Documentation · get-codex-theme@0.7.0

Security model

The trust boundaries for local code, publishing tokens, identity, downloads, and community actions.

01

Local safety

  • Theme inputs are treated as data, never executable instructions.
  • The CLI does not execute scripts from a pack.
  • Application bundles remain untouched.
  • Local services bind to loopback and restoration is tested.

02

Publishing safety

  • Build and publish capabilities are separate.
  • Tokens are short-lived, purpose-bound, one-time secrets.
  • Origin and browser-mutation checks protect account actions.
  • Server-side validation is authoritative.
  • Secrets, raw IP addresses, and internal account IDs are not exposed on public creator pages.

03

Community safety

Requests and votes require an account, are rate-limited, and use keyed pseudonymous abuse identifiers. Reference uploads remain disabled until automated file-safety checks and quarantine are configured.

PUBLISHER ACCESS

Sign in to
share your work.

Use an identity you already trust. We only use it for contributor attribution and publishing access.

No password or email registration. Your provider verifies your identity.