Skip to content
CAI
Software that uses CAICheck a score

Fei-Away/Codex-Dream-Skin

43.9

Weak · 1 October 2026

16.4k

lines of production code

JavaScript

with Swift

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a cross-platform theme engine for the Codex desktop application, providing native menu bar and system tray interfaces for macOS and Windows respectively. It enables users to apply, manage, and switch visual skins while enforcing strict security and stability through a unified runtime that validates CSS policies, image dimensions, and DOM selectors. The engine supports community themes via secure import mechanisms and includes comprehensive tooling for selector verification and automated testing to ensure compatibility across platform updates.

Features

Introduce Windows one-click installer with bundled Node.js runtime

Users can now install Codex Dream Skin on Windows via a single executable installer built with Inno Setup. The installer bundles the Node.js v22.23.1 runtime (verified by SHA-256), supports Simplified Chinese localization, and handles the full lifecycle: it waits for the Codex application to close, installs the theme engine, registers the 'dreamskin:' protocol, and offers an optional startup shortcut. Uninstallation safely restores the original Codex appearance and cleans up the runtime.

windows/installer · high confidence

Introduce Windows-side Dream Skin runtime and community theme application

This change adds the core Windows PowerShell scripts that power the Codex Dream Skin feature, including the system tray interface, theme application logic, and community theme installation. The new scripts enable users to apply and manage skins via a tray menu, check for client updates, and safely install community themes from the DreamSkin.cc API with strict validation (SHA-256, size limits, and Safe CSS checks). It also introduces bilingual (English/Chinese) localization support and robust file handling for configuration and state management.

windows/scripts · high confidence

Introduce canonical cross-platform skin runtime with safe CSS and theme validation

The runtime now ships a unified, cross-platform skin system that enforces strict safety and compatibility constraints. A new \dream-skin.css\ defines the core visual tokens and layout behaviors, while \renderer-inject.js\ applies these styles dynamically based on a selector contract and theme configuration. To prevent unsafe or breaking styles, \safe-css-validator.mjs\ and \safe-css-policy.json\ restrict community themes to a whitelist of CSS properties, variables, and structural parts. Theme packages are validated via \theme-package-validator.mjs\ to ensure manifest integrity and correct file structures, and \image-metadata.mjs\ provides a lightweight, zero-decode parser to validate image dimensions and aspect ratios before they are processed, ensuring performance and layout stability.

runtime · high confidence

Introduce macOS menubar app for Dream Skin management

This change introduces the macOS menubar application (Codex Dream Skin) that manages the Dream Skin engine and themes. It provides a status bar interface for applying, pausing, and switching themes, including support for one-click community theme application via the 'dreamskin://' URL scheme. The app features bilingual UI (English/Chinese), automatic background update checks with notifications, and secure handling of community theme imports with rollback capabilities. It also includes a custom HTTP client for bounded downloads and integrates with the system's notification center for update alerts.

macos/menubar-app · high confidence

Introduce secure, verified theme application and macOS build pipeline

This change adds a comprehensive set of macOS scripts that enable safe, verified theme application and reliable DMG distribution. Users can now import community themes via ZIP packages with strict size, entry, and content validation, and apply them through the menu bar with visible progress, localized prompts, and automatic rollback if the visible renderer does not match expectations. The build pipeline (build-menubar-app.sh and build-dmg.sh) now enforces architecture, version, icon, and preset integrity checks, and rejects rights-restricted presets. Image loading is protected by a preflight dimension check that rejects oversized files before rasterization, and update checks include a fallback to the release URL when the GitHub API is rate-limited.

macos/scripts · high confidence

Introduces a safe CSS policy and validator for theme skins

The macOS assets now include a strict validation layer for community themes to prevent unsafe or malformed CSS from breaking the UI. A new \safe-css-policy.json\ defines the allowed CSS parts, states, variables, and properties, while \safe-css-validator.mjs\ enforces these limits (e.g., max bytes, rules, declarations) at runtime. This is complemented by a \selectors.json\ contract that standardizes DOM selectors across platforms and versions, ensuring themes can reliably target UI elements without relying on unstable class names or hashes. The \theme-package-validator.mjs\ further validates theme package structure and metadata. These changes improve stability and security by rejecting invalid themes early and ensuring consistent rendering behavior.

macos/assets · high confidence

Introduces safe CSS policy and theme validation for Windows skins

The Windows assets now include a new safe CSS policy (\safe-css-policy.json\) and a validator (\safe-css-validator.mjs\) that enforce strict limits on CSS size, rules, and properties, allowing only a defined set of theme variables and safe CSS features. A new theme package validator (\theme-package-validator.mjs\) ensures theme packages meet manifest and content requirements. Additionally, a selector contract (\selectors.json\) defines stable DOM anchors for cross-platform skinning, and the renderer (\renderer-inject.js\) has been updated to use these contracts and apply the safe CSS policy, improving stability and security for user-installed skins.

windows/assets · high confidence

New selector contract and tooling for cross-platform DOM verification

This change introduces a unified selector contract (tools/selectors.json) that defines stable DOM anchors for the Codex Dream Skin across macOS and Windows, including support for new Codex 26.818 layout changes like the \ComposerLayoutRoot\ CSS module. To ensure these selectors remain accurate as the underlying Codex desktop app evolves, a new provenance gate (check-selector-provenance.mjs) now enforces that any selector modification must be accompanied by updated verification evidence (date, version, and evidence type). The tooling suite also adds a DOM capture utility (capture-dom-fixture.mjs) for generating cross-platform snapshots, a selector doctor (doctor-selectors.mjs) for grading selector health against live app states, and a build-time asset synchronizer (sync-runtime-assets.mjs) that compiles the contract into the runtime injectors and CSS files for both platforms.

tools · high confidence

Behavioural changes

macOS native menu bar app and theme engine update to v1.5.18

The macOS location now ships a native menu bar application (Codex Dream Skin) that replaces the previous SwiftBar plugin, providing a unified interface for theme switching, image customization, and status monitoring. This release bumps the version to 1.5.18 and includes significant behavioral changes: the menu bar now supports automatic background update checks with system notifications, organizes options into submenus to reduce visual noise, and adds persistent language selection (System/English/Chinese). It also fixes critical issues such as respecting quit cancellation during reapplication, handling GitHub API rate limits gracefully, preserving native Codex font preferences, and correcting version detection logic that previously caused false update notifications. The engine now uses a continuous full-window wallpaper approach instead of separate home banners, with adaptive readability layers for different routes.

macos · high confidence

Test coverage

Added Windows test coverage for theme injection, installer, and configuration rollback; Expanded test coverage for macOS skin application and runtime stability.

Dependencies

Updated macOS package versions and added Swift Package manifest

The macOS build configuration has been updated to version 1.5.18 in the Node.js package manifest (macos/package.json). Additionally, a new Swift Package Manager manifest (macos/menubar-app/Package.swift) was introduced to define the 'CodexDreamSkinMenuBar' executable, its core library dependency, and associated tests, targeting macOS 13 or later.

(dependencies) · high confidence

Housekeeping

Windows changelog and documentation initial release

The Windows directory now includes a comprehensive changelog (v1.5.18), English and Chinese READMEs, and a SKILL.md guide, documenting the platform's one-click theme application, managed CDP profile support, and theme import security. This entry reflects the addition of these documentation artifacts rather than a functional code change.

windows · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 43 → 44 (+1.0)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 23 → 25 (+1.1)
  • Architecture 100 → 97 (-3.0)
  • Maturity 62 → 63 (+0.4)
  • Readiness 49 → 48 (-1.1)
  • Security 74 → 67 (-6.8)
  • Performance 100 (new)

Resolved (2)

  • Dependency hygiene PARTLY measured — SwiftPM pinning read, dependency currency NOT established
  • Off-boarding risk: anonymized user #1

New (58)

  • Documentation: contradicts the code (docs/compat-profile-design.md)
  • Duplicated block (5 lines × 3) (macos/menubar-app/Sources/CodexDreamSkinMenuBar/AppDelegate.swift)
  • Duplicated block (6 lines × 2) (macos/menubar-app/Sources/CodexDreamSkinMenuBar/AppDelegate.swift)
  • FileTooLong: assets/renderer-inject.js (macos/assets/renderer-inject.js)
  • FileTooLong: assets/renderer-inject.js (windows/assets/renderer-inject.js)
  • FileTooLong: runtime/renderer-inject.js (runtime/renderer-inject.js)
  • FunctionTooLong: renderer-inject.analyzeArt (macos/assets/renderer-inject.js)
  • FunctionTooLong: renderer-inject.analyzeArt (runtime/renderer-inject.js)
  • FunctionTooLong: renderer-inject.analyzeArt (windows/assets/renderer-inject.js)
  • Hotspot: macos/assets/renderer-inject.js (macos/assets/renderer-inject.js)
  • Hotspot: macos/assets/safe-css-validator.mjs (macos/assets/safe-css-validator.mjs)
  • Hotspot: macos/menubar-app/Sources/CodexDreamSkinMenuBar/AppDelegate.swift (macos/menubar-app/Sources/CodexDreamSkinMenuBar/AppDelegate.swift)
  • Hotspot: macos/scripts/injector.mjs (macos/scripts/injector.mjs)
  • Hotspot: macos/scripts/publish-theme-import.mjs (macos/scripts/publish-theme-import.mjs)
  • Hotspot: macos/scripts/theme-config.mjs (macos/scripts/theme-config.mjs)
  • Hotspot: runtime/renderer-inject.js (runtime/renderer-inject.js)
  • Hotspot: runtime/safe-css-validator.mjs (runtime/safe-css-validator.mjs)
  • Hotspot: windows/assets/renderer-inject.js (windows/assets/renderer-inject.js)
  • Hotspot: windows/assets/safe-css-validator.mjs (windows/assets/safe-css-validator.mjs)
  • Hotspot: windows/scripts/injector.mjs (windows/scripts/injector.mjs)
  • …and 38 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Fei-Away/Codex-Dream-Skin was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 34335d27d54300eccb325cc652f6c93fef428b84 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.