1
00:00:00,000 --> 00:00:00,920
Picture this.

2
00:00:00,990 --> 00:00:05,680
You're mid refactor, Claude's moving fast,
and it quietly removes a helper that

3
00:00:05,720 --> 00:00:07,760
three other files still import.

4
00:00:07,817 --> 00:00:10,320
Nobody catches it until the tests go red.

5
00:00:10,480 --> 00:00:15,440
A new feature in Claude Code 2.1.287 is
aimed at exactly that.

6
00:00:15,568 --> 00:00:19,760
This is The Claude Code Changelog, brought
to you by Jellypod AI.

7
00:00:19,960 --> 00:00:21,200
I'm Lachlan.

8
00:00:21,208 --> 00:00:22,088
And I'm James.

9
00:00:22,208 --> 00:00:27,768
2.1.287 shipped October 1st, and the
headline is Claude Mods.

10
00:00:27,861 --> 00:00:29,208
Quick background first.

11
00:00:29,298 --> 00:00:31,928
Classic hooks are configured in
hooks.json.

12
00:00:32,019 --> 00:00:36,968
Claude Code sends your script JSON over
stdin, and the script can inspect the event

13
00:00:37,021 --> 00:00:38,168
or block a tool call.

14
00:00:38,328 --> 00:00:41,288
It's a separate process that only sees
what it's handed.

15
00:00:41,448 --> 00:00:42,728
Mods are different.

16
00:00:42,792 --> 00:00:45,768
They're TypeScript functions that run
inside Claude Code.

17
00:00:45,928 --> 00:00:50,568
You register against an engine event like
tool.call, session.start,

18
00:00:50,621 --> 00:00:54,408
or ui.render, and your function gets three
arguments.

19
00:00:54,568 --> 00:00:55,448
E is the event.

20
00:00:55,539 --> 00:00:58,088
Dollar sign is the engine interface.

21
00:00:58,128 --> 00:00:59,768
And next is a continuation.

22
00:00:59,912 --> 00:01:04,888
Call next with e to carry on, pass a
changed event to alter what happens,

23
00:01:04,915 --> 00:01:07,128
or skip it to stop the action entirely.

24
00:01:07,167 --> 00:01:09,807
That dollar object is where the power
sits.

25
00:01:09,954 --> 00:01:14,687
Pluto Security looked at a pre release
build and counted more than 60 methods on it.

26
00:01:14,801 --> 00:01:21,727
Dollar fs for files, dollar process for
shell commands, dollar http for network,

27
00:01:21,807 --> 00:01:23,887
plus session, model, and ui.

28
00:01:24,047 --> 00:01:29,007
That's how you get things like a custom
status line or a cache countdown timer.

29
00:01:29,267 --> 00:01:31,887
Now, the first built in mod.

30
00:01:32,047 --> 00:01:34,047
It's called You should know.

31
00:01:34,247 --> 00:01:39,567
The changelog describes it as a side agent
that watches your back and flags things

32
00:01:39,647 --> 00:01:41,487
you or Claude might miss.

33
00:01:41,700 --> 00:01:44,607
So that deleted helper scenario is the
target.

34
00:01:44,847 --> 00:01:50,847
To turn it on, run slash plugin enable,
then cc plugin you should know,

35
00:01:50,954 --> 00:01:51,807
at builtin.

36
00:01:51,987 --> 00:01:55,167
The exact string is in the changelog and
the show notes.

37
00:01:55,167 --> 00:01:56,607
The catch is where it works.

38
00:01:56,747 --> 00:02:00,847
The changelog says it's for first party
sessions with telemetry on.

39
00:02:00,980 --> 00:02:05,007
So if you're on Bedrock or Vertex, or
you've switched telemetry off,

40
00:02:05,047 --> 00:02:06,207
don't expect it to show up.

41
00:02:06,367 --> 00:02:08,807
The bigger caveat is trust.

42
00:02:08,880 --> 00:02:13,247
Pluto's write-up is clear that a mod is
code you run, not a document you read.

43
00:02:13,460 --> 00:02:17,487
In their tests, a mod could read files
like your credentials file and prompt

44
00:02:17,537 --> 00:02:21,447
history, and reach the network, without
any permission prompt.

45
00:02:21,519 --> 00:02:25,167
They also showed a mod rewriting the text
of a confirmation dialog.

46
00:02:25,274 --> 00:02:29,727
Their words: treat installing a mod like
running an untrusted binary.

47
00:02:29,887 --> 00:02:34,367
And remember, they tested a pre release
build, so details may have changed.

48
00:02:34,375 --> 00:02:35,815
So the practical habit is this.

49
00:02:35,941 --> 00:02:40,775
Before you install any third party mod,
run claude plugin validate on it.

50
00:02:40,919 --> 00:02:43,095
That lists the dollar calls it makes.

51
00:02:43,239 --> 00:02:47,415
Look hard for http fetch, process run, and
file reads.

52
00:02:47,562 --> 00:02:52,535
Pluto also found plugin details reported a
function hook mod as zero hooks,

53
00:02:52,588 --> 00:02:54,055
so don't lean on that screen.

54
00:02:54,242 --> 00:02:58,455
If you administer a team, managed settings
have disableAllHooks,

55
00:02:58,495 --> 00:03:02,055
and allowManagedHooksOnly, which blocks
user installed mods.

56
00:03:02,083 --> 00:03:03,683
A few smaller things in this release.

57
00:03:03,843 --> 00:03:09,203
In claude agents, there's a new n colon
filter that matches session names and tasks,

58
00:03:09,223 --> 00:03:10,963
and Enter opens the first match.

59
00:03:11,123 --> 00:03:16,963
On Bedrock, Vertex, Foundry, and the
Claude apps gateway, Opus 4.7 and newer,

60
00:03:17,011 --> 00:03:23,123
plus Fable, now default to a 1M context
window with no bracket 1m suffix.

61
00:03:23,283 --> 00:03:26,243
Set CLAUDE_CODE_DISABLE_1M_CONTEXT to 1 to
stay at 200K.

62
00:03:26,250 --> 00:03:31,610
Also, blanket Bash allow rules and
allowing hooks now prompt you before shell writes

63
00:03:31,637 --> 00:03:35,130
to protected files, like the credentials
file, instead of running them.

64
00:03:35,423 --> 00:03:40,410
In the VS Code extension there's a new Run
in background option on running commands

65
00:03:40,450 --> 00:03:41,690
and sub agents.

66
00:03:41,770 --> 00:03:46,650
And if an MCP server stops connecting
after the update, because of the new URL sign

67
00:03:46,677 --> 00:03:52,490
in prompts, add bareElicitationCapability
set to true in that server's config entry.

