Todd Schiller

Human ✘ Artificial Intelligence

Note This Week in Extensibility: Claude Code launches mods that let users reshape the tool, Atlassian opens Forge app tools to outside AI agents, and Shopify closes off the old script-injection path for apps

Week of September 26 – October 2, 2026: Anthropic launches mods for Claude Code, opening the coding tool to small programs that reshape how it works, Atlassian widens its Rovo module so a Forge app's tools reach AI agents built by other companies, and Shopify shuts off the old way apps injected code into storefronts.

Anthropic opened Claude Code to mods, which can rewrite what the tool does and replace its built-in features. Atlassian widened the module it opened in August so the tools a Forge app publishes now reach agents built by other companies, and wrapped the change in new marketplace governance. Meta adopted the draft WebMCP standard for its Ray-Ban Display glasses, a second product using it alongside Google's Chrome. Shopify shut off the long-standing way apps injected code into storefronts, and Cloudflare shipped the finished version of the sandbox it uses to run customer and agent code.

Customization: Anthropic launches mods for Claude Code

Anthropic launched mods for Claude Code, small programs that load inside the coding tool and reshape how it works. When the company named mods in September, they were an early-access preview a user had to switch on by hand. As of October 1 they ship through the same plugin system Claude Code users already know, the shareable bundles that add commands, connect outside tools, and run checks at set points in a session. A mod goes deeper than those pieces. Where a plugin adds to the tool or reacts at fixed points, a mod can rewrite what a user sends the model, step in on an action before it runs, change part of the interface, or replace a built-in feature. A user can write one, or ask Claude Code to write it. Anthropic has rebuilt some of Claude Code's own built-in pieces, such as its file-difference view, as mods, so the same mechanism that extends the tool now runs parts of it too. On Team and Enterprise plans, and any machine an administrator manages, a built-in security mod loads first to limit what the mods a user installs can do, such as blocking them from loosening the tool's safety rules, and administrators choose which mods load.

Why it matters: this turns one of the most widely used coding tools into something a user reshapes rather than only configures. A mod runs with the tool's own reach into a user's files, programs, and network. For an individual user, installing one means trusting whoever wrote it. In a managed workplace, the security mod and an administrator decide what can load.

Platforms: Atlassian opens Forge app tools to agents built by other companies

Atlassian widened the Rovo module it opened in August so a Forge app's tools now reach AI clients outside Atlassian. Since August, a marketplace app built on Atlassian's Forge platform could expose its actions as tools inside Atlassian's own Rovo agents; this week's preview release lets outside agents such as Claude Desktop and Cursor call those same tools. Alongside it, Atlassian brought to general availability a separate module that lets an externally hosted agent connect into Rovo, and gave administrators a policy control over which outside AI tools may reach its agent server. The company also launched "Enterprise Certified," a marketplace trust tier it had flagged in September as the successor to its retiring app-assurance program.

Why it matters: Atlassian is moving the unit a marketplace developer ships from an app a person opens to a tool a customer's agent can call, and doing it for agents built by other companies, not only its own.

Standards: Meta picks up the draft WebMCP standard for its smart glasses

Meta documented how developers can use WebMCP, the draft standard that lets a website offer tools to a visitor's AI agent, inside the web apps on its Ray-Ban Display glasses. That added a second product to the proposal's implementation list alongside Google's Chrome, the only browser that runs WebMCP today. In the same week the standard's editors kept working through the objections it drew a week earlier and resolved a narrow one, dropping a setup requirement that had made the draft harder to deploy on simple hosting and on browsers that have not yet adopted it. The objections about privacy still sit open, and WebMCP remains a Community Group draft that Chrome runs as an origin trial.

Why it matters: a second company now builds on the draft, and the editors cleared a deployment barrier. But WebMCP is still a single-browser experiment, and the open privacy objections, not deployment mechanics, are what stand between it and a standard other browsers would implement.

Marketplace: Shopify closes off the old script-injection path for apps

Shopify stopped letting apps register the script tags they had long used to inject their own code into a merchant's storefront. As of October 1, apps can no longer create new storefront script injections, and the ones already in place stop running on March 1, 2027. Apps that added functionality this way have to move to Shopify's newer extension points, which run an app's code in defined slots on the page rather than letting it inject code anywhere.

Why it matters: script injection let an app run open-ended code on a storefront, which is flexible but hard for the platform to secure and keep fast. Shopify is trading that path for extension points it defines and controls. The merchant gets a safer, quicker storefront, and Shopify gets a system it can keep evolving. Every app that relied on injection has to rebuild. Adobe and Atlassian made the same move over the past two weeks.

Infrastructure: Cloudflare ships the finished Sandbox SDK 1.0

Cloudflare released the finished 1.0 of the Sandbox SDK, the managed layer a product uses to run untrusted or agent-written code in an isolated container on Cloudflare's network. It previewed this version in August. At 1.0, a product can run a customer's own code, an AI agent's code, or a code interpreter inside a sandbox, decide how large it is and when it shuts down, control which outside services the code may reach, and hand a customer an authenticated web address to reach the app running in their sandbox. New in this release, and in public beta, a product can also save a sandbox's files and restore them later, so a customer's session survives a restart. Support for the older preview line ends December 31, 2026.

Why it matters: a managed sandbox lets a product offer customer or agent code execution without building and running its own isolation infrastructure. A session's files now persist, and a customer can open the app running inside their sandbox. That lets a product host a standing per-customer environment rather than only running a snippet and discarding it.

Also worth knowing

  • Microsoft opened two programs for partners building AI agents on its marketplace. A new partner specialization validates a company's ability to build, deploy, and secure agents across Microsoft's stack, and a companion program helps partners publish AI apps and agents to the Microsoft marketplace with Azure funding attached. Both are certification programs for who can sell agent-based extensions, not new platform capabilities.
  • Google began the gradual rollout of the Workspace automation features it announced in September. The tools that let an ordinary Workspace user build their own triggers and connect outside services started reaching scheduled-release customers on September 30, off by default and behind an administrator's approval, confirming the slower track the previous issue flagged. Google also began rolling out reusable "skills" across its Gemini assistant and Workspace, a rollout it expects to run through June 2027.
  • The reusable "skills" the Model Context Protocol finalized two weeks ago still have not reached the toolkit developers build on. The protocol's latest release came and went without them, so the instruction bundles meant to carry a user's customizations from one tool to another cannot yet move.
  • Figma keeps its editing MCP server closed to an approved list of AI clients, and the limit drew fresh pushback this week. Figma's remote Model Context Protocol server, the one that can change a design file rather than only read it, accepts only the clients on Figma's published catalog, such as Cursor, VS Code, Claude Code, and Codex, and rejects any other agent at sign-up. After an October 1 thread put the policy back in front of developers, the Model Context Protocol's own maintainers repeated that gating which clients may connect cuts against the protocol's premise that any client should work with any server. Figma set the limit while the server is in beta and has not changed it this week, and it has paused approving new clients.

On the radar

  • October 6: The W3C WebAssembly Community Group takes up a proposal to create a dedicated subgroup for the Component Model, the layer that lets WebAssembly plugins written in different languages compose.
  • October 8: The W3C WebExtensions Community Group holds its next public call.
  • October 15: The chartered W3C WebExtensions Working Group meets next.
  • October 16: Registration closes for the W3C's annual technical plenary, where the WebExtensions group plans sessions on autofill and extension security.
  • November 2: Microsoft 365 Copilot Business switches to usage-based billing by default.
  • November 17: Chrome's WebMCP origin trial is scheduled to end.
  • December 31, 2026: Support ends for the preview line of Cloudflare's Sandbox SDK.
  • March 1, 2027: Shopify stops running storefront scripts injected the old way.

This Week in Extensibility is curated by Todd Schiller. Research, drafting, and fact checking are AI-assisted.