# CSSwitch ships one signed-by-nobody macOS package and calls its own MCP support done

> CSSwitch is a Rust and Tauri desktop app that points Claude Science at a third-party model API instead of the official one. The provider and skill work is described in detail, MCP is marked as not yet available in the very release that advertises it, and the Linux build is a prerelease three patches behind the macOS one.

**SuperJJ007/CSSwitch** — 帮你的 Claude Science 一键接入你自己的 API：DeepSeek / 通义千问 / 智谱 GLM / Kimi / MiniMax / 小米 MiMo / 硅基流动 / OpenRouter / 任意 OpenAI·Anthropic 兼容端点

- Repository: https://github.com/SuperJJ007/CSSwitch
- Stars: 473 · Forks: 46
- Language: Rust
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/superjj007-csswitch

## One package, ad-hoc signed, and a Linux build three patches behind

The platform story is narrow and stated as a boundary rather than a roadmap. The official build is macOS Apple Silicon, version v0.8.4, distributed as an aarch64 disk image that you drag into Applications, and the document says the public desktop package supports macOS Apple Silicon only. Linux x64 users are pointed at a separate artefact, the v0.8.1 prerelease with an amd64 `.deb`, which is three patch versions behind the macOS build and marked as a prerelease rather than a release. Installation also assumes Claude Science is already present and that you hold either a third-party API key or a Codex account. The signing position is unusually candid: the first launch is expected to be blocked by macOS, the fix is to right-click the app and choose Open, and the public package is described as ad-hoc signed, explicitly not a Developer ID signature, not notarised and not a Gatekeeper conclusion. Every user does the manual bypass once.

## The MCP row says coming soon in the release that links to it

The feature table has four rows and they do not all say the same thing. Providers and models are marked supported, with built-in providers, relay services and custom compatible endpoints, and model names mapped strictly to what Science uses. Codex is marked experimental: it logs in through its own browser flow with its own account model catalog, is off by default, and does not read or modify the native Codex login directory. Skills are marked supported. MCP is marked as coming soon, with the note that v0.8.4 does not yet give users a way to add, configure or run their own MCP servers. The MCP section repeats it and adds a warning that the internal connector used for Skill installation should not be mistaken for MCP support, since that connector only installs, uninstalls and reports long-task status. So a feature list that mentions MCP is not a feature that works, and the document is careful to say so twice.

## The Skill installer pins a commit and never uses your credentials

Installing a public Skill is the most carefully specified part of the application. When you hand Science an accurate public GitHub URL, CSSwitch's host process does the work: anonymous download, pinning a specific commit, verification, then commit and bind, explicitly without using Science's or your own GitHub credentials. Before anything is installed it checks archive size, file count, path traversal, symbolic links, special files and name conflicts, and the commit step is atomic, so a name collision or already-modified content is never silently overwritten. Local packages go through the system file picker and accept `.zip` or `.skill`, with single skills and multi-skill bundles told apart automatically, and the frontend neither receives nor submits local file paths. Bundle handling is conservative too: a bundle keeps its shared directory and support assets, and uninstalling from any member must first show the full impact list and require confirmation before the package is detached and reclaimed as a whole.

## Bound is not the same as loaded, and the page says so twice

The Skill page draws a distinction that most installers do not. The list reports skills that genuinely exist in the current Science organisation, with their source, whether each is a single skill or a bundle, and one of three binding states named attached, detached or unknown. When Science is not running or its identity cannot be confirmed, the page refuses to guess. Then there is the trap the documentation keeps pointing at: attached only means the OPERON read-back succeeded at that moment, and it does not mean the current Agent session has loaded the skill, which is why the advice is to call `skill()` in the session and confirm. The same warning appears in the installation walkthrough, where a page that says bound is still followed by a suggestion to verify by invoking `skill()`. Whether a skill fires in a given turn is a runtime property, not an inventory property.

## Four model slots, and no default placeholder ever reaches the picker

Model mapping is where the app has to be exact, and it is specific about that. A configuration can name a single model, or it can fill four slots separately, described as quality, balanced, fast and Fable, which is a mapping onto the tiers Science itself expects. The default slot is the one that must be filled; the other three may be left empty or given an exact upstream model ID, so a provider that offers two models does not get padded with invented ones. The claim that Science displays the real model name rather than a `default` placeholder is repeated in two places, and it pairs with a promise that unknown models never silently switch to another model. The document also notes that providers differ in support for tool calling, thinking, images, long context and streaming, and that CSSwitch maps strictly to the current configuration rather than adapting behind your back.

## Isolation means a separate HOME and a loopback gateway

The third-party mode is isolated at three levels rather than one. It runs with its own HOME, its own data directory and a local loopback gateway, and it does not read or modify the real Claude login or the real Science data. The API key is written to `~/.csswitch/config.json` with file permissions `0600`, and credentials are not written to logs. Switching back is the reverse operation with an explicit order: choose official Claude on the home page, and CSSwitch stops the third-party chain before opening the real Science, so the two never run at once. The application also refuses to manage the Claude install itself, preferring a runtime snapshot the machine's own official updater has already downloaded and that passes local identity verification, and otherwise using the installed official app. The Rust gateway ships inside the application, so there is no separate Python runtime to install, which matters on a platform where Python is often absent.

## The release evidence page separates five layers of proof

The most unusual thing in this repository is a document that grades its own claims. The v0.8.4 evidence page exists so a downloader can check the SHA-256 of the public attachment, and the boundary section states that source and unit checks, the final attachment, installation identity, signing and live provider or account behaviour are different evidence layers, so passing a source gate or a download page cannot be extrapolated into a claim that every real provider, SSH path or Science capability has been verified. Development runs the same discipline, with a gate script that writes into a private temporary directory created with restrictive permissions:

```bash
cd desktop
npm install
npm run tauri dev
```

and the full check invoked as `test/run_all.sh` with an output root under `/private/tmp`. Two operational limits are listed with equal bluntness: third-party mode carries no Anthropic account entitlement, so managed MCP, directory connectors and some cloud capabilities may be unavailable, and Codex remains off by default with single-account browser login only.

## Conclusion

CSSwitch is worth reading for its isolation design and its honesty about what is not finished, and the second of those is rare enough to say plainly. The third-party mode is separated from the real Claude install at the level of HOME, data directory and gateway, the key sits in a 0600 config file, and the Skill installer pins a commit without touching your GitHub credentials. Before relying on it, accept two limits it states itself. MCP does not exist in v0.8.4, in any user-facing form, and the internal connector used for Skill installation is not it. And third-party mode carries no Anthropic account entitlement, so anything that depends on your Claude subscription, including managed MCP and directory connectors, may be unavailable. On installation, expect to right-click through Gatekeeper, because the public build is ad-hoc signed rather than notarised.

## FAQ

### What platforms does CSSwitch support?

The official desktop build is macOS Apple Silicon only, shipped as the v0.8.4 aarch64 disk image. Linux x64 users are directed to a v0.8.1 prerelease that provides an amd64 `.deb`, so the Linux path is three patch versions behind the macOS release.

### Where does CSSwitch store my API key?

Locally, in `~/.csswitch/config.json`, with the file created at permission `0600`. The documentation states that credentials are not written to logs, and that third-party mode uses a separate HOME, data directory and local loopback gateway rather than touching the real Claude login or Science data.

### Can I manage MCP servers in CSSwitch?

Not in v0.8.4. The feature table marks MCP as coming soon, and the MCP section states that users cannot yet add, edit or manage their own MCP servers. The internal connector used to install Skills only installs, uninstalls and reports long-task status, and should not be treated as MCP support.

### What does third-party mode do to my existing Claude setup?

It runs alongside it without touching it: a separate HOME, a separate data directory and a local loopback gateway, with no reading or modification of the real Claude login or Science data. Switching back to official Claude stops the third-party chain first, then opens the real Science application.

## Sources

- [Issues](https://github.com/SuperJJ007/CSSwitch/issues)
- [License: MIT](https://github.com/SuperJJ007/CSSwitch/blob/main/LICENSE)
- [README](https://github.com/SuperJJ007/CSSwitch/blob/main/README.md)
- [Releases](https://github.com/SuperJJ007/CSSwitch/releases)
- [SuperJJ007/CSSwitch on GitHub](https://github.com/SuperJJ007/CSSwitch)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/superjj007-csswitch
