modscode JA

modscode / Review

One rule, and your own check

modscode lists a mod when its code is laid out so a reader can check it, wherever it draws: the terminal, the desktop app, both, or nothing at all. Whether that code is safe for you is your call: check every mod yourself before you install it.

modscode does not vouch for any mod. Mods run unsandboxed, with your permissions: they can read your files and environment variables (API keys included) and start programs. Before you install one, read its code, see what it reaches, and install the commit you read.

The rule

Its code is laid out so you can check it
Entry readEvery module hooks/hooks.json names was read.62 of 4,178 mods fail this
ParsesEvery file parses as TypeScript or JavaScript.4 of 4,178 mods fail this
All its code is in the modEvery import is a file of the mod or the engine's own module; no packages, no require.158 of 4,178 mods fail this
ReadableNo minified lines, no eval or new Function, no import of a computed path, no encoded blobs.79 of 4,178 mods fail this
Calls in the openNetwork and programs are reached as $.http.fetch and $.process.run in place, never passed around.3 of 4,178 mods fail this

Of 4,178 mods found on GitHub on 2026-10-06, 3,906 meet it; after copies of the same mod are folded, 3,676 are listed: 2,939 draw in the terminal and the desktop app, 162 in the terminal only, 11 in the desktop app only, and 564 draw nothing (hooks only).

Shown for you to weigh

These never keep a mod out. Each mod's page shows them, flagged where the code does it, so you know where to look first.

Where it drawsThe terminal, the desktop app, both, or nothing (hooks only: a guard or a prompt rewriter), as its code says. Shown, never a reason to leave a mod out.a fact, never flagged
Install lineWhether its repository's own .claude-plugin/marketplace.json lists it, so it installs from that marketplace with the lines on its page.2,713 of 3,676 listed mods have an install line
Programs on WindowsWhether every program it starts through $.process exists on Windows (tail, date, open, osascript, /usr/… do not).flagged on 396 of 4,178 mods
NetworkWhether every fetch names its https host in the code.flagged on 357 of 4,178 mods
ProgramsWhether every program it starts is named in the code and is not a shell, an interpreter or a network tool.flagged on 1,118 of 4,178 mods
Reads and sendsWhether it both reads files or environment variables and reaches the network.flagged on 652 of 4,178 mods
Keys in the sourceWhether the source holds what looks like an API key or a private key.flagged on 5 of 4,178 mods
LicenceAn open licence (MIT, Apache-2.0, BSD, ISC, Unlicense, 0BSD, CC0) with its text lets modscode show its code; otherwise the code is linked.flagged on 1,230 of 4,178 mods

Check a mod yourself

  1. Read it. Most mods are one or two files of a few hundred lines. Every call outside the mod goes through $: look for $.http (network), $.process (programs), $.fs (files) and $.env (environment variables), and for the reason each is there.
  2. Let Claude Code list it. claude plugin validate . in the mod's folder lists every event it hooks and every API it calls.
  3. Install the commit you read. A marketplace that follows the author's latest commit changes whenever they push.

When a mod is read

About a thousand repositories are searched for mods: GitHub searches for Claude Code mods and for hooks.json files that name modules, and the awesome lists. Each mod's source is fetched as text at one commit, its design is rebuilt, and the two rules and the flags are read from that text.