ThreadBear supports macOS 12 or newer on Apple silicon and Intel, Codex Desktop 0.147.0 or newer, mounted app-native read_thread and set_thread_title, and the current task ID supplied to terminal commands. Install, self-test, and status reject an older or missing Desktop command before title work begins.
ThreadBear resolves Codex only from fixed Desktop locations: the system or user Applications bundle and the Desktop-managed ~/.local/bin/codex. It never executes codex from ambient repository PATH.
For an ordinary turn, the local title-script command binds the validated task ID and fixed title policy into the reviewed program embedded in the verified binary. One 219-byte loader evaluates the complete exit-zero output uncached inside the current Codex tool context. The program uses the mounted app to read the exact current task and, if needed, write once with no explicit target ID. Raw JSON-text results are decoded once; already-decoded objects are also accepted. A command failure, malformed program, wrong ID, unsafe title, throw, undecodable response, or non-exact setter result stays local with no alternate reader, writer, or retry. The public title command remains a data-only diagnostic for the same typed plan.
Ordinary title handling starts no App Server and writes no ThreadBear state, so it works under Codex's default workspace permissions. ThreadBear emits five exact status prefixes and recognizes the five inferred ✦ prefixes plus neutral 🐻 as removable decorations. Other safe leading emoji and subject bytes are preserved, while ambiguous old ThreadBear prefixes are deliberately left unchanged rather than guessed. Visible titles are at most 60 UTF-16 units and are never truncated.
After a successful install, Codex requests complete-catalog read permission once; refusal leaves every existing title unchanged. If allowed, the one-pass first read requires paginated thread/list, one-turn descending thread/turns/list, and ephemeral codex exec with a strict output schema. User config/rules and every hosted capability are disabled, request-input is disabled, shell/code-mode hosts are disabled, and the event trace rejects any tool attempt or extra assistant message. Missing or inaccessible history, model failure, malformed output, or interruption leaves affected tasks unchanged and does not change core installation health. The classifier is fixed to gpt-5.6-luna at medium reasoning and receives only bounded latest user/final text. It has no fallback or retry.
Uninstall cleanup explicitly asks for command permission, then follows the complete unarchived App Server thread/list catalog, tolerates notifications, and deduplicates IDs. Null or blank name stays raw regardless of preview. A later-page failure returns no partial plan. Confirmed preparation stores no titles and writes no titles. The installed skill serially rereads each prepared target through the mounted app immediately before its one possible explicit-target setter call; drift, wrong IDs, or non-exact setter results block artifact teardown and receive no retry.
ThreadBear never opens Codex SQLite or edits Desktop storage. It runs no App Server daemon or proxy, keeps no task-title database, executable-source cache, or App Server cache, and has no controller, queue, reconciliation, or alternate title path. Model classification is limited to ambiguous rows in the one ephemeral post-install first read; the ordinary title policy is fixed binary-embedded code rather than model-generated policy.
The supported public commands are install, title, status, self-test, update, uninstall, and version. The daily update-only LaunchAgent needs no sudo, Full Disk Access, model call, or persistent Codex task. Release binaries are checksum-verified but are not Developer ID signed or notarized.