Claude Code mods can rewrite your agent's tool calls (and aren't sandboxed), Cloudflare's Clef-flash makes a decision in 39ms, Cohere's Embed 5 lets you query a Pro index with the cheap model, and Shopify's Canvas builds themes by chat
Friday, October 2, 2026·8 min read·4 stories
Friday's theme is control. One tool hands you the steering column of your coding agent, with a warning label attached. Another makes the small yes/no calls inside your agent cheap enough to run on every step. And two launches move the boring parts of a build, retrieval and storefront themes, a little further from hand-written code.
No sponsored or affiliate links in this digest — the links below are sources only.
Story I
Claude Code mods are TypeScript hooks on prompts, tool calls and permissions. They run with your full machine access
Anthropic released mods for Claude Code on October 1, in both the terminal and the desktop app. A mod is a TypeScript function that hooks Claude Code's internal events. It can rewrite a prompt before the model sees it, block, rewrite or retry a tool call, approve or deny a permission request, or strip secrets from a tool's output before Claude reads it. Mods can also touch the interface: add buttons and inputs, redraw elements, replace built-in features. Anthropic made the point itself by moving the diff view into a mod you can disable or swap out.
Distribution reuses plugins, so mods install through /plugin and can be kept private or submitted to the Claude directory. Early examples covered by Crypto Briefing include Token Weather (context usage with a 12-turn sparkline), Blast Radius (flags risky shell commands and shows affected files before they run) and Replay Theater (per-turn edit history via /replay). The catch is stated plainly: mods are not sandboxed and get the same access to your machine as Claude Code. On Team and Enterprise plans, a built-in security mod loads first so user mods can't override permission denials. On individual plans, nothing like that is mentioned.
For builders
Write one mod before you install anyone else's: a tool-output hook that redacts anything matching your secret patterns (sk-, AKIA, your .env keys) before Claude reads it. You can ask Claude Code to write it in the same session. Then treat third-party mods like npm packages with root: read the source, pin the version, and skip anything that hooks permission requests unless you wrote it.
Story II
Cloudflare's Clef-flash is a 9B open decision model with a 38.8ms median, and it speaks the Jev API
Yesterday we covered AWS's Strands Decider 2B. Cloudflare's entry is bigger and hosted. Clef (27B, on Qwen 3.8-27B) and Clef-flash (9B, on Qwen 3.5-9B) are the first models Cloudflare trained in-house, both Apache 2.0, both on Workers AI and Hugging Face, both with a 64k context and vision input. Instead of text they return a probability for every allowed option across three question types: yes/no, choice, and rubric score. Cloudflare says they are fully compatible with TypeSafe AI's Jev API, so a Jev integration should swap over without a rewrite.
Cloudflare's own latency numbers: 209.3ms median for Clef, 38.8ms median and 122.4ms p95 for Clef-flash. MarkTechPost cites Jev at 524.1ms and reports Clef ahead of Jev on 7 of 10 benchmarks, including BANKING77 intent classification (94.20 vs 79.74), but well behind on knowledge-heavy GPQA Diamond (48.0 vs 78.3). MarkTechPost also lists hosted input prices of $0.24 per million tokens for Clef and $0.09 for Clef-flash. Cloudflare's post doesn't give prices, so check the Workers AI pricing page before you budget. TechCrunch counts dozens of decision models since Jev launched. This category is filling up fast.
For builders
Decision models win at routing and classification, not at questions that need world knowledge. Take your agent's intent router or ticket triage step, export 200 labeled examples, and run them through Clef-flash as a single choice question. If accuracy holds, you've swapped an LLM call that writes tokens for one that returns calibrated probabilities in tens of milliseconds. Keep a general model on anything that looks like GPQA.
Story III
Cohere's Embed 5 Pro and Fast share one vector space. Index with Pro, query with Fast, no re-index
Cohere launched Embed 5 on September 30 in two tiers: Pro at $0.12 per million text tokens and Fast at $0.08, with image input at $0.40 per million on both. Both take 128K-token inputs, text and images (including mixed inputs), cover 100+ languages, and output 256 to 2048 dimensions as float, int8 or binary. They're on the Cohere API, Microsoft Foundry, Amazon SageMaker, and vLLM for private deployment.
The interesting design choice is that Pro and Fast share one embedding space. You can index documents with Pro and embed queries with Fast, as long as both use the same output dimension. On Cohere's numbers, Pro scores 85.8 on the ViDoRe V3 visual document retrieval benchmark, ahead of Voyage 4 Large (83.7), Gemini Embedding 2 (83.2) and OpenAI's text-embedding-3-large (75.5). Multilingual results are mixed: Pro leads on European languages but trails Gemini Embedding 2 on several Asian ones. Those are vendor benchmarks. Treat them as a reason to test, not a reason to migrate.
For builders
Do the storage math first. A 256-dimension binary vector is 32 bytes, so 100 million documents drop from roughly 819 GB as 2048-dim float32 to about 3.2 GB. If your vector bill hurts, run your existing eval set three ways (your current model, Embed 5 Pro at 2048 float, Embed 5 Pro at 256 binary with Fast queries) and only switch if recall@10 on your own data holds.
Story IV
Shopify's Canvas edits real theme code by chat. Third-party themes, app blocks and translations aren't in v1
Shopify launched Canvas on October 1, a builder where merchants change their store by talking to Sidekick, Shopify's AI agent. Unlike a mockup tool, it renders the store's actual code live, so you can check interactions, animations and how a page looks across screen sizes while you edit. You can also edit elements directly next to the AI changes. It's desktop only for now.
The launch list of what's missing matters more than the feature list. Shopify confirmed that third-party themes, app blocks and extensions, Markets and translations, and rollouts and theme updates are not in the first version, with no dates given for any of them. Shopify hasn't said what Canvas costs or which plans get it. TechCrunch frames it as Shopify going after Wix, Squarespace and Webflow. On Tuesday we wrote about Shopify opening checkout to browser agents. This is the same company now putting an agent on the merchant side, too.
For builders
If you build or maintain Shopify themes for clients, note what Canvas can't touch: custom third-party themes and app blocks. That's your moat for now. Put a line in your next client update about it before they ask. If you run a store on a Shopify-made theme, duplicate the theme before your first Canvas session, since rollouts aren't supported yet and you'll want a clean copy to fall back to.