Validation
The Validator is the gate every .po9-skin passes before it runs. The same checks run in the CLI and in the app.
What it checks
Section titled “What it checks”- Security — no executable code, no remote CSS or
@import, no workspace-internal selectors. A skin is a token-only palette plus one embedded image. See Security. - Compatibility — the file’s
schemaVersionis supported by the target. See Versioning. - Structure — the document shape is well-formed: required
format,schemaVersion,manifest, andcss;artpresent iffmanifest.artis set; safe local paths. - Content — required manifest fields (
id,displayName,version,attribution.creator,attribution.rights); English-only; CSS ≤ 1 MB; document ≤ 30 MB.
Run it
Section titled “Run it”npx po9-skin validate ./my-skinA clean run exits 0. Any failure prints the rule and a fix hint and exits non-zero — so it drops straight into CI. Failures name the problem, e.g. “CSS must be scoped to codedrobe-codex-skin” or “CSS must not target Codex-internal selectors”.
Severity
Section titled “Severity”- Error — the skin is invalid and will not load. Must fix.
- Warning — allowed, but discouraged (e.g. an oversized image).