Security
Security Notes
CodexPet Nest treats marketplace packages as data, not executable code.
Package Safety
Nest packages may contain static images, metadata, layout JSON, and built-in widget slots. They must not contain scripts, WebViews, hidden local targets, or executable commands.
Verification
Downloaded packages should be checked with SHA256 and extracted with path traversal protections before installation.
Independence
CodexPet Nest is an independent open-source project and does not patch or inject into Codex Desktop.