electron-best-practices

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
references/ipc/electron-trpc.md

No clear supply-chain malware behavior or deliberate obfuscation is evident in the shown fragments. However, the main-process readFile procedure uses a renderer-controlled path directly in fs.promises.readFile with only type-level validation, and error messages/cause propagation embed user-controlled path information. If authorization, path allowlisting, and filesystem confinement are not enforced elsewhere, this design can enable high-impact unintended local file disclosure and information leakage via errors/logs.

Confidence: 62%Severity: 70%
Audit Metadata
Analyzed At
Sep 11, 2026, 08:25 AM
Package URL
pkg:socket/skills-sh/ninjasln-labs%2Fagent-skills%2Felectron-best-practices%2F@5dee52f65d54c61cfda8dfce954ff7c75e16b71ed7341259c755a8e12063e2b3
Security Audit — socket — electron-best-practices