Claude Code's New 'Second Set of Eyes' Agent Runs With Full Access to Your Machine
Kaino
YesterdayOct 4, 2026, 12:00 AM16 views

Claude Code's New 'Second Set of Eyes' Agent Runs With Full Access to Your Machine

Claude Code 2.1.287 introduces Mods and a built-in side agent, but third-party extensions inherit the user’s permissions.

Claude CodeClaude ModsAnthropicAI coding agentdeveloper tool securityUnsandboxed codeAI oversight agent

Claude Code 2.1.287 introduces Claude Mods, a new extension system that runs JavaScript and TypeScript directly inside Claude Code — and ships with a built-in mod called "You should know," described as a side agent whose job is to flag things the main agent or the user might have overlooked during a coding session.

The underlying idea is a genuinely useful one. A coding agent is productive partly because it moves fast, but speed is exactly what makes it easy to miss an implication, a prerequisite, or a conflicting change elsewhere in the codebase. A dedicated second agent built specifically to catch omissions is a more concrete, testable idea than a vague promise of "smarter AI."

Here's the part that actually matters for how you adopt this: Claude Mods are not sandboxed. According to an analysis by THE DECODER / MIXED, Anthropic itself warns that mods run with the user's own permissions — meaning installing a mod isn't like flipping a setting, it's running code that can access whatever your development environment already has access to: your working directory, credentials, network connections, and reportedly even your Anthropic API key, depending on configuration. Anthropic's own release notes confirm Mods and the built-in watcher exist, but don't independently detail exactly how API-key access is handled — that detail comes from the third-party analysis.

To be clear, none of this means any specific mod is malicious, or that Anthropic's own "You should know" mishandles anything. What it does establish is a real design fact: the safety of this whole system depends on what code you choose to trust and install, not on any sandbox doing that work for you.

It's worth treating Anthropic's built-in watcher and any third-party mod as genuinely different trust decisions. The built-in one ships directly from Anthropic as part of Claude Code. An external mod brings a new, unvetted code publisher into your dev environment — and deserves the same scrutiny you'd give any other locally executed developer tool: know the publisher, check what the code actually does where you can, and remove anything you're not actively using.

Bottom line: An oversight agent catching what the main agent misses is a promising idea, and worth trying if you want another layer of attention during Claude Code sessions. But the execution model — unsandboxed, running with your own permissions — means mods need the same caution you'd apply to any other code you let run on your machine, not the casual trust of a toggle switch.

Key takeaways
  • 1

    A coding agent is productive partly because it moves fast, but speed is exactly what makes it easy to miss an implication, a prerequisite, or a conflicting change elsewhere in the codebase.

  • 2

    Anthropic's own release notes confirm Mods and the built in watcher exist, but don't independently detail exactly how API key access is handled — that detail comes from the third party analysis.

  • 3

    To be clear, none of this means any specific mod is malicious, or that Anthropic's own "You should know" mishandles anything.

Continue reading

Latest from Kaino News