Claude Code Mods Ship in v2.1.287 With Default-On TypeScript Event Hooks
Developers can intercept, rewrite, or take over tool calls and UI renders — no sandbox included

Anthropic on October 1 shipped Claude Code Mods, a TypeScript and JavaScript extension system that lets developers intercept, rewrite, or answer events inside Claude Code's agent loop — the continuous cycle of model requests, tool calls, and result processing that drives every Claude Code session. Mods require Claude Code v2.1.287 or later and are on by default, and Anthropic has already migrated its own /diff command onto the same mechanism, beginning what the team describes as a longer-term effort to reduce Claude Code's built-in core and let users install specific capabilities as needed.
The release arrives alongside an observation from Tianyi Cui, the lead of DeepSeek AI's DeepSeek Harness project, who called it a "convergence of ideas" — both projects are building extensible, self-modifying agent environments. The architectural distance between the two approaches, though, is significant: Claude Code Mods hook into an existing agent loop; DeepSeek Harness makes the loop driver itself a replaceable component.
Three Hook Patterns Give Mods Middleware-Level Control
A Claude Code mod is a plugin that exports a single register(on) function. The on function installs event handlers for named Claude Code events: tool.call, ui.render, session.start, turn.complete, prompt.submit, and others. An optional filter object narrows the scope — { tool: "Bash" } targets only Bash tool calls, { component: "AbovePrompt" } targets only the UI render slot above the input field.
Each handler receives three arguments: $ (the host API object), the typed event, and next (a function representing the remainder of the middleware chain). The relationship between a handler and next defines three compositional patterns:
Observe: Call await next(e), capture the result, return it. The handler runs as a side effect without modifying any data.
Rewrite: Mutate the event object before calling next(e). This lets a mod replace a prompt before it reaches the model, alter Bash command arguments before execution, or change UI rendering props.
Answer: Return a value without ever calling next(e). The entire downstream chain is skipped; Claude Code receives the mod's return value. This is how a mod cancels a command — it returns { deny: "..." } without the Bash call ever executing.
The $ object exposes roughly 19 namespaces covering UI rendering ($.ui), session inspection ($.session), persistent state ($.state), filesystem access ($.fs), process execution ($.process), HTTP requests ($.http), tool invocation, slash-command registration ($.command), and model queries ($.model). State stored via $.state survives a hot reload; module-level JavaScript variables do not. That distinction matters for mods that accumulate data across multiple agent turns, because hot reload — generating a new version of a mod and loading it without restarting Claude Code — wipes module scope while preserving the host-managed state store.
Read more: Claude Code adds AGENTS.md support, and the mods system previews
Token Weather, Blast Radius, and Replay Theater Show What Hooks Make Possible
Anthropic's official getting-started tutorial demonstrates three mods that span the three hook patterns and three points in the agent execution timeline.
Token Weather attaches to session.start and turn.complete events using the observe pattern to read context-window occupancy via $.session.getContextUsage() after each turn. It stores a rolling window of twelve readings in $.state. A separate ui.render hook for the AbovePrompt component slot reads that history and renders a weather-metaphor status bar above the input field: clear sky below 25 percent occupancy, clouds between 25 and 50, showers between 50 and 75, storm between 75 and 90, and a "compact soon" alert above 90. The entire implementation is approximately 80 lines of TypeScript. Because all data lives in $.state, the weather bar survives hot reloads — a developer can ask Claude to adjust the warning threshold or tighten the layout, hot-load the revised mod, and the bar continues updating without losing its reading history.
Replay Theater uses the observe pattern on tool.call events filtered to Edit and Write tool calls, recording the before-and-after file state for each operation. It registers a /replay slash command via $.command that opens a UI panel stepping through the recorded diffs in order. In the tutorial's demonstration of a function rename — greet changed to welcome — the panel recorded five edits across three files. The panel presents one diff at a time, letting a developer retrace what Claude changed without touching the files themselves. Replay Theater does not undo edits; it is an audit and review mechanism, not a rollback tool.
Blast Radius uses the answer pattern on Bash tool calls classified as high-risk. When it detects commands like rm -rf or find ... -delete, it runs a dry-run or status query to estimate impact, opens a UI panel with the results, and holds the chain until the user confirms or cancels. In the tutorial's example, rm -rf build would have deleted nine files totaling approximately 1.1 megabytes; the confirmation panel showed that summary before any file was touched. On cancellation, the mod returns a { deny: ... } object and never calls next(e) — the Bash command is never executed.
Mods Carry Claude Code's Machine Permissions — No Sandbox Included
Anthropic's own documentation explicitly states that mods run with the user's permissions — reading and writing files anywhere on the machine, starting programs, and making network requests — and that "mods aren't sandboxed." That language is easy to overlook in the context of a feature announcement focused on demos, but it defines the trust model for the entire ecosystem: installing a third-party mod is an act of substantial trust.
Security researchers at Pluto Security documented the concrete attack surface in testing before the GA release. A mod with default permissions can read ~/.claude/.credentials.json, which holds the Claude Code OAuth credential, and ~/.claude/history.jsonl, which in their test contained an 834 KB record of every prompt typed across all projects and sessions. A mod that silently exfiltrates either file — while displaying a useful feature to the user — has full network access via $.http to transmit that data anywhere. Anthropic's sec-default mod, which loads first in the middleware chain on Team and Enterprise plans, is designed to guard what an organization manages from user-installed mods; it does not restrict filesystem reads.
The practical implication for teams deploying Claude Code is that mod installation policies need to be treated similarly to npm package trust policies, but with higher stakes — a malicious npm package can harm a build; a malicious mod can exfiltrate the conversation history of every Claude Code session on a developer's machine. Anthropic's documentation recommends running claude plugin validate on any mod before installing, which lists the $ methods and environment variables the mod references without executing it.
DeepSeek Harness Takes the Same Idea Down to the Agent Loop Driver Itself
Tianyi Cui framed his comparison carefully. He celebrated what both projects share — making agent environments extensible, letting the agent write its own extensions, enabling sharing — then drew a precise architectural line. Claude Code opens hooks into a running loop; DeepSeek Harness, which his team leads, makes the loop driver, model adapter, tool registry, filesystem service, and subprocess service all replaceable plugins.
DeepSeek Harness is built on Cordis, a Node.js meta-framework for plugin-based systems. In Cordis, plugins contribute typed services (injectable dependencies), event streams, and reversible lifecycle effects to a shared context object. The result is that every architectural layer of the agent harness is a Cordis plugin: swapping one out requires only pointing to a new implementation that satisfies the same service interface.
The practical consequence of this design is visible in how DeepSeek Harness handles execution environments. It abstracts the filesystem and child-process interfaces as injectable services. Every tool that uses those services — the Bash execution tool, the PTY terminal, the LSP language server — automatically redirects when you replace the service implementations. Replacing both with remote-sandbox implementations migrates the entire execution environment — Bash, terminal, and LSP — to the sandbox without touching individual tool code. No equivalent substitution is possible in the Claude Code Mods architecture, where the execution environment is fixed and hooks can only modify what happens at event boundaries within it.
This is not a criticism of Claude Code Mods — the two projects serve different audiences. Claude Code Mods are production-ready infrastructure for developers who use Claude Code daily and want to extend its behavior without building their own agent framework. DeepSeek Harness is infrastructure for developers who want to compose a custom agent system from replaceable parts, released under an MIT license and still in developer preview with no stability guarantees.
Read more: Claude Code's AI-drafted session failure reports signal a shift in feedback
Self-Modifying Agents: Hot Reload Now, Profile Persistence Later
Both systems include mechanisms for the agent to extend itself at runtime. In Claude Code, a developer can describe a desired mod in natural language, have Claude generate the TypeScript, load it into the current session via hot reload, and iterate on it without restarting. Mods generated this way are session-local until the developer saves the file and installs it as a persistent plugin. Thariq Shihipar, an Anthropic engineer on the Claude Code team, demonstrated a next-steps mod: after a task completes, the mod surfaces suggested follow-up actions with runnable skill or command links, reducing the gap between completing one step and starting the next.
DeepSeek Harness has a formalized version of this through Creator Mode. The agent can inspect the current plugin composition, write a new plugin or configuration package, and install it via the Plugin Manager. Hot-update mode lets newly installed components become available within the running session. Configurations saved through Creator Mode persist to the active profile and survive restarts — a distinction from Claude Code where persistence requires the developer to manually save and reinstall the generated mod file.
Both approaches represent the same underlying shift Tianyi Cui identified: the set of things a developer can ask their agent to do is expanding beyond "complete this task" to include "modify the tooling used to complete tasks." What differs is the scope of that modification — event-level interception in Claude Code, component-level replacement in DeepSeek Harness — and whether the resulting configuration survives a restart automatically or requires an explicit save step.
The more consequential near-term development to watch is whether Anthropic's stated plan — thinning Claude Code's built-in core and migrating more features to Mods — proceeds at a pace that meaningfully expands what event hooks can reach. The migration of /diff is a first data point. If tool registration, permission management, and model-selection logic follow onto the Mods layer, the architectural gap between the two systems narrows from both sides.