HeiGe Codex Skin Studio themes Codex Desktop over a debug port it does not own
给 Codex Desktop 一键换肤:OpenAI Codex/ChatGPT 桌面端主题工具,CDP 注入零修改应用,Miku/原神/鸣潮/火影/恋与深空 9 预设+自定义图片取色 | One-click theme & skin switcher for OpenAI Codex Desktop (macOS/Windows)
At a glance
- What is it?
- A JavaScript theming tool that attaches to Codex Desktop through a local Chrome DevTools Protocol port and injects a skin at runtime, leaving app.asar alone. The Chinese README is unusually candid about the three places the project is not finished.
- Who is it for?
- Install this if you want a themed Codex Desktop and you accept that the mechanism is a debug port rather than a supported extension point, because that is the only route it found that leaves the application binary alone. Read the ad hoc signing paragraph before you hand the Mac launcher to Gatekeeper, since it is explicitly not a Developer ID signature and not notarized.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 4 days ago.
- What is it written in?
- Mainly JavaScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The skin rides a local debug port on your own machine
The mechanism is the Chrome DevTools Protocol attached to a loopback port. Codex Desktop is driven through 127.0.0.1:9341 and Tencent's WorkBuddy through 127.0.0.1:9342, two numbers picked so the products do not collide when both are running. The payload is injected at runtime, so app.asar, the application binaries and the signing resources are never written to, and the native controls stay clickable rather than becoming a picture of a control. That is the appeal of the approach and also its ceiling: the documentation states that if Codex Desktop changes its launch arguments or its interface structure, this project may still need adapting. Nothing is patched into the host application, and nothing about a host upgrade requires reverting anything.
WorkBuddy gets a one-shot skin, and that one is a decision
WorkBuddy runs on the same engine under two deliberate restrictions. The first concerns the control channel. Its renderer is a local file:// page, so a callback arriving at the control service carries an origin of null, and allowing that through would weaken the service's own origin check, so this version leaves the channel closed. The stated consequence is that WorkBuddy receives a one-time skin with no persistence: after a restart the skin is gone, and that is expected, fixed by applying again. The command is short:
"<仓库路径>/scripts/workbuddy-apply.command" --restartRestoring runs scripts/workbuddy-restore.command. Verification is uneven underneath that: macOS was checked against a real WorkBuddy 5.3.11, while the Windows side has the structure written but nothing behind it on a real device.
Two different theme counts, and the headline one is generated
The repository description advertises nine presets with custom image colour extraction. The theme section of the Chinese README is headed thirteen built-in themes, and the arithmetic backs the larger number: Miku 488137 as the high precision base, two lightweight themes for each of four named franchises, then three further entries and one easter egg preset. Nine is the total if you stop at the franchise set. That heading also sits directly under an empty marker, an HTML comment reading heige-bundled-theme-count, which is the shape of a value written by a generator rather than typed by a person, and the manifest carries a sync script that runs node scripts/sync-derived.mjs. The headline number is therefore derived data, while the description was written against a narrower idea of what counts as a preset.
A Node command line entry point sits next to the double-click scripts
Everything the documentation asks you to run is a file you double-click: scripts/install.command on macOS, or scripts\windows\install.bat on Windows. Underneath that sits an entry point the documentation never mentions. The manifest declares a bin named heige-codex-skin pointing at src/cli.mjs, and four npm scripts wrap its subcommands, each in the form node src/cli.mjs followed by doctor, status, list or apply. The package is marked private and declares no runtime dependencies at all; the only two devDependencies are happy-dom, a DOM implementation used by the tests, and yazl, a zip writer. A theming engine with zero runtime dependencies is a defensible choice, and the cost of it is that the command line surface is the part of the tool with no written entry in the project's own instructions.
Node 22 is required three times over, and one entry always fails
The manifest sets engines.node to 22 or newer and pins the package manager to npm 10.9.8. The documentation repeats the Node requirement in narrower form, saying that Node.js 22 or newer is needed when using system Node. The hedge is doing real work, because WorkBuddy does not bundle an executable Node of its own, so on that product path a system Node is not optional. A second requirement hides in the legacy entries. enable-skin.command survives as a session-only compatibility entry, while enable-persist.command is now a deprecated entry that exits with a non-zero status. A script left sitting in a scripts directory that always fails is a trap for anyone following an older guide, and the current instructions do not warn about it.
The Mac launcher is ad hoc signed, not Developer ID
Installing on macOS creates or upgrades a native application in $HOME/Applications, the HeiGe skin launcher, and every install regenerates it at what the documentation calls Schema 5. It uses an independent Hatsune Miku window logo, reads the real Codex and WorkBuddy application icons off the machine, registers itself with LaunchServices, and folds its universal AppKit binary, Dock icon, window logo and entry point into a local ad hoc integrity signature. The documentation is careful about what that signature is not. Ad hoc signing is there to detect local tampering, it is explicitly not the same as an Apple Developer ID signature or notarization, and it carries no promise to bypass future system security policies. Gatekeeper users should read that paragraph before assuming the launcher is a signed and notarized application. The launcher also states that it creates no new login items, downloads no code over the network and asks for no administrator rights.
Reading enhancement ships switched on, with an opacity floor
One display feature is enabled by default rather than offered. Reading enhancement is on out of the box, and at the default of 50 steps both the final reply and the intermediate replies get a theme matched semi-transparent background at 90 percent opacity, with symmetric padding kept in place so text stays readable. The transparency slider in the theme center runs from 0 to 100, where 50 preserves the original look and higher values get more transparent, and the mask never drops below 60 percent opacity. Turning reading enhancement off leaves the reply background fully transparent rather than reverting to opaque. The preference is stored locally and synced across windows, the slider applies to every Codex theme, and WorkBuddy skinning does not show it at all. The documentation also states what the feature deliberately avoids: no large area real-time blur, no shadows, no observers, no scroll listeners and no background requests.
The Windows Store build needs a one-time administrator grant
The Windows 11 path is the least finished part. Installation uses scripts\windows\install.bat and the daily entry point is scripts/windows/apply.ps1, surrounded by compatibility wrappers named enable-skin.bat, pause.ps1, resume.ps1, restore.ps1, close-codex.bat and enable-loopback.bat. The caveat that matters is attached to the Microsoft Store and MSIX build, which is still waiting on real-device verification. Where the store version reports loopback isolation, you run enable-loopback.bat once with administrator rights and retry the apply, and auto takeover cannot complete while that port stays unreachable. The script exists precisely so the privilege prompt does not appear on every single apply. The removal path is the most complete part of the Windows story: uninstall.bat deregisters the per-user scheduled task, removes the Start menu entry and clears AppData state, and it still works when the stable install directory has been deleted by hand.
Editorial conclusion
Install this if you want a themed Codex Desktop and you accept that the mechanism is a debug port rather than a supported extension point, because that is the only route it found that leaves the application binary alone. Read the ad hoc signing paragraph before you hand the Mac launcher to Gatekeeper, since it is explicitly not a Developer ID signature and not notarized. Treat the Windows Store build as unfinished, and treat its one-time loopback grant with the same caution as any other administrator step. And if you count presets before deciding, count the cards in the theme center, because the description text and the generated heading disagree about whether you have nine or thirteen.
Frequently asked questions
Does HeiGe Codex Skin Studio modify the Codex app itself?
No. Injection runs through a local loopback CDP session on 127.0.0.1:9341 and leaves app.asar, the application binaries and the signing resources untouched. The Mac launcher carries an ad hoc integrity signature for tamper detection, not an Apple Developer ID signature.
Why does the WorkBuddy skin disappear after I restart?
That is the documented behaviour. The WorkBuddy renderer is a local file:// page whose callbacks arrive with an origin of null, so this version leaves the control channel closed and applies a one-time skin only. Running the apply command again restores it.
How many themes does heige-codex-skin-studio ship with?
The theme section is headed thirteen built-in themes, counting Miku 488137, two lightweight themes for each of four franchises, three further entries and one easter egg preset. The repository description advertises nine presets.
Can I build a theme from a single image in HeiGe Codex Skin Studio?
There are three documented routes: upload through the theme menu, which writes a user theme with automatic colour extraction; run customize.command against a PNG, JPG, JPEG or WebP; or hand output/heige-codex-skin-studio.skill to Codex and let it generate and apply the theme without an extra API key.
What does the skin persistence switch actually install?
Turning it on registers a login scheduled task for the current user on Windows, with a LaunchAgent used on macOS, so a background controller restores the last skin on a normal start. The launcher itself creates no new login items and requests no administrator rights.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/heigeai-heige-codex-skin-studio)