01
Verified Windows target
The runner validates the registered Microsoft Store package, manifest executable, signature kind, process path, debugger owner, and launch-time Browser ID.
Safety model
CodexSkin changes the renderer you see without modifying the application you trust. Safety comes from strict inputs, exact local identities, visible restart consent, and a tested recovery path—not from pretending CDP is harmless.
No app patch
No credential migration
127.0.0.1 only
Verified restore
01
The runner validates the registered Microsoft Store package, manifest executable, signature kind, process path, debugger owner, and launch-time Browser ID.
02
The themed launch keeps your current Codex profile. It does not copy, migrate, or rewrite credential data.
03
CodexSkin tells you to save unfinished input and never closes an open Codex window without explicit approval.
04
Unknown JSON fields, arbitrary CSS, absolute paths, extra scripts, unsafe URLs, and oversized image content are rejected.
05
WindowsApps, app.asar, installers, application bundles, and official code signatures are never modified.
06
Restore checks the saved package, process, port, Browser ID, Node, and injector identities before stopping anything.
Remaining CDP risk
Binding Chromium DevTools Protocol to 127.0.0.1 prevents LAN access, but CDP has no same-user authentication. Other software running as your user could attempt to inspect the themed renderer. Run only trusted local software and restore when finished.
Unsigned preview
“Store package verified” refers to the official Codex application, not CodexSkin. The current ZIP and launcher scripts are not code-signed. Compare the downloaded ZIP against the published SHA-256 before running it.
Ready to continue?