electron-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides code examples for implementing file system access via Electron's Inter-Process Communication (IPC). These examples represent an attack surface where instructions or malicious paths from a renderer process could influence the main process.
  • Ingestion points: The ipcMain.handle functions for read-file and write-file in references/EXAMPLES.md receive filePath and content directly from the renderer process.
  • Boundary markers: The example code does not include path validation, allow-listing, or explicit warnings to ignore malicious input within the handler logic.
  • Capability inventory: The main process scripts in references/EXAMPLES.md utilize fs.readFile and fs.writeFile to interact with the host file system based on input from the IPC bridge.
  • Sanitization: Sanitization and path validation are absent in the provided code snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — electron-expert