Anthropic's Claude Code Mods Run Unsandboxed, Posing Security Risks
Claude Code Mods — JavaScript or TypeScript functions that hook into the AI coding tool's events — run with full user permissions and no sandboxing. Anthropic advises installing them only from trusted sources, but experts argue sandboxing is needed to protect sensitive data.
- Claude Code Mods are unsandboxed and run with user permissions
- Built-in features like /diff are themselves implemented as Mods
- A malicious Mod could exfiltrate data or execute arbitrary code
- Anthropic's guidance is to install Mods only from trusted sources
Read next
Business