Standalone Dream Skin theme management for codexhost-launched Codex: theme hot-switch, ZIP import, gallery, in-app settings page - non-invasive to Codex Dream Skin and codex-host
Automatic installation modifies a separately installed Codex-hosting CLI and its renderer. The patch causes package code to load and supervise during later codexhost launches, with CDP code evaluation in application targets.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic code evaluation.
src/tools/check-payload-render.cjsView on unpkg · L60Package source references dynamic require/import behavior.
src/patch.mjsView on unpkg · L107A manifest entrypoint or package-local install chain reaches persistence behavior.
install.mjsView on unpkg · L24Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.mjsView on unpkgA single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/cli.mjsView on unpkg · L19Source downloads or fetches remote code and executes it.
src/cli.mjsView on unpkg · L19Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/hook.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/platform.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/ui-verify.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/probe-action.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/probe-bridge.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/probe-export-logs.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/probe-status.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/probe-targets.cjsView on unpkgThis report applies to codexskin-hub@0.4.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source writes installer persistence such as shell profile or service configuration.
install.mjsView on unpkg · L24A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/cli.mjsView on unpkg · L19Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/cli.mjsView on unpkg · L19Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L20Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L20Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/hook.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/platform.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/ui-verify.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/probe-action.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/probe-bridge.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/probe-export-logs.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/probe-status.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/probe-targets.cjsView on unpkgPackage source references dynamic code evaluation.
src/tools/check-payload-render.cjsView on unpkg · L60Package source references dynamic require/import behavior.
src/patch.mjsView on unpkg · L107Source writes installer persistence such as shell profile or service configuration.
install.mjsView on unpkg · L24A manifest entrypoint or package-local install chain reaches persistence behavior.
install.mjsView on unpkg · L24Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.mjsView on unpkgA single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/cli.mjsView on unpkg · L19Source downloads or fetches remote code and executes it.
src/cli.mjsView on unpkg · L19A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/cli.mjsView on unpkg · L19Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/cli.mjsView on unpkg · L19