The Intake — Sunday, October 4, 2026

On the substrate

Anthropic ships plugin layer for Claude Code; mods run with full machine access and no sandbox

Anthropic AI Weekly Post-Cutoff

If you use Claude Code and plan to install mods from the directory, the architectural fact to know before you do: mods run inside Claude Code's own process with the same machine privileges as the tool itself. They are not sandboxed.

Anthropic launched mods on October 1, 2026. The release ships in Claude Code v2.1.287. Mods are TypeScript event handlers packaged as plugins. A mod can rewrite prompts before they reach the model, or intercept and redirect tool calls. Mods can also approve and deny permission requests. Mods can redact secrets from tool output and add or replace interface elements. Anthropic migrated three built-in features to the mods framework at launch: the /diff pane, the agents.md loader, and telemetry.

Team and Enterprise plans include a built-in mod named sec-default. It loads before any third-party mod and prevents overrides of permission denials. If you're on an individual plan, that guardrail doesn't run ahead of installed mods.

DigitalOcean opens microVM-isolated agent runtime in public preview; sessions pause and resume in 305 milliseconds

DigitalOcean InfoQ StreetInsider

If your agent sessions run on cloud compute and idle-time billing is a cost you're absorbing, DigitalOcean's Managed Agents platform has a different billing model: active time only, with sessions pausing automatically and resuming in 305 milliseconds.

DigitalOcean launched Managed Agents on September 22, 2026. The service is in public preview. It has two components: Harness Runtime and Action Gateway. Harness Runtime runs each agent session in a hardware-isolated microVM. CPU billing is $0.044 per vCPU-hour, charged for active time only. Memory billing is $0.0095 per GB-hour. Snapshot storage is $0.005 per GiB-month. Action Gateway provides a unified MCP endpoint. It connects to 16,000+ tools from 500+ providers. Supported agent frameworks include Claude Code, Codex CLI, OpenCode, Hermes, and LangGraph.

If you're currently running agent workloads on always-on compute, the public preview is the path to try the pause-and-resume billing model — new users receive a $5 credit for the first session.

---

For operators

Installing a Claude Code mod carries the same trust requirement as installing any local program on the machine

Anthropic AI Weekly Post-Cutoff

If you're evaluating mods to add to your Claude Code setup, three things to examine before installing any mod: what it rewrites in prompts before they reach the model, which tool calls it intercepts or redirects, and how it handles permission approval and denial.

A mod that intercepts permission requests can approve actions Claude Code would otherwise have surfaced to you. On Team and Enterprise plans, the built-in sec-default mod loads first. It prevents third-party mods from overriding permission denials.

If you're on an individual plan, that guardrail doesn't run — the evaluation of each mod's permission behavior is yours to do before installing.

DigitalOcean Managed Agents introduces a usage-billed option alongside self-hosted and platform-managed agent runtimes

DigitalOcean InfoQ StreetInsider

If you're running agent workflows on cloud infrastructure and need centralized control over which operations require human approval, Action Gateway provides that as a configured setting.

Action Gateway includes centralized permission management for MCP tool access and configurable human approval requirements for sensitive operations.

If you're deploying agent workflows where certain tool calls should require human sign-off, the configurable approval requirement in Action Gateway is the specific capability to evaluate in the preview period.

---