memujo
AI7 min read

DeepSeek Runs Claude Code Mods in Its Own Harness

Anthropic's new in-process Mods API got a compatibility layer from DeepSeek within 48 hours. The four mods that break show exactly where the API cuts deep.

By Alice

In this article
  1. 01What Claude Mods actually are
  2. 02The bridge, and what fails to cross it
  3. 03Our Read: two things this tells builders
  4. 04Outlook

On October 3, DeepSeek published Harness v0.2.1-alpha.1 on GitHub. Buried in the release notes, past the new desktop apps and plugin management from the v0.2 preview, was something more interesting than any of it: an experimental compatibility layer that loads Anthropic's brand new Claude Code Mods and runs them inside Harness as native plugins, as Pandaily reported and Let's Data Science summarized. The mods feature itself shipped on October 1, in Claude Code version 2.1.287, per the official changelog. A rival lab building a rival harness wrote a bridge for a competitor's extension API in under 48 hours. That is not a compatibility gesture. That is a tell about where the moat in coding agents actually sits.

What Claude Mods actually are

Mods sound like plugins, and Anthropic files them under plugins in its documentation, but the architectural claim is specific and new: a mod is JavaScript or TypeScript event handler code that runs inside the Claude Code process itself. Everything else in the Claude Code extension toolbox, settings hooks, skills, status lines, MCP servers, lives outside that process. A settings hook shells out a command or fires an HTTP request. A skill is a markdown file Claude reads. An MCP server is a separate program handing Claude tools over a wire. A mod is a function the host calls directly when events fire: a tool call about to run, a prompt being submitted, a line of the interface being drawn.

Each registered handler gets three choices about an event, and the docs name them precisely: observe it and let it pass, rewrite it on the way through, or answer it, meaning the handler handles the event itself so the usual behavior never runs. The docs' example mod is eleven lines long: one tool.call hook increments a counter, one ui.render hook on the Spinner component appends that counter to the spinner text. Two hooks sharing one module-scope variable is enough to build a live tool-call readout beside the prompt.

The capability surface is wider than it looks. Per the docs, a mod can draw a pane beside the transcript or a band above the prompt, complete with tabs, buttons and text fields. It can replace parts of the interface Claude Code renders itself, including tool-call rows and the question dialog. It can hold a tool call mid-flight, ask the user something, answer without running the tool, or route a single request to a different model. It can register /commands that execute immediately, with no model turn, even while Claude is working.

The strongest signal of intent is that Anthropic is eating its own dogfood. The docs confirm /diff is now implemented as a mod (cc-plugin-diff), alongside built-ins that load AGENTS.md (cc-plugin-agents-md), emit analytics (cc-plugin-telemetry), and guard organizational policy (cc-plugin-sec-default). The first shipped third-party-style mod is cc-plugin-you-should-know, described in the changelog as "a built-in mod where a side agent watches your back and flags things you or Claude might miss," enabled with /plugin enable cc-plugin-you-should-know@builtin in first-party sessions with telemetry on. Anthropic also published sample mods: token-weather forecasts your context window above the prompt, blast-radius intercepts dangerous shell commands like rm -rf and shows what they would change, replay-theater steps through the last turn's file edits.

The bridge, and what fails to cross it

DeepSeek's layer wraps a mod's register function and mounts it as a Harness plugin. According to Pandaily's account of the release notes, the bridge can support the core event verbs: guarding tool calls, rewriting prompts, adding commands and tools, reading session data, and rendering a band above the prompt. All three of Anthropic's sample mods run under it.

The interesting data is what does not run. Four of the mods in Anthropic's own repository are marked non-runnable under the bridge, per the release notes: diff, agents-md, sec-default, and telemetry, blocked by unsupported events or interface differences.

Mod Runs on DeepSeek bridge What it needs
token-weather Yes Band rendering, token usage reads
blast-radius Yes Tool-call guard, buttons, proceed/cancel
replay-theater Yes Custom command, transcript access
diff No Deep UI replacement (pane, keyboard bindings, scrolling)
agents-md No Instruction-file loading events
sec-default No Org-policy enforcement hooks
telemetry No Host analytics plumbing

Read that table like an engineer. The mods that port are the ones that read events and paint simple surfaces. The mods that fail are the ones wired into host internals: Anthropic's own rendering engine, its instruction-loading pipeline, its policy layer, its telemetry spine. DeepSeek's release notes frame the exercise explicitly as a test of whether the Mods API is broadly a subset of Harness plugin capabilities, not a production compatibility promise. But the experiment still produced a clean measurement: the public API surface is portable in a weekend; the private surface, where Anthropic's own first-party features live, is the lock-in.

Our Read: two things this tells builders

From a systems standpoint, the mods design is a bet that the harness, not the model, is the product. For most of 2025 and 2026, agent extensibility meant MCP: external servers, any language, process isolation, the lowest common denominator interface. MCP gives Claude tools. Mods give third parties the terminal itself. The docs' own comparison table says it plainly: a mod can change tool calls, prompts, commands, turns, and what the interface draws; a settings hook can only gate or annotate; a skill can only inform. When a platform hands outsiders its render loop and its event pipeline, it is conceding that user lock-in via workflow depth beats lock-in via model weights. Which explains DeepSeek's 48-hour sprint. If extension ecosystems decide which harnesses fit existing workflows, then the winning move for a challenger is not to argue about benchmark deltas. It is to make Claude Code's extension ecosystem work on your runtime, the way Wine made Windows libraries work on Linux and compatibility layers made Android run Google-free. The four broken mods are the honest scoreboard of how much of that ecosystem is actually API versus how much is Anthropic-private plumbing.

From a data and security standpoint, I think the more consequential decision is the one Anthropic documented bluntly: mods are not sandboxed. The docs list what a loaded mod can reach, in language more candid than most vendor security pages: it acts on your machine as you, reads environment variables and settings files including API keys, sees every prompt and tool call, can rewrite a prompt or submit one as if you typed it, can message your other sessions, can approve a tool call before you are asked, and can spend your plan on model calls. Enabling sandboxing isolates Claude's Bash commands, but a process a mod spawns runs outside the sandbox. A mod that approves tool calls can approve calls that an ask rule would prompt for, and in some cases calls a deny rule refuses. The one hard boundary the docs draw: a mod can restyle almost any interface element except the permission prompt itself.

That carve-out is doing enormous load-bearing work, and the changelog shows it already bending. Version 2.1.289's first entry fixes "a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines." Translation: for at least a few releases, a mod's approval could carry a nested subcommand past a deny rule on a managed enterprise machine. This is the exact failure class we watched consumer agents expose on the Mac's Full Disk Access permission, where one all-or-nothing grant predicated on trusting the app turned out to be the wrong trust unit for autonomous software. Anthropic's mitigation is inspection, not isolation: claude plugin validate statically lists a mod's handled events and requested API calls before you install, and org admins get allowManagedModsOnly to restrict loading. Static capability lists plus a permission prompt that mods cannot restyle is a coherent design, but it shifts verification onto humans, the slowest parser in the loop. If the mod ecosystem gets a npm-style dependency graph with transitive installs, the supply-chain math gets ugly fast, one typosquatted mod with file and network reach is a full account compromise, not a scoped one.

Outlook

Two things to watch over the next month. First, whether an independent mod marketplace appears outside Anthropic's own marketplaces, because that is where claude plugin validate goes from useful to load-bearing, and where the first genuinely malicious mod will get measured. Second, whether the bridge gap closes from the wrong side: DeepSeek has every incentive to chase the four broken mods, but sec-default and telemetry depend on events Anthropic controls and could keep moving. The strategic asymmetry is that Anthropic can ship new capability into first-party mods, as it just did with /diff, and instantly widen the gap, while challengers port against a moving public API. If you are evaluating agent tooling right now, the practical takeaway is narrow but real: mods that only observe, guard, and draw bands are the portable tier, and a team writing their first mod should probably stay in that tier deliberately, because those are the ones that will still run on somebody else's harness in six months. The cross-vendor compatibility war over agent harnesses, which we first saw sketching out around DeepSeek v4's open-weights harness play and the coding-model competition between Claude and GPT, now has a defined interface to fight over. Interfaces are how ecosystems start.

  • #anthropic
  • #claude-code
  • #deepseek
  • #plugins
  • #developer-tools
  • #agent-harness

Sources

Share this story