---
title: 'In the News: October 1, 2026 (Extra 4)'
description: "Anthropic's Claude Code mods let plugin code rewrite tool calls and answer permission requests. The post says mods are not sandboxed."
canonical_url: 'https://darkfactory.dev/news/2026-10-01-extra-4'
markdown_url: 'https://darkfactory.dev/news/2026-10-01-extra-4.md'
collection: news
date_published: '2026-10-01T19:40:00-04:00'
date_modified: '2026-10-01T19:40:00-04:00'
---

# In the News: October 1, 2026 (Extra 4)


One item this edition: Anthropic's announcement of mods for Claude Code, small TypeScript functions that can intercept, rewrite or replace what the agent does, including answering its permission requests.

## 1. Claude Code mods let plugin code rewrite tool calls and answer permission requests

**[Customize Claude Code with mods in TypeScript](https://claude.com/resources/articles/claude-code-mods)** · Anthropic · claude.com, October 1, 2026

Anthropic describes a mod as a function that hooks one of the events Claude Code emits, such as calling a tool, asking for permission, or drawing part of the screen. A mod can run before the event, after it, or instead of it. According to the post, one function can rewrite a prompt before it reaches the model, block, rewrite or retry a tool call, approve or deny a permission request, and redact secrets from tool output before Claude reads it. Mods ship inside plugins, work in the CLI and the desktop app, and are available at launch. Anthropic says hooks "can't rewrite events, draw new UI, or replace features." The built-in `/diff` command is now a mod that can be turned off or replaced, and the company says it plans to move more built-in features the same way.

The post is direct about the risk: "Mods run with the same access to your machine as Claude Code itself." On Team and Enterprise plans, and on any machine with managed settings, a built-in mod called `sec-default` loads first and stops user-installed mods from "doing risky things, like overriding your permission deny rules." The post describes no equivalent default for other installs. We read the announcement, not the linked documentation or the `sec-default` source.

**Why it matters:** Plugins can now sit in the permission path instead of only watching it. A mod that auto-approves requests or rewrites tool calls changes what your deny rules actually protect, so a mod deserves the same review as any other code with shell access. Teams on managed settings get a default guard; everyone else should check what a mod hooks before installing it.
