跳到主要內容

Claude Code Mods評測:AI代理秒變可編程擴充平台 | Claude Code Mods Review: Hook Into Your AI Coding Agent

By Kit 小克 | AI Tool Observer | 2026-10-04

🇹🇼 Claude Code Mods評測:AI代理秒變可編程擴充平台

Claude Code Mods 是 Anthropic 在 2026 年 10 月初隨 Claude Code 2.1.287 版推出的全新機制,讓開發者用一小段 TypeScript 程式碼掛進 AI 編碼代理的事件迴圈,直接改寫提示詞、攔截工具呼叫,甚至換掉介面元件。這篇評測帶你搞懂 Claude Code Mods 到底能幹什麼、裝起來簡不簡單,以及最該注意的風險在哪裡。

Claude Code Mods是什麼?

Claude Code Mods 是跑在 Claude Code 內部的小型外掛,能監聽、修改或直接攔截代理執行時觸發的事件,等於把編碼代理變成一個可編程的執行環境。

技術上,每個 Mod 是 plugin 裡的一個 hooks 模組,匯出 register(on, options) 函式,掛上 tool.call、prompt.submit、turn.start、turn.complete、session.start、command.run、ui.render 等事件的處理器。每個處理器拿到一個 API 物件和事件內容,可以選擇放行(next)、改寫內容,或直接回應讓 Claude Code 原本的行為完全不執行。Mod 載入一次會持續整個 session,能保留狀態、訂閱畫面重繪、註冊斜線指令,甚至對模型曝露新工具。

Mods能做什麼?開發者的實際用法

從官方文件和社群範例看,目前已經出現的用法包括:

  • 改寫提示詞:在 prompt.submit 階段自動加上專案規範或上下文
  • 攔截高風險工具呼叫:在 tool.call 階段擋掉或要求重試危險指令
  • 自動決定權限:不跳確認視窗,直接批准特定工具動作
  • 自動遮蔽機密:偵測並刪除輸出中疑似 API key、密碼的字串
  • 客製化介面:替換終端機顯示元件,加上自訂狀態列

這讓 Claude Code Mods 概念上接近瀏覽器擴充功能或 VS Code 外掛,只是掛的對象是 AI 代理本身的思考與行動迴圈,彈性明顯更大。

Mods安全嗎?風險在哪裡?

風險很直接:Mod 會以安裝者本人的權限運行,等於能讀寫你帳號能碰到的任何檔案、讀取環境變數裡的機密、看到每一句提示詞與每個工具呼叫。

官方文件自己也坦白列出這些風險:Mod 能像你一樣在機器上動作、讀密鑰、看 session、改 session、不經確認就先批准動作、花你的用量額度。而且 Mod 無法改變系統原本的權限彈窗內容,但可以在彈窗跳出前就先攔截決定。目前已經有社群開始討論要幫 Mods 建立供應鏈盤點與審查機制,原因很簡單——裝一個來源不明的 Mod,等於把整台機器的控制權交出去。這跟十年前「裝瀏覽器擴充功能前要三思」是同一個道理,只是風險更高,因為代理本身就有執行指令的能力。

怎麼安裝第一個Claude Code Mod?

Mods 目前以 plugin 形式發布,安裝方式跟一般 Claude Code plugin 相同,裝完後 Mods 預設是開啟的。實測後建議:只裝官方或信譽良好的開發者發布的 Mod,啟用前先讀一遍它的 hooks 模組原始碼,確認它掛的事件和改寫的內容跟說明一致,別讓一段幾十行的 TypeScript 代管了你整台機器。

好不好用,試了才知道。


🇺🇸 Claude Code Mods Review: Hook Into Your AI Coding Agent

Claude Code Mods is a new mechanism Anthropic shipped in early October 2026 with Claude Code 2.1.287, letting developers hook a small TypeScript module straight into the AI coding agent's event loop — rewriting prompts, intercepting tool calls, even swapping out UI elements. This review covers what Claude Code Mods can actually do, how easy it is to install, and the risk you should watch for most.

What Are Claude Code Mods?

Claude Code Mods are small plugins that run inside Claude Code itself, watching, rewriting, or outright intercepting events as the agent executes — turning the coding agent into a programmable runtime.

Technically, a mod is a plugin's hooks module exporting a register(on, options) function that attaches handlers to events like tool.call, prompt.submit, turn.start, turn.complete, session.start, command.run, and ui.render. Each handler receives an API object and the event payload, and can call next to pass it through, rewrite it, or return a result so Claude Code's own behavior never runs. A mod loads once and persists for the session, so it can hold state, subscribe to UI redraws, register slash commands, and even expose new tools to the model.

What Can Mods Do? Real Developer Use Cases

Based on official docs and community examples, use cases already in the wild include:

  • Rewriting prompts: automatically injecting project conventions or context at the prompt.submit stage
  • Intercepting risky tool calls: blocking or forcing a retry on dangerous commands at the tool.call stage
  • Auto-approving permissions: skipping confirmation dialogs for specific tool actions
  • Redacting secrets: detecting and stripping API keys or passwords from output
  • Customizing the UI: swapping terminal display components or adding a custom status bar

Conceptually, Claude Code Mods are closer to browser extensions or VS Code plugins — except they hook into the agent's own reasoning and action loop, which gives them far more leverage.

Are Mods Safe? What's the Risk?

The risk is straightforward: a mod runs with the permissions of whoever installed it — meaning it can read and write any file your account can touch, read secrets from environment variables, and see every prompt and tool call in your session.

Anthropic's own docs are upfront about this: a mod can act on your machine as you, read your secrets, see and change your session, approve tool calls before you're even asked, and spend your usage. Mods can't change what the permission prompt itself displays, but they can intercept and decide before that prompt ever shows up. The community has already started discussing supply-chain vetting for mods, for a simple reason — installing one from an unknown source hands over control of your machine. It's the same caution that applied to browser extensions a decade ago, just higher-stakes, because the agent itself can execute commands.

How Do You Install Your First Claude Code Mod?

Mods ship as plugins today, so installation works like any other Claude Code plugin, and mods are on by default once installed. After testing this, our advice: stick to mods from Anthropic or developers with a track record, read the hooks module source before enabling it, and confirm the events it hooks and the content it rewrites match what it claims — don't let a few dozen lines of TypeScript take over your whole machine.

You won't know until you try it.

Sources / 資料來源

常見問題 FAQ

Claude Code Mods是什麼?

Claude Code Mods是Anthropic於2026年10月推出的可編程擴充機制,用TypeScript模組掛鉤Claude Code的事件迴圈,能改寫提示詞、攔截工具呼叫、客製化介面。

Claude Code Mods安全嗎?

Mod以安裝者本人的權限運行,能讀寫你帳號能碰到的檔案、讀取密鑰、看到並改寫session內容,存在供應鏈風險,建議只裝信譽良好來源的Mod並檢查原始碼。

Mods和一般Claude Code plugin有什麼不同?

Mods是plugin的一種,但專門透過hooks模組掛進tool.call、prompt.submit等事件,能直接介入或取代Claude Code原本的行為,一般plugin通常只是擴充功能,不會攔截核心事件。

怎麼知道一個Mod掛了哪些事件?

讀該Mod的hooks模組原始碼,檢查它呼叫register(on, options)時掛上了哪些事件名稱(如tool.call、prompt.submit),確認跟說明文件一致再啟用。

延伸閱讀 / Related Articles


AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends

留言

這個網誌中的熱門文章

Google Ironwood TPU v7 推理專用晶片解析:效能追平 NVIDIA、成本低 44%,AI 晶片戰爭正式開打 | Google Ironwood TPU v7 Explained: Matching NVIDIA Performance at 44% Lower Cost — The AI Chip War Heats Up

Claude Code 實測:AI 幫你寫程式到底行不行? | Claude Code Review: Can AI Really Code for You?

Cursor vs GitHub Copilot vs Claude Code:AI 程式助手大比拼 | AI Coding Assistants Compared: Cursor vs GitHub Copilot vs Claude Code