electron-app-dev
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a Python utility script (scripts/create_electron_app.py) intended for project scaffolding. Execution of this script results in extensive file system modifications, including the creation of directory structures and the writing of various source and configuration files.
- [INDIRECT_PROMPT_INJECTION]: The scripts/create_electron_app.py file exposes a vulnerability surface through its handling of user-supplied arguments. (1) Ingestion points: The project_name CLI argument in scripts/create_electron_app.py. (2) Boundary markers: None. (3) Capability inventory: The script creates directories and writes files (Path.mkdir, Path.write_text) to the disk. (4) Sanitization: The script fails to validate the project name, which could allow path traversal sequences (e.g., ../) to escape the intended directory and overwrite or create files in other locations on the host system.
- [EXTERNAL_DOWNLOADS]: The tool generates a package.json file that includes dependencies on multiple external packages from the NPM registry, including electron, vite, and react-related libraries.
Audit Metadata