Claude Code's /diff is now a mod you can delete

The /diff command in Claude Code is now a mod, a small TypeScript function you can switch off in /plugin or replace with a version you wrote yourself. /diff is the clearest example of mods, a new extension layer that Anthropic announced on the Claude blog and that is available today in the Claude Code CLI and desktop app.
At a glance
- Anthropic has added mods to Claude Code. They are TypeScript functions, packaged inside plugins, that can rewrite prompts, add interface elements, replace built-in features or add entirely new functionality.
- Each mod hooks into an event Claude Code emits, such as a tool call or a permission request, and runs before it, after it, instead of it, or wrapped around it.
- Mods are not sandboxed and run with Claude Code's own access to your machine. On Team and Enterprise plans, a built-in mod called sec-default loads first to block risky moves.
If you have not been following, Claude Code already had two ways to extend it. According to GitHub, plugins are lightweight packages that bundle slash commands, subagents, MCP servers and hooks, and you install or disable them with the /plugin command. Hooks, as Pushary describes them, are shell commands that run at fixed lifecycle events. They read a JSON event on stdin and answer with an exit code or JSON on stdout.
Anthropic says hooks could not rewrite events, draw UI or replace features
According to Anthropic, developers wanted more control over how Claude Code works without having to wait for the team to ship each feature. The company says hooks gave them some of that control but cannot rewrite events, draw new UI or replace features, and mods can. The design was posted on GitHub before launch so developers could give feedback.
The hooks reference shows where those limits sit. According to Pushary, which checked the official reference on 29 September 2026, there are 33 hook events, and only some of them can block anything. PreToolUse can stop a tool call. PostToolUse cannot, because by then the tool has already run.
Pushary also notes that exit code 2 means different things on different events. It stops the tool on PreToolUse and the turn on Stop, blocks nothing on SessionStart and is ignored on PermissionDenied. Some rewriting already existed through per-event fields such as updatedInput, updatedToolOutput and displayContent, but hooks had no general way to rewrite an event.
A mod runs before, after, instead of or around any event Claude Code emits
Every time Claude Code does something, it emits an event. Calling a tool, asking for permission and drawing part of the screen are all events. A mod is a function attached to one of them. It can run before the event, after it or instead of it, or it can wrap the event and run code on both sides.
With a single function, a mod can rewrite a prompt before it reaches the model, block, rewrite or retry a tool call, approve or deny a permission request, or redact secrets from tool output before Claude reads it. It can also edit or replace parts of the interface, such as a tool result or a question from Claude.
Mods can add buttons and inputs, and other mods can respond when you press them. When several mods hook the same event, they run in load order. The first mod to load sees the event first and the result last, which is how mods from different authors stack. Think of nested Russian dolls: you open the outermost one first and close it last.
Today a mod can target the terminal, the desktop app or both. That lets one author write a single mod for both places or keep separate versions for each.
The built-in /diff ships as a mod, and Claude Code can write new ones
Some built-in features of Claude Code now ship as mods, and /diff is one of them. You can turn it off in /plugin or put your own version in its place. Anthropic says it plans to move more built-in features to mods over time, so you can pare Claude Code down to a small core and add back only what you want.
You do not have to write the TypeScript yourself. If you ask Claude Code for a mod, it can write the code, install it and hot reload it in your current session. Mods ship inside plugins, so you install and share them like any other plugin. To share one, you package it in a plugin and submit it to the Claude directory.
On Team and Enterprise plans, a mod called sec-default loads first
Since mods live in plugins, existing plugin controls apply to them. Admins can allow or block plugin marketplaces. On Team and Enterprise plans an owner does this in the admin console. On Claude API and third-party API plans, admins push managed settings to users' machines. According to Claude Code Docs, managed settings rank above every other settings level, apart from a few security-sensitive exceptions.
On Team and Enterprise plans, and on any machine with managed settings, sec-default (short for "security default") loads before other mods. It stops mods that users install from doing risky things, such as overriding permission deny rules, and you can read its source code. Admins can load their own mods first instead, but then they should add sec-default to their list to keep its restrictions.
Anthropic gives three examples of what teams can build: a pane beside the conversation that shows CI/CD pipeline status and updates as builds pass or fail, a confirmation step before any command touches production config, and an audit mod that loads first and records every call made by every other mod.
Mods run unsandboxed with the same access as Claude Code
The announcement states the risk plainly. Mods run with the same access to your machine as Claude Code itself, and they are not sandboxed. Anthropic advises installing them only from sources you trust, the same way you would treat any other code on your computer.
Unsandboxed execution has been a real problem for Claude Code before. According to Penligent, CVE-2026-55607 affected Claude Code 2.1.38 through 2.1.162 and was fixed in 2.1.163. It was a Git worktree path confusion that let a malicious repository with prompt-injection content reach unsandboxed code execution on the developer's machine. Penligent argues that features which each look reasonable on their own can combine into a host compromise.
The announcement says sec-default loads on Team and Enterprise plans and on machines with managed settings. It does not mention any default guardrail for anyone else. In our view, that is an odd gap: solo developers have no admin vetting their marketplaces, yet they appear to be the group that gets no built-in restriction on what an installed mod can override.
Which built-in features follow /diff
Anthropic says more built-in features will move to mods over time, but the announcement names none besides /diff and gives no schedule. The Claude directory is where to watch, since plugins with mods can be installed from it today and authors can submit their own. We do not yet know how fast that catalogue will grow, or how many admins will replace sec-default rather than keep it.
Related stories
- Claude Mods ship in weeks, and you can flip them on now
- DeepSeek Harness v0.2 lands on macOS and Windows, not Linux
- OpenAI's Decisions API picks an answer in 150 milliseconds
- Claude's hillclimb cut support costs to about a fifth
- Microsoft Copilot gets a Code mode on GitHub Copilot tech
- Cursor's new bot follows each pull request into production
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
