Skip to content

Security

PO9 is security-first. A skin is data, not a program: it can restyle a workspace, and nothing more.

  • No code execution. A .po9-skin is a JSON document of color tokens, copy, and one static image — never scripts.
  • No network access. The CSS cannot use @import or remote url(...), so a skin cannot phone home, fetch remote content, or exfiltrate anything. Inline url(data:...) is allowed.
  • Token-only. The CSS is scoped to codedrobe-codex-skin and cannot target workspace-internal selectors, so a skin can only set --dream-* tokens — it cannot restyle or hide real app UI.
  • Bounded. One embedded image (PNG/JPEG/WebP/GIF), CSS ≤ 1 MB, whole document ≤ 30 MB.
  • Validated on every boundary. Checks run at package time and again on import — a tampered file is rejected.

Found a security issue in the spec, validator, or app? Please report it privately through GitHub Security Advisories rather than opening a public issue.