Standalone Dream Skin theme management for codexhost-launched Codex: theme hot-switch, ZIP import, gallery, in-app settings page - non-invasive to Codex Dream Skin and codex-host
LPM flags this version as an AI-agent control-surface risk. Automatic installation modifies the separate @codexhost/cli launcher and renderer to load package code. The injected code can run a detached supervisor against Codex Desktop's local debugging interface.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install.mjsView on unpkg · L20A manifest entrypoint or package-local install chain reaches persistence behavior.
Package source references dynamic require/import behavior.
src/patch.mjsView on unpkg · L107A single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/cli.mjsView on unpkg · L19Source downloads or fetches remote code and executes it.
src/cli.mjsView on unpkg · L19A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/platform.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/ui-verify.mjsView on unpkgThis report applies to codexskin-hub@0.3.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source writes installer persistence such as shell profile or service configuration.
install.mjsView on unpkg · L25A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/cli.mjsView on unpkg · L19Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L20Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L20A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/platform.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/ui-verify.mjsView on unpkgSource writes installer persistence such as shell profile or service configuration.
install.mjsView on unpkg · L25Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install.mjsView on unpkg · L20A manifest entrypoint or package-local install chain reaches persistence behavior.
install.mjsView on unpkg · L25Package source references dynamic require/import behavior.
src/patch.mjsView on unpkg · L107A single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/cli.mjsView on unpkg · L19Source downloads or fetches remote code and executes it.
src/cli.mjsView on unpkg · L19A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/cli.mjsView on unpkg · L19