Claude Code mods: TypeScript functions that rewrite the agent
Hook its events to gate tool calls, redact secrets and add UI — but they run unsandboxed; shipping in 2.1.288, as DigitalOcean bundles agent hosting.

Copy markdown
Hook into everything Claude Code does
Mods are TypeScript functions that fire on Claude Code's events: rewrite a prompt before it reaches the model, block or rewrite or retry a tool call, approve or deny a permission, redact secrets from tool output, or inject your own UI. That means you can wire in a CI-status sidebar, a "confirm before touching prod" gate, or full audit logging — and mods stack, the first to load seeing the event first and the result last.
No sandbox — a mod is code you run
The catch: mods run with the same access to your machine as Claude Code itself, and are explicitly not sandboxed. A mod shipped inside a plugin you install can do anything you can, so read third-party mods before you enable them.
Live now in 2.1.288
Mods landed in 2.1.287 (Oct 1) and were hardened in 2.1.288 (Oct 2), which also restores a draft cleared with Ctrl+C — press Up on the empty prompt — and fixes API timeouts, session resumption, and permission handling across cloud and desktop. Update to pull both.
DigitalOcean bundles agent hosting
Separately, DigitalOcean reportedly launched Agent Droplets: flat-rate plans (Pro around $50/mo, Team around $200/mo) that bundle managed agent runtimes, serverless inference, persistent memory, and tool access — pitched as predictable cost for running many agents instead of metered per-call bills.