Claude Code mods are not sandboxed, and version 2.1.289 fixes a deny rule they could override
Anthropic introduced mods for Claude Code on October 1, 2026. They are TypeScript functions, shipped inside plugins, that can rewrite prompts, change tool calls, and redraw parts of the interface. The documentation says mods are not sandboxed and run with your permissions, which covers your files, environment variables, and API keys. On Team and Enterprise plans a built-in mod named sec-default loads first and restricts the mods that users install. Versions 2.1.288 and 2.1.289 fix several cases where permission rules did not hold.
Anthropic announced mods for Claude Code on October 1, 2026. They require version 2.1.287 or later, and they are on by default. A mod is a function that Claude Code calls when an event happens, such as a tool call, a submitted prompt, or part of the interface being drawn. The two releases that followed the announcement, 2.1.288 and 2.1.289, include fixes for permission rules that a mod or a shell command could get around.
What a mod can change
Each time Claude Code does something, it emits an event. A mod hooks into an event and can run before it, after it, or instead of it. According to the announcement, one function can rewrite a prompt before it reaches the model, and it can block, rewrite, or retry a tool call. It can also approve or deny a permission request and redact secrets from tool output before Claude reads it.
A mod can also draw. It can add a pane beside the transcript or a band above the prompt, with buttons and text fields, and it can replace parts of the interface that Claude Code draws itself. The documentation names one exception: a mod cannot change what a permission prompt shows you. When several mods handle the same event, they run in the order they load.
Some built-in features now ship as mods. The /diff command is one of them, and you can turn its mod off in /plugin or replace it with your own version. Anthropic says it plans to move more built-in features to mods over time.
What a mod can reach on your machine
Anthropic states the risk directly: mods are not sandboxed, and they run with the same access to your machine as Claude Code itself. The documentation lists what a loaded mod can do:
- It can read and write files anywhere your user account can, start programs, and make network requests.
- It can read environment variables and settings files, including an API key you keep in either.
- It sees every prompt you send and every tool call Claude makes, and it can rewrite them.
- It can approve a tool call before you are asked.
- It can call a model on your plan or API key.
How to inspect a mod and turn mods off
If you turn on sandboxing, the sandbox isolates the Bash commands Claude runs, but a process that a mod starts runs outside it. Before you install a mod, you can run claude plugin validate on its directory. The hooks: and calls: lines in the output list the events the mod handles and what it asks Claude Code to do, and the mod itself does not run.
You can disable a single mod from the Installed tab in /plugin. The --safe-mode flag stops every installed mod for one session, along with your other customizations. Setting "disableAllHooks": true in ~/.claude/settings.json stops every mod you installed, in every session. That setting also stops your settings hooks and your custom status line. None of these options stops the built-in mods.
A mod's hooks also run where nothing is drawn: in the VS Code extension's chat panel, in claude -p, and in the Agent SDK. Only the terminal and the Code tab of the Claude Desktop app show what a mod draws.
What organizations get
Mods ship inside plugins, so existing plugin controls apply, and administrators can allow or block plugin marketplaces. On Team and Enterprise plans, and on any machine with managed settings, a built-in mod called sec-default loads first. Anthropic says it stops mods that users install from doing risky things, such as overriding permission deny rules.
Administrators can load their own mods first instead. Anthropic advises adding sec-default to that list to keep its restrictions. The managed setting allowManagedModsOnly stops the mods a user installed and leaves the rest of each plugin loaded.
What versions 2.1.288 and 2.1.289 fix
Anthropic released version 2.1.288 on October 2, 2026, and version 2.1.289 on October 3, 2026. Most entries in both releases are small fixes. Several of them concern permission rules:
- 2.1.289: a deny or ask rule on a nested part of a compound shell command now holds over a user-installed mod's approval on managed machines.
- 2.1.289:
Readdeny rules now apply to files that are @-mentioned, changed, or selected in the IDE through a symlink. - 2.1.289: a user-installed plugin can no longer rewrite the descriptions of sign-in tools that belong to an organization-managed Model Context Protocol (MCP) server.
- 2.1.289: Bash deny and ask rules no longer miss a command that follows an environment variable prefix or a bare variable assignment when the sandbox auto-allows commands.
- 2.1.288: a dangerous
rminside abash -corsh -cscript no longer runs without a prompt in bypassPermissions mode or under a shell allow rule. - 2.1.288: when a PreToolUse or PermissionRequest hook cannot be matched, or the tool's input cannot be serialized to JSON, the call is now blocked instead of the hook being skipped.
„They aren't sandboxed, and you should only install mods from sources you trust.“
Sources
Related
GitHub Copilot retires four models and makes Balanced its default code review effort
GitHub deprecated four models across all Copilot experiences on October 2, 2026: Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7. On the same day it made Copilot code review available through the REST and GraphQL APIs. Balanced is now the default review effort level, a change that took effect on September 28, 2026. According to GitHub's documentation, a Balanced review consumes more AI credits than a Lite one.
GitHub Changelogverified

Apple will add controls to Full Disk Access on macOS, citing risks from AI agents
Apple said on October 2, 2026, that it will add controls to Full Disk Access, the macOS permission that lets an app read nearly everything on a Mac. The company says some developers use the permission in ways that expose files, mail, messages, and browsing history without users fully understanding it. Apple expects the risk to grow as AI agents become more capable and autonomous. The post gives no date, no macOS version, and no description of the new controls.
Appleverified
AWS previews Well-Architected Agent, limited to Business+ Support plans and above
AWS announced a preview of AWS Well-Architected Agent on October 1, 2026. The service scans your AWS accounts on a schedule and returns recommendations for cost, security, resilience, and performance, ranked against business goals that you write yourself. Remediation scripts come attached, and the agent also reviews infrastructure-as-code templates on demand. Access requires an AWS Support plan at the Business+ tier or higher, and agent profiles are hosted in three US Regions.
AWSverified

