electron-desktop-review

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of instructional content and reference documentation for performing security reviews of Electron applications. It defines a structured process for evaluating process boundaries, IPC handlers, storage security, and update mechanisms.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external data such as source code and repository configuration (SKILL.md). While this presents a surface for indirect prompt injection via malicious comments or code patterns in the analyzed files, the skill does not possess tools or instructions that would facilitate harmful actions. The risk is considered inherent to the function of code analysis and is mitigated by the agent's internal safety guardrails. Evidence chain: Ingestion points (analyzed repo files per SKILL.md), Boundary markers (absent), Capability inventory (analysis only, no write/exec capabilities found in reference docs or SKILL.md), Sanitization (absent).
  • [REMOTE_CODE_EXECUTION]: No patterns for remote code execution, package installation, or unauthorized script execution were found in the skill's instructions or references. The mention of itsol-current-tech-context is treated as a vendor-specific context reference.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:31 PM
Security Audit — agent-trust-hub — electron-desktop-review