electron-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides code examples for implementing file system access via Electron's Inter-Process Communication (IPC). These examples represent an attack surface where instructions or malicious paths from a renderer process could influence the main process.
- Ingestion points: The
ipcMain.handlefunctions forread-fileandwrite-fileinreferences/EXAMPLES.mdreceivefilePathandcontentdirectly from the renderer process. - Boundary markers: The example code does not include path validation, allow-listing, or explicit warnings to ignore malicious input within the handler logic.
- Capability inventory: The main process scripts in
references/EXAMPLES.mdutilizefs.readFileandfs.writeFileto interact with the host file system based on input from the IPC bridge. - Sanitization: Sanitization and path validation are absent in the provided code snippets.
Audit Metadata