electron-dev
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides high-quality security guidance for Electron applications, explicitly mandating critical security settings such as
contextIsolation: true,sandbox: true, andnodeIntegration: false. - [SAFE]: IPC (Inter-Process Communication) patterns described in the documentation emphasize security boundaries, including channel whitelisting and strict argument validation in the main process to prevent renderer-to-main exploits.
- [SAFE]: The documentation includes a 'Common Pitfalls' section that correctly identifies and warns against dangerous practices like exposing the
requirefunction to the renderer or failing to validate file paths in IPC handlers. - [SAFE]: Recommended configurations for build tools like Electron Vite and Electron Builder follow standard patterns for handling native modules and resource management without introducing external risks.
Audit Metadata