Security

Security Notes

CodexPet Nest treats marketplace packages as data, not executable code.

Package Safety

Nest packages may contain static images, metadata, layout JSON, and built-in widget slots. They must not contain scripts, WebViews, hidden local targets, or executable commands.

Verification

Downloaded packages should be checked with SHA256 and extracted with path traversal protections before installation.

Independence

CodexPet Nest is an independent open-source project and does not patch or inject into Codex Desktop.