# Claude Code mods: create a context display and inspect its access

> Claude Code mods can draw inside a session and change its behavior. This documentation-based guide explains how to request a context display and inspect its access.

By BIG CHANGE Editorial

Published: 2026-10-02T04:59:25.238Z
Updated: 2026-10-02T04:59:25.238Z
Canonical: https://bigchange.ai/blog/claude-code-mods-context-display-guide

![Illustrated close-up of a computer display with three mod files, a session usage call, and an orange context strip.](https://bigchange.ai/api/media/file/claude-code-mods-context-hero-v2.png)
AI-generated by OpenAI; BIG CHANGE conceptual editorial illustration.

Claude Code users can now change the assistant's interface and behavior with JavaScript or TypeScript functions packaged as plugins. Anthropic [released mods on October 1](https://claude.com/blog/claude-code-mods), with support in the CLI and Claude Desktop's Code tab. Developers can add a context-use display inside the conversation.

Anthropic says mods run with the user's machine permissions and are not sandboxed. A mod can also read session data or make model calls. Inspect its code and publisher before installing it.

This guide is for developers who already use Claude Code and want a small, visible customization. The task is to create a display of context-window usage, inspect the resulting plugin, and decide whether to retain it. The instructions are documentation-based, checked October 2 against Claude Code v2.1.287 and later. BIG CHANGE has not run this procedure or independently tested the generated code.

## The big change

- What changed: Claude Code mods add functions that can alter events and draw inside the assistant's interface, packaged through its existing plugin system.
- Why it matters: Developers can build a display or workflow control into their session, while giving that code access to their machine and conversation.
- What to watch: Whether the mod's actual calls and behavior match its purpose, which organizational controls apply, and API changes between Claude Code versions.

## Check the version, account and workspace

Run `claude --version` in a shell. The [current mods documentation](https://code.claude.com/docs/en/plugins/mods/overview) requires v2.1.287 or later and says mods are enabled by default. Existing early-access environment-variable settings do not control this release.

You need Claude Code access and a workspace you have accepted as trusted. Anthropic's [setup documentation](https://code.claude.com/docs/en/setup) lists Pro, Max, Team, Enterprise and Console accounts, as well as supported third-party API providers. The free Claude chat plan does not include Claude Code. An organization's settings may prevent user-created mods from loading.

Use an interactive terminal session. The CLI and supported Desktop sessions show mod interfaces. Hooks also run in the VS Code chat panel and headless sessions, where drawings do not appear. Desktop's WSL sessions do not support plugins.

## Create and inspect the display

Anthropic's [October 1 tutorial](https://claude.dev/blog/getting-started-with-claude-code-mods/) documents Token Weather, a display that reads context usage after turns. Its percentage is based on the context used for the last response and the model's context window. It is a usage indicator, with no documented measure of answer quality.

1. Start `claude` in the trusted workspace. Ask it to create a mod that displays the context percentage, tokens used and context-window size above the prompt, updating after each completed main-agent turn. Request the documented session-usage API and a display-only implementation, with no file access, process execution, network requests or model calls. This is our narrower specification for the documented creation path; the request itself does not enforce those restrictions.
2. Review the files Claude creates. The [creation manual](https://code.claude.com/docs/en/plugins/mods/create) places the plugin in the session's directory under `~/.claude/dev-mods/`. Inspect its manifest, hooks configuration and code. Claude Code asks whether to enable hot reloading; accepting runs this session's mods and later revisions.
3. Before enabling it, run `claude plugin validate` followed by the actual plugin directory in your shell. Read the reported event hooks and API calls. The intended behavior needs a usage reading, state and rendering. Investigate any access to files, environment variables, processes, the network or models, and read event rewrites in the source as well. A successful validation reports compatibility with the loader, not a security guarantee.
4. After approving a reviewed implementation, run `/plugin` and check the Installed tab for the mod. Make an ordinary request and check that the band updates after the turn. The completion signal is a loaded plugin with visible usage values that update; a generated file alone does not establish that it works.

These steps do not promise Claude will generate the intended implementation on its first attempt. The complete [Token Weather implementation and test example](https://claude.dev/blog/getting-started-with-claude-code-mods/#build-your-first-mod-token-weather) provide a reference for comparing what it writes. The tutorial says a normal session-usage reading is free; requesting a breakdown can send a token-count request. Asking Claude to write or revise the mod still consumes ordinary Claude Code usage.

## Keep the code and its permissions in view

A session-created mod is temporary. The creation manual says to retain it by copying its directory to your own location, then start sessions with `claude --plugin-dir` followed by that location. Each load writes version-specific declarations under `.claude-plugin/types/`; check these when updating because the API can change.

Anthropic's [administration manual](https://code.claude.com/docs/en/plugins/mods/admin) explains a limit that tool-permission rules can obscure. The built-in security guard loads for Team or Enterprise users, or on machines with managed settings. With its default configuration, deny rules take precedence over user mods approving Claude's tool calls. Those rules do not restrict a mod's own filesystem or process API calls. Administrators can block user-installed mods, or apply a policy mod to their calls.

The [September 22 Pluto Security investigation](https://pluto.security/blog/claude-code-function-hooks-security/) reported credential access, interface deception and remotely changing code in tests of the pre-release implementation. Pluto sells security software for these extensions, and its report explicitly predates general availability. It is useful evidence for reading a plugin's source and downloaded dependencies; its specific findings do not establish the behavior of v2.1.287. Current Anthropic documentation supplies the release's permission details.

Disable a mod through its plugin controls. `--safe-mode` omits installed mods and other customizations for one session.

## Usage and cost

Anthropic's launch and mods manuals specify no separate mods fee. [Claude Code's cost documentation](https://code.claude.com/docs/en/costs) says subscription use draws from plan allowances, while Console and cloud-provider use is billed by tokens. A mod that calls a model can spend that usage. Check `/usage` and the billing interface for your sign-in method; a context percentage is not a bill or a spending cap.

Record the Claude Code version alongside the reviewed plugin. Adding command approvals or downloaded helpers requires a further review because it changes what the code can do.

## Sources & further reading

- [Anthropic, Customize Claude Code with mods](https://claude.com/blog/claude-code-mods), October 1, 2026: release announcement, plugin packaging and explicit machine-access warning. Anthropic makes and sells Claude Code.
- [Mods overview](https://code.claude.com/docs/en/plugins/mods/overview), checked October 2: version, session surfaces, host permissions, validation and disabling controls.
- [Create a mod](https://code.claude.com/docs/en/plugins/mods/create), checked October 2: creation, approval, hot reload, retention and version-specific type declarations. It documents expected behavior rather than a BIG CHANGE test.
- [Getting started with Claude Code mods](https://claude.dev/blog/getting-started-with-claude-code-mods/), Addy Osmani, October 1: Token Weather's metric, code and test example. The demonstrated result is Anthropic's.
- [Manage mods for your organization](https://code.claude.com/docs/en/plugins/mods/admin), checked October 2: guard availability, deny-rule scope and administrator options. It does not make user mods generally isolated from the machine.
- [Advanced setup](https://code.claude.com/docs/en/setup) and [Manage costs effectively](https://code.claude.com/docs/en/costs), checked October 2: account prerequisites, authentication-dependent billing and usage tracking. No separate mods price was specified in the launch sources reviewed.
- [Pluto Security, Inside Claude Code Function Hooks](https://pluto.security/blog/claude-code-function-hooks-security/), September 22: researcher-run pre-release tests and their limits. Pluto markets extension-security products; we did not reproduce its tests.

## Sources

- [Customize Claude Code with mods](https://claude.com/blog/claude-code-mods) — Anthropic release announcement: mods in the CLI and Desktop, plugin packaging, machine permissions. The vendor sells Claude Code.
- [Mods overview](https://code.claude.com/docs/en/plugins/mods/overview) — Living official documentation: v2.1.287+, surfaces, permissions, validation and disabling. Vendor instructions, not our test.
- [Create a mod](https://code.claude.com/docs/en/plugins/mods/create) — Official creation, approval, reload, retention and version-specific type declarations. The requested code still needs inspection.
- [Getting started with Claude Code mods](https://claude.dev/blog/getting-started-with-claude-code-mods/) — Addy Osmani's Anthropic tutorial: Token Weather metric, complete implementation and test example; demonstrated by vendor, not BIG CHANGE.
- [Manage mods for your organization](https://code.claude.com/docs/en/plugins/mods/admin) — Official guard availability, deny-rule scope and admin controls. Tool deny rules do not restrict a mod's own filesystem/process calls.
- [Advanced setup](https://code.claude.com/docs/en/setup) — Account and access prerequisites: paid subscriptions, Console or supported providers; free chat does not include Claude Code.
- [Manage costs effectively](https://code.claude.com/docs/en/costs) — Plan allowances, API/provider token billing and usage tracking. Reviewed launch sources specify no separate mods fee.
- [Inside Claude Code Function Hooks: The Trust Problem Behind Claude Mods](https://pluto.security/blog/claude-code-function-hooks-security/) — Pluto researcher-run pre-release security tests. Does not establish v2.1.287 behavior; Pluto sells extension-security products. Not reproduced by BIG CHANGE.
