electron-builder

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill documents the implementation of build hooks (such as beforePack, afterSign, and afterAllArtifactBuild) and custom NSIS scripts (.nsh). These features enable the dynamic loading and execution of Javascript, Typescript, or shell scripts during the software packaging process.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing project configuration files and source code for packaging. It possesses capabilities for network operations (publishing to GitHub, S3, etc.) and file system access.
  • Ingestion points: Configuration files including electron-builder.yml, package.json, and project source directories as defined in SKILL.md and references/configuration.md.
  • Boundary markers: No specific delimiters are documented for configuration file parsing.
  • Capability inventory: The skill facilitates network requests for artifact publication (referencing references/publishing.md), executes shell commands via the CLI, and performs file write operations to the output directory.
  • Sanitization: Sanitization protocols for external configuration data are not explicitly defined, which is typical for developer tools operating on local project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — electron-builder