electron-builder
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous examples of shell commands for building and publishing applications using the electron-builder CLI.
- [DYNAMIC_EXECUTION]: The documentation describes the use of build hooks (e.g., beforePack, afterSign, afterAllArtifactBuild), which allow for the execution of arbitrary JavaScript or TypeScript scripts during the packaging and distribution process. This is a standard feature of the tool but constitutes a dynamic execution surface.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface where an agent might process untrusted user requirements to generate build configurations and execution commands.
- Ingestion points: User prompts requesting specific build targets, release workflows, or configuration overrides (e.g., artifact naming templates).
- Boundary markers: No specific delimiters or warnings for the agent to ignore instructions embedded in user-provided metadata or file paths are mentioned in the guide.
- Capability inventory: The skill involves file writing (configuration files and hook scripts), shell command execution (CLI build calls), and network operations (publishing artifacts to remote providers).
- Sanitization: The instructions do not explicitly provide methods for sanitizing user inputs before they are interpolated into build scripts or configuration files.
Audit Metadata