Anthropic 为 Claude Code v2.1.287 推出 Mods:用 TypeScript 函数改写工具调用与界面
Claude Code v2.1.287: Skills Instruct. Mods Decide.
Anthropic 于 2026 年 10 月 1 日发布 Claude Code Mods,需 Claude Code v2.1.287 或更高版本,官方称其为可改变 Claude Code 工作方式的小型 TypeScript 函数,随插件分发,在 CLI 和桌面端可用。
原文梳理了 Mods 与 Skills、MCP 的分工和可挂载的事件点,并提醒 Mods 无沙箱、可读取文件与密钥的风险。
You ask Claude Code to clean up a directory. It wants to run a delete command, so a dialog pops up: allow or deny. The dialog never tells you which files the command would remove. You press Yes without knowing what you are agreeing to. That is not a skill problem on your side — the permission system only decides whether to ask, not what would happen after. On October 1, 2026, Anthropic shipped Mods, and this position is now yours.
Facts in this post come from the official announcement and docs (checked 2026-10-02/03). I have not run every step myself; Mods require Claude Code v2.1.287 or later, and if your UI differs, trust your build.
Do it first: two chat sessions
Skip the architecture. Open a Claude Code session and type:
Make me a mod that shows the current git branch above the prompt box.
Claude writes a plugin directory — a manifest, a hooks.json, and a register.js — you approve hot reloading when the first file lands, and at the end of that turn the branch name sits above your prompt. That is session one.
Session two: change the display to a tool-call counter. One line, save, effective at the end of the turn. No Node.js install, no bundler — Claude Code loads your .js and .ts directly.
What just happened, in plain words: you wrote one function that tells Claude Code "whenever you are about to do something, come through me first."
The three layers, finally straight
Skill is the manual. Instructions written for the model. But a manual cannot stop a hand — it says what to do and the model may still do otherwise.
MCP is the controller. External devices: databases, APIs, browsers. More games to play, same game rules.
Mods rewrite the game itself. The game is still the game, but interface, numbers, and behavior can all change. Officially: "small TypeScript functions that change how Claude Code works," shipped inside plugins, working in CLI and desktop.
One sentence: Skills tell it how. Mods decide for it.
Where a mod can hook
- tool.call — allow, rewrite arguments, or deny (the deny reason is read by Claude as the tool result), even bypass the original tool and return your own result.
- prompts — rewrite user input before it is sent; replace or drop individual system-prompt sections.
- turn.step — fires before each model request and may change the model field. The capability is documented; a production "route by task" mod does not officially exist yet, so do not build on it today.
- ui.render — panes, the band above the prompt, even re-drawing tool rows and the spinner.
Handlers form a middleware chain: on(event, matcher, handler) with ($, e, next). Call next(e) to observe, next({...e}) to rewrite (events are deeply frozen), or return without calling next to answer the event yourself — a deny short-circuits everything downstream.
The proof: Claude Code mods itself
The anthropics/claude-code repo ships four built-in mods under mods/: diff (the /diff command), agents-md (AGENTS.md support), telemetry, and sec-default (organization policy guard). The features you use daily are written with the same mechanism you are about to use.
Read this before installing anything
Official words: "Mods run with the same access to your machine as Claude Code itself. They aren't sandboxed." A loaded mod can read your files, read API keys from environment variables, see every prompt, approve tool calls on your behalf, and spend your quota. Install only from sources you trust; a mod Claude wrote for you is convenient, but once approved it runs as you. The docs show how to list a mod's registered events before you load it.
Skip these for now
- Model-routing mods: capability documented, no official reference implementation yet.
- Writing a command-audit mod from scratch: command parsing leaks edge cases; start by modifying the official blast-radius sample.
- Treating mods as a backup: an interceptor is not a backup.
Back to that dialog: with blast-radius installed, you see which paths a command would touch before you press Yes — and you are still the one pressing it. Anthropic put it best: "We want Claude Code to feel like yours."
Sources
- Announcement (2026-10-01): https://claude.com/blog/claude-code-mods
- Mods docs: https://code.claude.com/docs/en/plugins/mods
- Built-in mods: https://github.com/anthropics/claude-code/tree/main/mods
- Sample mods: https://github.com/anthropics/claude-code-playground/tree/main/claude-code/mods
来源:Google AI:DEV 作者专属(RSS) · dev.to