electron-wrapper
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes a utility script (
scripts/download-bun.ts) to fetch platform-specific Bun binaries. These downloads are performed from GitHub's official release infrastructure, which is a well-known and trusted service. - [COMMAND_EXECUTION]: The skill utilizes
Bun.spawnand Node.jschild_process.spawnfor legitimate administrative and lifecycle tasks, such as extracting downloaded binaries, setting executable permissions (chmod +x), and managing the bundled web server process. - [REMOTE_CODE_EXECUTION]: The core architecture of the skill involves spawning a Bun binary (downloaded from a trusted source) to execute the application's server logic. This is the intended primary purpose of the skill and is implemented using standard process management patterns.
- [SAFE]: The implementation documentation explicitly enforces Electron security best practices, including enabling the
sandbox,contextIsolation, and disablingnodeIntegrationin theBrowserWindowconfiguration.
Audit Metadata