ModsCode / Claude Code Mods / Rules
One rule, and your own check
ModsCode lists a mod when its code is laid out so a reader can check it, wherever it draws: the terminal, the desktop app, both, or nothing at all. Whether that code is safe for you is your call: check every mod yourself before you install it.
ModsCode does not vouch for any mod. Mods run unsandboxed, with your permissions: they can read your files and environment variables (API keys included) and start programs. Before you install one, read its code, see what it reaches, and install the commit you read.
The rule
| Its code is laid out so you can check it | |
|---|---|
| Entry read | Every module hooks/hooks.json names was read.78 of 5,315 mods fail this |
| Parses | Every file parses as TypeScript or JavaScript.3 of 5,315 mods fail this |
| All its code is in the mod | Every import is a file of the mod or the engine's own module; no packages, no require.193 of 5,315 mods fail this |
| Readable | No minified lines, no eval or new Function, no import of a computed path, no encoded blobs.110 of 5,315 mods fail this |
| Calls in the open | Network and programs are reached as $.http.fetch and $.process.run in place, never passed around.28 of 5,315 mods fail this |
Of 5,315 mods found on GitHub on 2026-10-11, 4,972 meet it; after copies of the same mod are folded, 4,750 are listed: 3,848 draw in the terminal and the desktop app, 186 in the terminal only, 13 in the desktop app only, and 703 draw nothing (hooks only).
Shown for you to weigh
These never keep a mod out. Each mod's page shows them, flagged where the code does it, so you know where to look first.
| Where it draws | The terminal, the desktop app, both, or nothing (hooks only: a guard or a prompt rewriter), as its code says. Shown, never a reason to leave a mod out.a fact, never flagged |
|---|---|
| Install line | Whether its repository's own .claude-plugin/marketplace.json lists it, so it installs from that marketplace with the lines on its page.3,638 of 4,750 listed mods have an install line |
| Programs on Windows | Whether every program it starts through $.process exists on Windows (tail, date, open, osascript, /usr/… do not).flagged on 548 of 5,315 mods |
| Network | Whether every fetch names its https host in the code.flagged on 394 of 5,315 mods |
| Programs | Whether every program it starts is named in the code and is not a shell, an interpreter or a network tool.flagged on 1,386 of 5,315 mods |
| Reads and sends | Whether it both reads something of yours (files, environment variables, the transcript, settings) and reaches outside (the network, an MCP server, another session, telemetry).flagged on 951 of 5,315 mods |
| Keys in the source | Whether the source holds what looks like an API key or a private key.flagged on 5 of 5,315 mods |
| Licence | An open licence (MIT, Apache-2.0, BSD, ISC, Unlicense, 0BSD, CC0) with its text lets ModsCode show its code; otherwise the code is linked.flagged on 1,620 of 5,315 mods |
| Settings hooks | Hooks declared in hooks/hooks.json or plugin.json beside the module: a command (a shell when it has no args), an HTTP request, an MCP tool or a model prompt at an event. They run outside $.flagged on 184 of 5,315 mods |
| Servers it ships | MCP servers (a program, or a URL; a headersHelper is a shell command; a .mcpb bundle is unpacked at run time), LSP servers, monitors (a shell command for the whole session) and bin/ (on the PATH of the Bash tool).flagged on 197 of 5,315 mods |
| Skills, commands, agents | What its Markdown declares beyond text: allowed-tools granted for the turn, hooks added when a skill is invoked, a command run before Claude reads the skill.flagged on 149 of 5,315 mods |
| Tools and MCP | Whether every tool it calls through $.tool.call and $.mcp.call is named in the code, and none is a shell (Bash through the tool runs a shell without $.process).flagged on 158 of 5,315 mods |
| Asks of the model | Completions it runs ($.model.complete, fork, classify), subagents it spawns, prompts it submits as you, and the tools, commands and agents it adds.a fact, never flagged |
| Events it hooks | By what a hook there can do: gates (refuse a tool call, a prompt, a setting, another plugin), shapes (what the model reads: the system prompt, tool descriptions, each request), reads (your input, the events of the settings hooks, every event with *), and the rest.a fact, never flagged |
| Reads, by name | The environment variables and files it names, and whether it reads the transcript, settings.json, the prompt box or the mouse selection.a fact, never flagged |
| Writes, by name | The files and environment variables it names, and whether it changes settings, the prompt box, the clipboard, the conversation (a row the model reads) or another session.a fact, never flagged |
Check a mod yourself
- Read it. Most mods are one or two files of a few hundred lines. Every call outside the mod goes through
$: look for$.http(network),$.process(programs),$.fs(files) and$.env(environment variables), and for the reason each is there. - Let Claude Code list it.
claude plugin validate .in the mod's folder lists every event it hooks and every API it calls. - Install the commit you read. A marketplace that follows the author's latest commit changes whenever they push.
When a mod is read
The repositories come from GitHub searches (for Claude Code Mods and for hooks.json files that name modules), the awesome lists and public mod catalogues. Each mod's source is fetched as text at one commit; where it draws is read from its JSX, and the rule and the flags from that text.