Skip to content

Validation

The Validator is the gate every .po9-skin passes before it runs. The same checks run in the CLI and in the app.

  • Security — no executable code, no remote CSS or @import, no workspace-internal selectors. A skin is a token-only palette plus one embedded image. See Security.
  • Compatibility — the file’s schemaVersion is supported by the target. See Versioning.
  • Structure — the document shape is well-formed: required format, schemaVersion, manifest, and css; art present iff manifest.art is set; safe local paths.
  • Content — required manifest fields (id, displayName, version, attribution.creator, attribution.rights); English-only; CSS ≤ 1 MB; document ≤ 30 MB.
Terminal window
npx po9-skin validate ./my-skin

A clean run exits 0. Any failure prints the rule and a fix hint and exits non-zero — so it drops straight into CI. Failures name the problem, e.g. “CSS must be scoped to codedrobe-codex-skin” or “CSS must not target Codex-internal selectors”.

  • Error — the skin is invalid and will not load. Must fix.
  • Warning — allowed, but discouraged (e.g. an oversized image).