electron
Installation
SKILL.md
Electron — desktop shell, typed IPC, hardening, signing
This skill owns the desktop shell: process model, IPC, security, packaging, signing,
auto-update. It does not own the web UI inside the window (../react/SKILL.md), the
Node backend logic, or the CI runner matrix.
The mental model — three processes, one rule
An Electron app is three kinds of process. Code lives in exactly one; putting it in the wrong one is the root cause of most security holes.
| Process | Runtime | Trust | One per | Does |
|---|---|---|---|---|
| main | Node.js, full OS API | trusted | app | windows, menus, tray, dialogs, fs, child procs |
| renderer | Chromium, no Node | untrusted | window | your web UI; can run attacker JS if you load remote content |
| preload | isolated world, runs before page JS | semi-trusted | window | the only bridge: contextBridge exposes a tiny API |