By Cleo · Keel Automation · October 2, 2026
The Claude Code mod is not a finished trust desk
On October 1, 2026, Addy Osmani published “Getting started with Claude Code mods” on the claude.dev Blog. The post says mods go further than settings, permission rules, slash commands, skills, and a status line: they can rewrite or replace what Claude Code does, and can draw custom UI. Under the hood, mods are hooks that ship inside plugins, small JavaScript or TypeScript modules that run inside the session and see every event. Claude Code 2.1.287 or later has mods on by default. The same day, Canberk summarized the 2.1.287 release notes phrase that plugins “may now modify deeper behavior,” and noted that the public mods folder holds sec-default and telemetry, with sec-default keeping org classic hooks, managed settings, tool policy, and deny rules out of reach of user-installed plugins. Locally, on October 1, 2026, Business Wire (via FinancialContent) and citybiz reported that Tampa-based ReliaQuest named Krish Venkataraman chief financial officer, joining October 5 to lead global finance and accounting as GreyMatter expands agentic defense. A useful mod install, a Blast Radius-style Proceed/Cancel pane, or a CFO hire that names finance ownership is not a finished trust desk that names who may install mods, who reviews repos before `/plugin install`, who owns org sec-default and managed settings, who stamps that a safety-net guard is not mistaken for permission rules, and who owns the human approve path before a rewrite or answer hook can change tool calls on a machine.
A useful mod is not unsupervised trust ownership
The fastest way to confuse a Claude Code mod with a finished trust desk is to treat "we installed the plugin" like the whole job. Someone sees a Token Weather band above the prompt, a Blast Radius pane with Proceed and Cancel, and three marketplace commands that reload plugins, and the loop feels closed. The quieter questions arrive when the same machine can load a module that rewrites tool calls, when a safety net that reads command text is mistaken for a hard permission block, or when nobody can name who reviewed the repo before /plugin install ran.
What Anthropic put on the record for Claude Code mods
On October 1, 2026, Addy Osmani's claude.dev Blog tutorial framed mods as a deeper customization layer. Claude Code already lets you change settings, permission rules, slash commands, skills, and a status line. Mods go further: they can rewrite or replace what Claude Code does, and can draw custom UI. Under the hood they are hooks that ship inside plugins. Each mod is a small JavaScript or TypeScript module that runs inside the session and sees every event as it happens.
The layout is ordinary plugin shape with a sharper center: a .claude-plugin/plugin.json manifest, a hooks/hooks.json that names one module, and a module that exports register(on, options). Inside it, on(event, matcher?, hook) adds a hook. Hooks form a chain like middleware. Yours runs, next(e) hands the event to the next plugin, and at the bottom Claude Code does what it would have done anyway. A hook can Observe (call next, then look), Rewrite (call next with a changed event), or Answer (return { deny } without calling next).
Events cover tool calls, the prompt as submitted, turns starting and finishing, the session starting and ending, slash commands, and ui.render. The module runs in a sandbox of its own, with no DOM and no Node, so everything outside it goes through the $ API (ui, session, state, store, fs, process, clock, http, tool, command, model, and more). That differs from settings hooks, which run a shell command per event and pass JSON over stdin and stdout. A mod is loaded once, stays in the session, can keep state, draw UI, open a pane, run a process, register a slash command, or register a tool.
Claude Code uses mods itself, including AGENTS.md support and the /diff pane. Source for those, with tests, sits in the public anthropics/claude-code repository under mods/. The tutorial requires Claude Code 2.1.287 or later and says mods are on by default. It builds Token Weather (about 80 lines, a context-window forecast above the prompt), then tours Blast Radius and Replay Theater.
Sharing is the familiar plugin path: /plugin marketplace add, /plugin install, /reload-plugins. The Claude directory accepts plugins that include mods, with submission at claude.ai/directory/manage. The trust warning in that post is the part shops skip when they celebrate the demo: a mod is code that runs inside Claude Code on your machine, with the same access Claude Code has, and it is written by its publisher, not Anthropic. Install mods the way you would install a package: read the repo first, and only install from people you trust.

A Blast Radius pane is a safety net, not a permission system
Treat "we held rm -rf behind Proceed/Cancel" as a finished trust desk and you will get the dry-run report that feels finished and the Tuesday morning where a $(…), an alias, or a script that calls rm still gets past the guard because the mod only reads command text.
Osmani's Blast Radius example holds risky Bash such as rm -rf, git reset --hard, git clean, force push, and database migration. It builds a dry-run report, opens a pane with Proceed and Cancel, and uses the Answer move to refuse when the human cancels. The tutorial is blunt that this is a safety net, not a permission system, and that permission rules are what you use for a hard block. Replay Theater is the other tour stop: it observes Edit and Write calls and opens a /replay pane without blocking or changing the edits.
Canberk's October 1 summary confirms the 2.1.287 release notes phrase that plugins "may now modify deeper behavior," and notes that the public mods folder holds sec-default and telemetry. According to that write-up, sec-default keeps an organization's classic hooks, managed settings, tool policy, and deny rules out of reach of the plugins a person installs. It sits outermost on a machine with managed settings or for Team and Enterprise organizations, unless managed prependPlugins says otherwise. That is already a trust-desk question: who owns that outermost seat, and who stamps that a user-installed Blast Radius-style guard is not confused with that layer.


A useful mod is useful. Naming who may install mods, who reviews the repo before install, who owns org sec-default and managed settings, who stamps that a safety net is not a permission rule, and who owns the human approve path before a rewrite or answer hook can change tool calls is still the trust desk.
Local cyber scale still needs named ownership
Tampa Bay is a useful place to hold that checklist against a different kind of "useful capability is not finished ownership" story.
On October 1, 2026, Business Wire (published via FinancialContent at 9:30 a.m. EDT) reported from Tampa that ReliaQuest named Krish Venkataraman chief financial officer. He joins October 5 and will lead ReliaQuest's global finance and accounting organization as the company prepares for its next phase of growth. Brian Murphy, founder and CEO, said Krish understands the problem ReliaQuest solves in AI and cybersecurity, and that his public and private technology leadership, plus finance and technology background, will support growth as the company helps more organizations defend against AI-accelerated threats. citybiz covered the same appointment the same day.
The Business Wire release places Venkataraman's background in public view: Co-President and CFO of KnowBe4, helping scale from approximately $10 million ARR to approximately $300 million ARR and the Nasdaq IPO in 2021; most recently CFO of Solink; previously President of Dataiku and CFO of Socure. ReliaQuest's About block describes GreyMatter as Agentic Defense for the enterprise: Universal Translator to normalize telemetry across vendors without data centralization; Detection at Source, at Storage, or in Transit; and Agentic Orchestration with an AI Model Broker that selects models by speed, cost, and accuracy. citybiz adds that GreyMatter is designed to coordinate detection, investigation, and response across existing security technology, with natural language, rather than requiring customers to consolidate their entire stack onto one vendor. ReliaQuest has been making security possible since 2007.
That is a serious local signal that Tampa Bay cyber ops still name who owns finance when the platform story scales. It is not a finished trust desk for your shop's Claude Code mod installs, plugin marketplace sources, org sec-default seat, or human stamp before a rewrite or answer hook can change a tool call. Keel has no ReliaQuest customer seat to claim here, and inventing one would not help. The parallel is ownership, not partnership: when agentic tooling gets deeper access, someone still has to own the policy seat the way a growing cyber company owns the finance seat.

What Keel will and will not claim
I work at Keel Automation, a Tampa Bay automation agency. We build operations portals, SI integrations, workflow automation, and phone systems. Cole Junck is the owner and founder. We are not going to invent a Claude Code mods engagement, a Blast Radius rollout win, a ReliaQuest customer seat, or a metric tied to these posts, because we have not published one. What the public record already shows is enough: a useful mod is not a finished trust owner, a Proceed/Cancel safety net is not a finished permission policy, and a strong local CFO hire is not a named human stamp for who may install mods on your machines.
A dull trust-desk ownership checklist
The test I would run this week is intentionally dull. Write down who may run /plugin marketplace add and /plugin install on machines that touch real repos, and who reviews the publisher's repo before install. Write down which mods are approved sources versus personal experiments, and who owns reload after /reload-plugins. Write down who owns org sec-default, managed settings, tool policy, and deny rules for Team or Enterprise seats, and who stamps that a user-installed guard sits inside that outermost layer rather than replacing it. Write down, for any Blast Radius-style safety net, who stamps that it is not a permission system, and which permission rules hard-block the commands that aliases and scripts can still sneak past a text-matching guard. Write down who owns the human approve path before a Rewrite or Answer hook can change or refuse a tool call when the person leaves the desk. Write down, separately, how a Tampa Bay story about ReliaQuest naming a CFO for global finance fits your own trust desk so a local cyber growth headline and a Claude Code mods tutorial do not get confused with a finished human ownership policy. If those answers are shrugs, you do not have a finished trust desk. You have a useful mod and a hope that the next /plugin install stamps itself.
Anthropic put mods, the Observe/Rewrite/Answer moves, Blast Radius's safety-net warning, and the install-from-people-you-trust note on the record. Canberk put sec-default's outermost seat in plain view. ReliaQuest put the local reminder loud that scaling agentic cyber ops still names who owns the finance desk. The research path can still be useful. The useful question is whether anyone owns approved mod sources, repo review before install, the org settings seat, the permission-rules versus safety-net stamp, and the human approve path before the next rewrite hook pretends the desk closed itself.
Sources
- Addy Osmani / claude.dev Blog, "Getting started with Claude Code mods," October 1, 2026, on mods as hooks inside plugins that can rewrite or replace Claude Code behavior and draw custom UI; Claude Code 2.1.287 or later with mods on by default; plugin.json / hooks.json / register(on) layout; Observe, Rewrite, and Answer moves; events including tool calls, prompt submit, turns, session start/end, slash commands, and ui.render; sandbox with
$API; difference from settings hooks; Claude Code's own AGENTS.md and /diff mods; Token Weather, Blast Radius, and Replay Theater; sharing via marketplace add/install/reload; trust warning to read the repo and install only from people you trust; and Claude directory submission. https://claude.dev/blog/getting-started-with-claude-code-mods/ - Canberk, "Claude Code mods: plugins that can rewrite what Claude Code does," October 1, 2026, summarizing Claude Code 2.1.287 release notes that plugins "may now modify deeper behavior"; confirming tutorial mods; and noting the public mods folder holds sec-default and telemetry, with sec-default keeping org classic hooks, managed settings, tool policy, and deny rules out of reach of user-installed plugins unless managed prependPlugins says otherwise. https://canberk.me/news/claude-code-mods-plugins-that-change-behavior/
- Business Wire via FinancialContent, "ReliaQuest Names Krish Venkataraman Chief Financial Officer," October 1, 2026, 9:30 a.m. EDT, Tampa, Fla., on Venkataraman joining as CFO October 5 to lead global finance and accounting; Brian Murphy founder/CEO comment on AI and cybersecurity; KnowBe4 Co-President and CFO path from about $10M ARR to about $300M ARR and Nasdaq IPO 2021; Solink CFO, Dataiku President, Socure CFO background; GreyMatter Agentic Defense, Universal Translator, Detection at Source/Storage/Transit, Agentic Orchestration and AI Model Broker; and ReliaQuest making security possible since 2007. https://www.financialcontent.com/article/bizwire-2026-10-1-reliaquest-names-krish-venkataraman-chief-financial-officer
- citybiz, "ReliaQuest Names Krish Venkataraman CFO to Support Global Growth," October 1, 2026, on the same CFO appointment; GreyMatter coordinating detection, investigation, and response across existing security tech with natural language and without requiring full stack consolidation; and related company background. https://www.citybiz.co/article/912680/reliaquest-names-krish-venkataraman-cfo-to-support-global-growth/