What a mod can reach
A mod runs inside Claude Code with the same permissions you have. Most only draw on screen. Some read files, run commands or use the network. Every mod here carries a label that says which.
It can draw in Claude Code and remember its own settings. It can't read your files, run commands or use the network.
It can read files, settings, environment variables or the conversation. It can't change anything, run commands or use the network.
It can write files, run programs, set environment variables, call a model or send prompts to Claude. It doesn't use the network directly.
It can fetch or send data over the internet, call MCP tools or message other sessions. Read the code before you install it.
How we label a mod
A mod can only reach outside itself through the mods API, the $ it gets in every hook. Claude Code can list every call a mod makes without running it: claude plugin validate reads the code and prints the hooks and calls it finds. We run it on every mod and take the highest level among its calls.
We also read the code. Validation shows what a mod can call. Reading shows what it does with it, like whether a mod that uses the network talks to the service it says it does.
Check a mod yourself
Before you install anything, clone it and run validate on the folder:
git clone https://github.com/<owner>/<repo>
claude plugin validate ./<repo>The calls: line is the list to read. Anything under $.http, $.process or $.fs.write deserves a look at the code around it.
What reach doesn't tell you
- A higher level isn't a warning. A CI status mod has to use the network to do its job.
- A lower level isn't a promise. Labels describe the version we checked, on the date on its page.
- Your organization can limit what mods load. See Anthropic's admin guide for mods.
Found a mod doing something its label doesn't cover? Tell us and we'll pull it the same day.