Security fixes are applied to the latest published GptSkin Skill release. Please update to the newest release before reporting an issue that may already be resolved.
Please do not open a public issue for a suspected vulnerability.
Email support@gptskin.best with the subject Security report and include:
- the affected GptSkin Skill version and operating system;
- reproducible steps;
- the potential impact;
- any suggested mitigation;
- whether the issue is already public.
Do not include passwords, API keys, payment credentials, private Codex conversations, or data belonging to another person.
We aim to acknowledge a valid report within 3 business days. We will investigate, coordinate a fix, and agree on a responsible disclosure timeline before public discussion.
GptSkin applies visual themes locally. It does not read, modify, or transmit Codex conversations. The Skill launches Codex with a loopback-only Chrome DevTools Protocol endpoint while applying a theme. Another process running as the same local user could attempt to connect while that process remains open, so only run the Skill on a trusted machine.
The complete and current security model is published at gptskin.best/docs/security.
GptSkin is an independent product and is not affiliated with or endorsed by OpenAI.