---
title: "Claude Code Mods, Explained: I Built One That Watches My Own Agent"
description: "Claude Code can run its own hooked-in plugins now: live status lines, toasts, panes, hooks into every tool call it makes. I built two, one flags risky commands before you scroll past them, the other just revs a motorcycle gauge."
date: "2026-10-07"
tags: [ai, claude-code, mods, agent-security, developer-tools]
---
Claude Code can run its own hooked-in plugins now, and most of what's out there about them is vague. So I built two: one genuinely useful, one a motorcycle gauge. Both are real, both are installable right now, and you can click through a working simulation of each one before you leave this page.

## What's a Claude Code Mod, Actually {#what-is-a-mod}

A mod is a small plugin that hooks into Claude Code's own agent loop. Not a wrapper around it, not a separate process watching logs. It registers handlers for the events the engine already raises as it works: `tool.call` fires every time Claude runs a tool, `prompt.submit` when you hit enter, `turn.complete` when a turn wraps up. A handler sees the event, can act on it, and calls `next()` to let everything beneath it keep running.

From there a mod can draw things: a line in the status bar (`$.ui.status`), a toast (`$.ui.toast`), a whole pane or a band above the prompt. It can also just watch and stay quiet, which is the shape both of mine take. Neither one blocks anything. They narrate.

Mods hot-reload while you're building one: save the file, it reloads at the end of the turn, and `claude plugin validate` / `claude plugin test` check the manifest and hooks against the real engine before you ship anything. That tooling is a decent signal that this isn't a weekend hack feature, but I'll say the honest thing up front: I don't have visibility into Anthropic's roadmap, and I'm not going to promise you this API is permanent. What I can tell you is it's validated, tested, and typed today, which is more than a lot of "experimental" features ship with.

## The Useful One: agent-watch {#agent-watch}

This is the one I'd actually recommend installing. It watches `Bash`, `Write`, and `Edit` calls and flags two things: shell commands that read as hard to undo, and writes to paths that shouldn't be touched without someone noticing.

```ts
const RISKY_BASH: RegExp[] = [
  /(^|\s)sudo(\s|$)/,
  /\brm\s+-[a-z]*r[a-z]*f[a-z]*\b/i,
  /curl[^\n|]*\|\s*(sh|bash)\b/,
  /chmod\s+777/,
  /git\s+push\s+--force(?!-with-lease)/,
]

const PROTECTED_PATH = /(^|\/)(\.env(\.[^/]*)?$|\.ssh\/|id_rsa|credentials\.json|\.pem)$/
```

When a call matches, the status line's tally ticks up and a toast fires with exactly what got flagged. That's it: no `{ deny }`, no blocking, no asking permission. This is OWASP LLM08, excessive agency, made visible instead of enforced: the goal isn't to stop the agent, it's to make sure a human notices what it just did, in real time, instead of finding out three commits later.

I went back and forth on whether it should actually block the risky stuff. Decided against it, on purpose: a flagging tool that's wrong once in a while is annoying. A blocking tool that's wrong once in a while is the thing you disable entirely, and then it protects you from nothing. Heuristics stay narrow and visible instead of clever and silent. Tune the regex for your own repo if these don't fit.

Here's what it looks like running against a handful of calls:

[MOD-DEMO:agent-watch]

## The Fun One: throttle {#throttle}

No security angle, no excuse, just a motorcycle-themed activity gauge for the status line. It counts tool calls in the current turn and revs through four stages:

```ts
const STAGES = [
  { max: 2, label: '🏍️ idle' },
  { max: 6, label: '🏍️💨 cruising' },
  { max: 12, label: '🏍️🔥 revving' },
  { max: Infinity, label: '🏍️🔥💨 full throttle' },
]
```

Hit full throttle (13+ calls in one turn) and it drops a toast about wearing a helmet. That's the whole mod. I built it mostly to prove the "fun" side of this isn't harder than the "useful" side: same three files, same `on('tool.call', ...)` shape, just a sillier payload.

[MOD-DEMO:throttle]

## Try Them Yourself {#try-it}

Both mods, plus their tests, live in one small repo set up as a plugin marketplace. Install either with one line at the prompt of a terminal session:

```
/plugin install agent-watch --marketplace hereshecodes/claude-mods
/plugin install throttle --marketplace hereshecodes/claude-mods
```

That's the whole install. No build step, no config beyond the prompt that shows up asking you to confirm the marketplace. The source, including the test files, is at [github.com/hereshecodes/claude-mods](https://github.com/hereshecodes/claude-mods) if you want to read the hooks before you trust them with your terminal, which, honestly, you should.

## TL;DR

| | agent-watch | throttle |
|---|---|---|
| What it watches | `Bash`, `Write`, `Edit` tool calls | every tool call, this turn |
| What it does | flags risky commands + sensitive-path writes | revs a status-line gauge |
| Blocks anything | no (visibility only) | no |
| Install | `/plugin install agent-watch --marketplace hereshecodes/claude-mods` | `/plugin install throttle --marketplace hereshecodes/claude-mods` |
| Why it exists | OWASP LLM08 (excessive agency), made visible | because I could |

Mods are a real, validated, testable way to hook into what your agent is actually doing while it does it, not a log you read after the fact. Start with something that just watches. Build the fun one once you've got the shape down.

---

**More posts:**
- [Claude Code Finally Reads AGENTS.md (Here's Exactly How It Works)](/blog/claude-code-agents-md-support-2026)
- [How I Made Claude Code Enforce OWASP Rules (So I Don't Have To)](/blog/claude-code-security-skills-owasp-accessibility)
- [My Actual Dev Setup: Google Antigravity + Claude Code](/blog/antigravity-claude-code-workflow-2026)

---

*// hereshecodes.com*
