skills/ericrisco/rsc-harness/electron/Gen Agent Trust Hub

electron

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive security guidance for the Electron framework, specifically instructing users to implement process isolation, context isolation, and OS-level sandboxing to mitigate RCE risks.
  • [SAFE]: The included utility script scripts/verify.sh is designed for local static analysis. It uses standard shell utilities like find and grep to identify insecure configuration patterns without requiring network access or elevated privileges.
  • [SAFE]: All recommended dependencies, such as @electron/forge, electron-builder, and zod, are reputable and industry-standard tools for Electron development and data validation.
  • [SAFE]: Secret management guidance is robust, explicitly advising users to utilize environment variables for sensitive build credentials like Apple ID passwords and signing certificates, avoiding any hardcoded secrets in the codebase.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:36 PM
Security Audit — agent-trust-hub — electron