◧ Claude Mods Directory

Claude Code Mods FAQ

Updated October 5, 2026

The questions everyone asks about Claude Code mods — sandboxing, cost, safety, and the eternal mods-vs-plugins confusion — answered in plain language, each in under a minute.

Are Claude Code mods sandboxed? Are they safe?
No — mods are explicitly not sandboxed. A mod runs with the same permissions as Claude Code itself: it can read your files, run commands, make network requests, and read environment variables, including API keys. Only install mods from authors and repositories you trust, skim the code first, and consider running the secret-redacting guard claude-code-redact.
Do Claude Code mods cost money?
The mods themselves are free — they are open-source code published on GitHub, and every mod in our directory costs nothing to install. You do need Claude Code itself to run them. There are no paid mods in the ecosystem as of October 2026.
What is the difference between a mod, a plugin, and a skill?
A plugin is the distribution unit — the marketplace entry you install. A mod is the TypeScript module inside the plugin that hooks the agent execution pipeline. A skill is markdown instructions that guide the model's behavior (for example, a code-review checklist). One plugin can ship several mods. Full breakdown: Mods vs Plugins.
Where can I find Claude Code mods?
Right here — our directory lists every verified mod, searchable by category, each linked to its source repository. The awesome-claude-code-mods community catalogue is the other essential bookmark; new mods tend to surface there first.
How do I install a Claude Code mod?
Inside Claude Code: /plugin marketplace add <owner>/<repo>, then /plugin install <mod>@<marketplace>, then /reload-plugins. From the shell: claude plugin marketplace add … && claude plugin install … --scope user. Step-by-step with troubleshooting: How to Install Claude Code Mods.
How do I build my own mod?
Fastest path: describe the mod in plain language and let Claude Code scaffold it — it knows the API. Manually: create plugin.json, hooks/hooks.json and the module file, export register, build UI with the $ API, iterate with claude --plugin-dir, then claude plugin validate and claude plugin test. Full walkthrough: Build Your First Claude Code Mod.
Do mods work on Windows, macOS, and Linux?
Mods run inside the Claude Code process, so they work wherever Claude Code runs — the plugin commands are identical on all three. The only OS-level concerns are the usual ones: claude on your PATH, and forward-slash paths in the examples working as written.
Will mods slow down Claude Code?
A mod runs code on the pipeline events it subscribes to, so a heavy mod — say, one making network calls on every response — can add latency. In practice the popular mods are tiny: darrelltw's bands famously cost zero model tokens. Prefer small, focused mods, and if a session feels sluggish, disable mods one by one to find the culprit.
Can a mod steal my API keys?
In principle, yes — that is what 'not sandboxed' means. A malicious mod could read environment variables and exfiltrate them. This is why the trust rules matter: install from reputable authors, read the code (most mods are short TypeScript files), keep production secrets out of shells where you run untrusted mods, and run claude-code-redact.

Still stuck? The full guide goes deeper on every one of these, and the install page walks through setup step by step.