Security
PO9 is security-first. A skin is data, not a program: it can restyle a workspace, and nothing more.
Guarantees
Section titled “Guarantees”- No code execution. A
.po9-skinis a JSON document of color tokens, copy, and one static image — never scripts. - No network access. The CSS cannot use
@importor remoteurl(...), so a skin cannot phone home, fetch remote content, or exfiltrate anything. Inlineurl(data:...)is allowed. - Token-only. The CSS is scoped to
codedrobe-codex-skinand cannot target workspace-internal selectors, so a skin can only set--dream-*tokens — it cannot restyle or hide real app UI. - Bounded. One embedded image (PNG/JPEG/WebP/GIF), CSS ≤ 1 MB, whole document ≤ 30 MB.
- Validated on every boundary. Checks run at package time and again on import — a tampered file is rejected.
Reporting
Section titled “Reporting”Found a security issue in the spec, validator, or app? Please report it privately through GitHub Security Advisories rather than opening a public issue.