The extension boundary moved inward.
Claude Code 2.1.287 added Mods. Its release note says plugins may now modify deeper behavior. The same release added a built-in mod that runs a side agent and flags things it thinks the user or main agent may have missed.[1]
The mod documentation supplies the sharper definition. A mod is a plugin whose JavaScript or TypeScript handlers run inside Claude Code. A handler can watch an event, change it, or take it over. Named events include a tool call, a submitted prompt, and interface drawing.[2]
The right review unit is not the menu item. It is every event the mod can intercept.
List behavior before benefits.
The documentation says a mod can draw panes, replace parts of the existing interface, hold or answer a tool call, route a request to another model, and run a command without a model turn. Its handlers can also share variables inside the file.[2]
Those powers may produce useful controls. They can also change what the operator sees, what the agent sends, and whether a tool runs. A useful install review names each handler, its event, the data it reads, the result it can replace, and the code path that disables it.
Package scope is runtime scope.
The plugin overview says an enabled plugin becomes part of every session, not only the sessions where a person invokes it. Plugin MCP servers run beside enabled sessions, hooks fire on their events, and plugin code runs with the user's permissions.[3]
That makes provenance and update policy part of behavior review. Record the source, exact version, installed scope, update route, loaded surfaces, and ejection command. Repeat the review when the package changes.
Test the disagreement path.
A mod that advises, blocks, reroutes, or redraws needs an adversarial fixture. Feed it a tool call that should pass and one that should stop. Check the original request, the changed request, the visible notice, the final result, and the behavior after the mod is disabled.
- Inventory every event handler and direct command.
- Run allow, block, error, and disable fixtures.
- Compare the original event with the event that continued.
- Restart a clean session and prove the mod is absent.
The fuseboard below drafts that review. It does not inspect, install, enable, test, or approve a mod.