Skip to content
The AI-First Web

Claude Code mods can approve tool calls before the user is asked

Anthropic's new plugin type runs unsandboxed code inside the coding agent. Treat each one like software with your login.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Claude Code mods can approve tool calls before the user is asked

AI-generated image for WebPulse. About our images

In brief
  • Anthropic's documentation says a Claude Code mod can approve a tool call before the user is asked. Mods are code that runs inside the tool.
  • Mods act with the user's permissions and are not sandboxed, so each one carries the access of the developer who installs it.
  • Leaders should decide which mods may load, have each one reviewed before install, and know the three off switches.

The permission prompt is where a developer decides whether an AI agent may act. Anthropic's documentation for Claude Code mods says a mod can approve a tool call before the user is asked. That means any mod, including third-party ones, can sit inside the approval step. The question for leaders is who vets that code.

What Anthropic released

Anthropic's documentation describes mods as plugins that change how Claude Code looks and works. The Decoder, which reported the launch, calls them middleware that runs inside the tool. Developers write them in JavaScript or TypeScript.

On the interface side, a mod can add panels with tabs, buttons and text fields. It can replace how Claude Code shows its own elements, including the spinner and the row for each tool call. On the behavior side, it can pause a tool call to put a question to the user. It can route a single request to another model. It can also register a slash command that runs the mod's code immediately, without a Claude turn.

Some built-in features are already mods. The documentation names /diff as one. The Decoder reports that mods work in the command-line tool and the desktop app, and only partly in the VS Code extension.

How a mod works

Each mod has a file called register.js, which Anthropic calls the hooks module. It tells Claude Code which events should trigger which functions. Think of a hook as a doorbell: when the event happens, the mod's code runs.

Anthropic's example uses two hooks. One fires just before every tool use, adds one to a counter and lets the tool proceed. The other fires when the spinner is drawn and appends the count to it. They can share the count because they live in the same file.

For any event, a hook has three options. It can observe and leave the event alone. It can rewrite the event before it continues. Or it can answer, taking over so the normal behavior never runs. Refusing a command is the documentation's example of answering.

3
Ways a hook can handle an event
Source: Anthropic, Claude Code mods documentation (accessed October 3, 2026)

What a mod can reach

Anthropic sorts a mod's reach into six areas. First, it acts on your machine as you. That means reading and writing any file your account can, starting programs and making network requests. Second, it can read secrets. If a developer keeps an API key in an environment variable or a settings file, a mod can see it.

Third, it sees the whole session: every prompt and every tool call. Fourth, it can change the session. It can rewrite a prompt or a tool call, send a prompt as though the developer typed it, or pass a message to a different session. Fifth, it can approve a tool call before you are asked. Sixth, it can use up your plan or API key by calling a model.

The fifth item is the one to dwell on. The Decoder reports that mods are not sandboxed and run with the user's permissions. Anthropic warns users to install them only from trusted sources.

6
Areas of access the documentation lists for a mod
Source: Anthropic, Claude Code mods documentation (accessed October 3, 2026)

A third party inside the approval step

Mods are not the first way to customize Claude Code. The documentation includes a section comparing mods with settings hooks, skills and MCP servers. Its notes on turning mods off also mention settings hooks. We have not seen that comparison's content, so we cannot say how those tools differ on approvals, or whether they could already approve tool calls.

What the documentation does say is specific. A mod can be a participant in the approval step, answering before the human is asked. That widens who you must trust, if you install mods. The vendor's defaults are one layer. Each installed mod is another.

That is not a flaw. Anthropic's own samples use the access for protection. The blast-radius sample intercepts dangerous shell commands, with recursive deletes and force pushes as its examples. It previews the effect and lets the user proceed or cancel. The sec-default mod is described as a model for enforcing policy.

Browser extensions took a similar route. They made browsers more useful, and they also became a place where trust was won or lost. The same lesson may apply here: the safety of an agent depends on its add-ons as well as its maker.

The Decoder reports one more example. Anthropic's first official mod, "You Should Know," runs a second agent next to the session. When that agent notices something important the user may have missed, it posts a "Heads up" note. It is a handy feature. It also shows how much of a session a mod can see.

What leaders should ask

Anthropic gives organizations some control. The Decoder reports that organizations can decide which mods are allowed to load. The documentation has a guide to managing mods across an organization, covering managed settings and reviewing a mod. It also points to a page on checking what a mod does before it is installed.

Put three questions to your engineering lead. Who decides which mods may load on company laptops, and where is that written down? Is a mod's code reviewed, as a new dependency would be, before it is installed? Do developers keep API keys in environment variables or settings files that a mod could read?

Know the off switches too. The documentation gives three. You can disable or uninstall one mod from the Installed tab in /plugin. You can start a session with --safe-mode, which turns off every mod for that session and your other customizations. You can set "disableAllHooks": true in ~/.claude/settings.json to stop every mod you installed, along with your settings hooks and custom status line. Under that last switch, what your organization manages keeps running.

3
Levels of off switch: one mod, one session, all sessions
Source: Anthropic, Claude Code mods documentation (accessed October 3, 2026)

A mod is not a theme. It is software that acts as your developer, with access to any keys kept in environment variables or settings files, inside the tool that acts for your developer. Review it like any other code with that much access.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Anthropic.

Share this insight