<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Todd Schiller - Claude Code</title><link href="https://toddschiller.com/" rel="alternate"></link><link href="https://toddschiller.com/feeds/tag/claude-code.atom.xml" rel="self"></link><id>https://toddschiller.com/</id><updated>2026-10-02T00:00:00-04:00</updated><subtitle>Human ✘ Artificial Intelligence</subtitle><entry><title>This Week in Extensibility: Claude Code launches mods that let users reshape the tool, Atlassian opens Forge app tools to outside AI agents, and Shopify closes off the old script-injection path for apps</title><link href="https://toddschiller.com/blog/extensibility-radar-2026-10-02.html" rel="alternate"></link><published>2026-10-02T00:00:00-04:00</published><updated>2026-10-02T00:00:00-04:00</updated><author><name>Todd Schiller</name></author><id>tag:toddschiller.com,2026-10-02:/blog/extensibility-radar-2026-10-02.html</id><summary type="html">Week of September 26 – October 2, 2026: Anthropic launches mods for Claude Code, opening the coding tool to small programs that reshape how it works, Atlassian widens its Rovo module so a Forge app's tools reach AI agents built by other companies, and Shopify shuts off the old way apps injected code into storefronts.</summary><content type="html">&lt;!-- markdownlint-disable MD013 --&gt;
&lt;p&gt;Anthropic opened Claude Code to mods, which can rewrite what the tool does and
replace its built-in features. Atlassian widened the module it
opened in August so the tools a Forge app publishes now reach agents built by other
companies, and wrapped the change in new marketplace governance. Meta adopted the
draft WebMCP standard for its Ray-Ban Display glasses, a second product using it
alongside Google's Chrome. Shopify shut off the long-standing way apps injected code into
storefronts, and Cloudflare shipped the finished version of the sandbox it uses to
run customer and agent code.&lt;/p&gt;
&lt;h2&gt;Customization: Anthropic launches mods for Claude Code&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Anthropic launched mods for Claude Code, small programs that load inside the coding
tool and reshape how it works.&lt;/strong&gt; When the company
&lt;a href="https://github.com/anthropics/claude-code/issues/91870"&gt;named mods in September&lt;/a&gt;,
they were an early-access preview a user had to switch on by hand.
&lt;a href="https://claude.com/blog/claude-code-mods"&gt;As of October 1&lt;/a&gt; they ship through the
same plugin system Claude Code users already know, the shareable bundles that add
commands, connect outside tools, and run checks at set points in a session. A mod
goes deeper than those pieces. Where a plugin adds to the tool or reacts at fixed
points, a mod can rewrite what a user sends the model, step in on an action before it
runs, change part of the interface, or replace a built-in feature. A user can write
one, or ask Claude Code to write it. Anthropic has rebuilt some of Claude Code's own
built-in pieces, such as its file-difference view, as mods, so the same mechanism
that extends the tool now runs parts of it too. On Team and Enterprise plans, and any
machine an administrator manages, a built-in security mod loads first to limit what
the mods a user installs can do, such as blocking them from loosening the tool's
safety rules, and administrators choose which mods load.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why it matters:&lt;/strong&gt; this turns one of the most widely used coding tools into
something a user reshapes rather than only configures. A mod runs with the tool's own
reach into a user's files, programs, and network. For an individual user, installing
one means trusting whoever wrote it. In a managed workplace, the security mod and an
administrator decide what can load.&lt;/p&gt;
&lt;h2&gt;Platforms: Atlassian opens Forge app tools to agents built by other companies&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Atlassian widened the Rovo module it opened in August so a Forge app's tools now
reach AI clients outside Atlassian.&lt;/strong&gt; Since August, a marketplace app built on
Atlassian's Forge platform could expose its actions as tools inside Atlassian's own
Rovo agents; this week's
&lt;a href="https://developer.atlassian.com/platform/forge/changelog/"&gt;preview release&lt;/a&gt; lets
outside agents such as Claude Desktop and Cursor call those same tools.
Alongside it, Atlassian brought to general availability a separate module that lets
an externally hosted agent connect into Rovo, and gave administrators a
&lt;a href="https://developer.atlassian.com/changelog/"&gt;policy control over which outside AI tools may reach its agent server&lt;/a&gt;.
The company also launched &amp;quot;Enterprise Certified,&amp;quot; a marketplace trust tier it had
flagged in September as the successor to its retiring app-assurance program.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why it matters:&lt;/strong&gt; Atlassian is moving the unit a marketplace developer ships from
an app a person opens to a tool a customer's agent can call, and doing it for agents
built by other companies, not only its own.&lt;/p&gt;
&lt;h2&gt;Standards: Meta picks up the draft WebMCP standard for its smart glasses&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Meta documented how developers can use WebMCP, the draft standard that lets a
website offer tools to a visitor's AI agent, inside the web apps on its Ray-Ban
Display glasses.&lt;/strong&gt; That
&lt;a href="https://github.com/webmachinelearning/webmcp/pull/325"&gt;added a second product&lt;/a&gt; to
the proposal's implementation list alongside Google's Chrome, the only browser that
runs WebMCP today. In the same week the standard's editors kept working through the
objections it drew a week earlier and resolved a narrow one,
&lt;a href="https://github.com/webmachinelearning/webmcp/pull/330"&gt;dropping a setup requirement&lt;/a&gt;
that had made the draft harder to deploy on simple hosting and on browsers that have
not yet adopted it. The objections about privacy still
&lt;a href="https://github.com/webmachinelearning/webmcp/issues/313"&gt;sit open&lt;/a&gt;, and WebMCP
remains a Community Group draft that Chrome runs as an origin trial.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why it matters:&lt;/strong&gt; a second company now builds on the draft, and the editors cleared
a deployment barrier. But WebMCP is still a single-browser experiment, and the open
privacy objections, not deployment mechanics, are what stand between it and a standard
other browsers would implement.&lt;/p&gt;
&lt;h2&gt;Marketplace: Shopify closes off the old script-injection path for apps&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Shopify stopped letting apps register the script tags they had long used to
inject their own code into a merchant's storefront.&lt;/strong&gt;
&lt;a href="https://shopify.dev/changelog/online-store-script-tags-deprecation"&gt;As of October 1&lt;/a&gt;, apps can no
longer create new storefront script injections, and the ones already in place stop
running on March 1, 2027. Apps that added functionality this way have to move to
Shopify's newer extension points, which run an app's code in defined slots on the
page rather than letting it inject code anywhere.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why it matters:&lt;/strong&gt; script injection let an app run open-ended code on a storefront,
which is flexible but hard for the platform to secure and keep fast.
Shopify is trading that path for extension points it defines and controls. The
merchant gets a safer, quicker storefront, and Shopify gets a system it can keep
evolving. Every app that relied on injection has to rebuild. Adobe and Atlassian made
the same move over the past two weeks.&lt;/p&gt;
&lt;h2&gt;Infrastructure: Cloudflare ships the finished Sandbox SDK 1.0&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Cloudflare released the finished 1.0 of the Sandbox SDK, the managed layer a
product uses to run untrusted or agent-written code in an isolated container on
Cloudflare's network.&lt;/strong&gt; It
&lt;a href="https://developers.cloudflare.com/changelog/2026-08-07-sandbox-sdk-1-0-preview/"&gt;previewed this version in August&lt;/a&gt;.
At &lt;a href="https://developers.cloudflare.com/changelog/2026-09-30-sandbox-sdk-1-0/"&gt;1.0&lt;/a&gt;, a
product can run a customer's own code, an AI agent's code, or a code interpreter
inside a sandbox, decide how large it is and when it shuts down, control which
outside services the code may reach, and hand a customer an authenticated web address
to reach the app running in their sandbox. New in this release, and in public beta, a
product can also save a sandbox's files and restore them later, so a customer's
session survives a restart. Support for the older preview line ends December 31, 2026.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why it matters:&lt;/strong&gt; a managed sandbox lets a product offer customer or agent code
execution without building and running its own isolation infrastructure. A session's
files now persist, and a customer can open the app running inside their sandbox. That
lets a product host a standing per-customer environment rather than only running a
snippet and discarding it.&lt;/p&gt;
&lt;h2&gt;Also worth knowing&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Microsoft opened two programs for partners building AI agents on its
marketplace.&lt;/strong&gt; A
&lt;a href="https://learn.microsoft.com/en-us/partner-center/announcements/2026-september"&gt;new partner specialization&lt;/a&gt;
validates a company's ability to build, deploy, and secure agents across
Microsoft's stack, and a companion program helps partners publish AI apps and
agents to the Microsoft marketplace with Azure funding attached. Both are
certification programs for who can sell agent-based extensions, not new platform
capabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Google began the gradual rollout of the Workspace automation features it
announced in September.&lt;/strong&gt; The tools that let an ordinary Workspace user build
their own triggers and connect outside services
&lt;a href="https://workspaceupdates.googleblog.com/2026/09/automate-workflows-with-custom-starters-and-steps-third-party-integrations-and-webhooks-in-Workspace-Studio.html"&gt;started reaching scheduled-release customers on September 30&lt;/a&gt;,
off by default and behind an administrator's approval, confirming the slower
track the previous issue flagged. Google also began rolling out reusable
&amp;quot;skills&amp;quot; across its Gemini assistant and Workspace, a rollout it expects to run
through June 2027.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The reusable &amp;quot;skills&amp;quot; the Model Context Protocol finalized two weeks ago still
have not reached the toolkit developers build on.&lt;/strong&gt; The protocol's
&lt;a href="https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/v2.2.0"&gt;latest release&lt;/a&gt;
came and went without them, so the instruction bundles meant to carry a user's
customizations from one tool to another cannot yet move.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Figma keeps its editing MCP server closed to an approved list of AI clients,
and the limit drew fresh pushback this week.&lt;/strong&gt; Figma's remote Model Context
Protocol server, the one that can change a design file rather than only read it,
accepts only the clients on Figma's published catalog, such as Cursor, VS Code,
Claude Code, and Codex, and
&lt;a href="https://github.com/geelen/mcp-remote/issues/186"&gt;rejects any other agent at sign-up&lt;/a&gt;.
After an &lt;a href="https://news.ycombinator.com/item?id=49922729"&gt;October 1 thread&lt;/a&gt; put
the policy back in front of developers, the Model Context Protocol's own
maintainers repeated that gating which clients may connect cuts against the
protocol's premise that any client should work with any server. Figma set the
limit while the server is in beta and has not changed it this week, and it has
paused approving new clients.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;On the radar&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;October 6:&lt;/strong&gt; The W3C WebAssembly Community Group
&lt;a href="https://github.com/WebAssembly/meetings/blob/main/main/2026/CG-2026-10-06.md"&gt;takes up a proposal to create a dedicated subgroup for the Component Model&lt;/a&gt;,
the layer that lets WebAssembly plugins written in different languages compose.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;October 8:&lt;/strong&gt; The W3C WebExtensions Community Group holds its next public call.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;October 15:&lt;/strong&gt; The chartered W3C WebExtensions Working Group meets next.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;October 16:&lt;/strong&gt; Registration closes for the W3C's annual technical plenary, where
the WebExtensions group plans sessions on autofill and extension security.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;November 2:&lt;/strong&gt; Microsoft 365 Copilot Business switches to usage-based billing by
default.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;November 17:&lt;/strong&gt; Chrome's WebMCP origin trial is scheduled to end.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;December 31, 2026:&lt;/strong&gt; Support ends for the preview line of Cloudflare's Sandbox
SDK.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;March 1, 2027:&lt;/strong&gt; Shopify stops running storefront scripts injected the old way.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;This Week in Extensibility is curated by Todd Schiller. Research, drafting, and
fact checking are AI-assisted.&lt;/em&gt;&lt;/p&gt;
</content><category term="Extensibility"></category><category term="extensibility"></category><category term="plugins"></category><category term="sandboxes"></category><category term="web standards"></category><category term="MCP"></category><category term="WebMCP"></category><category term="Claude Code"></category><category term="Anthropic"></category><category term="Atlassian"></category><category term="Shopify"></category><category term="Cloudflare"></category><category term="Microsoft"></category><category term="Google"></category></entry></feed>