a process a mod starts.
Anthropic already ships some of its own features as mods, including /diff and AGENTS.md loading. The plugin system is now a core part of the product, not a side project.
Why it matters for your business
A mod is the strongest extension point Claude Code has ever had. We like it. A mod that blocks rm -rf, logs every tool call, or charts token spend is a real control. The same hook that approves a safe call can approve a bad one.
Decide the policy before someone installs a mod. The admin guide gives you one managed setting, allowManagedModsOnly, set under pluginConfigs for cc-plugin-sec-default@builtin. With it, only mods your organization deploys will load. Add disableSideloadFlags to block --plugin-dir as well.
Know what the built-in guard covers. On Team or Enterprise plans, or on any machine with managed settings, a built-in guard loads first. It keeps user mods from overriding your deny rules and managed hooks. It does not stop a mod from reading .env directly with its own file API.
Read a mod before you run it. claude plugin validate ./some-mod lists the events a mod handles and the API calls it makes, without running it. Look for $.process.run, $.http.fetch and $.env.get.
Key takeaways
- Claude Code mods shipped in v2.1.287 on October 1 and are on by default
- Mods can rewrite prompts, approve tool calls and read secrets; they are not sandboxed
- Set
allowManagedModsOnlyin managed settings to load only your organization's mods - The built-in guard keeps deny rules and managed hooks in front, but not a mod's own file reads
- Run
claude plugin validateon any mod before you install it
Rolling Claude Code out to a team? We set up managed settings, policy mods and audit logs so your coding agents work inside rules you wrote. See what we build, or tell us about your setup.
Sources: Claude Code Docs: Mods overview, Claude Code Docs: Manage mods for your organization.
- #claude-code
- #claude-code-mods
- #ai-coding-agents
- #managed-settings
- #developer-security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
TA419 faked an Anthropic exec to phish: MFA codes didn't help
Proofpoint says China-aligned TA419 impersonated an Anthropic employee and used browser-in-browser phishing to steal MFA codes and sessions. Move to passkeys.
Read itMicrosoft settles Cerence TTS suit: track your license end dates
Microsoft and Nuance agreed to settle Cerence's text-to-speech copyright suit over use after a license expired. Track the end date on every license you ship.
Read it