Mod security: L0–L3 explained
These are directory scan levels
L0–L3 are ClaudeMods' descriptions of detected capabilities. They are not Anthropic permission modes, an operating-system sandbox or a certification. A higher level describes additional access; a lower level does not prove that code is harmless.
| Level | Detected capability | What to ask before installing |
|---|---|---|
| L0 | Display or pure logic | Does it mislead or expose sensitive text? |
| L1 | Read files or environment | Which paths or secrets can it read? |
| L2 | Write, execute or alter tool behavior | Can it overwrite work or run commands? |
| L3 | Network or model access | Where can it send data and what can it cost? |
Read the findings
Open the cited file and line, then inspect surrounding code. Trace imported modules and package dependencies. An incomplete scan must stay “incomplete”; do not treat missing findings as zero permissions. A network call hidden behind a library can evade simple pattern detection.
Reduce exposure
Try the mod in a disposable project without production credentials. Grant only the access the feature requires. Review updates because new code can change the permission footprint. A tool-call guard is itself behavior-changing code; it needs review and must not replace the host's permission checks.