Anthropic argued in August that auto mode protects developers better than their own permission clicks. On 1 October 2026 it shipped mods for Claude Code, TypeScript plugins that can approve a tool call after rules and PreToolUse hooks, with no classifier check in auto mode. Outside managed settings and Team or Enterprise sign-in, a mod can approve calls that a deny rule refuses.
The episode weighs the counterpoint: malicious plugins could already run shell commands through hooks, and Anthropic ships mitigations such as claude plugin validate, a trust prompt and allowManagedModsOnly. The conclusion that vetting is now the boundary is the article’s inference, not an observed incident count.