electron-builder
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill documents the implementation of build hooks (such as
beforePack,afterSign, andafterAllArtifactBuild) and custom NSIS scripts (.nsh). These features enable the dynamic loading and execution of Javascript, Typescript, or shell scripts during the software packaging process. - [INDIRECT_PROMPT_INJECTION]: The skill involves processing project configuration files and source code for packaging. It possesses capabilities for network operations (publishing to GitHub, S3, etc.) and file system access.
- Ingestion points: Configuration files including
electron-builder.yml,package.json, and project source directories as defined inSKILL.mdandreferences/configuration.md. - Boundary markers: No specific delimiters are documented for configuration file parsing.
- Capability inventory: The skill facilitates network requests for artifact publication (referencing
references/publishing.md), executes shell commands via the CLI, and performs file write operations to the output directory. - Sanitization: Sanitization protocols for external configuration data are not explicitly defined, which is typical for developer tools operating on local project files.
Audit Metadata