electron-wrapper

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes a utility script (scripts/download-bun.ts) to fetch platform-specific Bun binaries. These downloads are performed from GitHub's official release infrastructure, which is a well-known and trusted service.
  • [COMMAND_EXECUTION]: The skill utilizes Bun.spawn and Node.js child_process.spawn for legitimate administrative and lifecycle tasks, such as extracting downloaded binaries, setting executable permissions (chmod +x), and managing the bundled web server process.
  • [REMOTE_CODE_EXECUTION]: The core architecture of the skill involves spawning a Bun binary (downloaded from a trusted source) to execute the application's server logic. This is the intended primary purpose of the skill and is implemented using standard process management patterns.
  • [SAFE]: The implementation documentation explicitly enforces Electron security best practices, including enabling the sandbox, contextIsolation, and disabling nodeIntegration in the BrowserWindow configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 03:45 PM
Security Audit — agent-trust-hub — electron-wrapper