Electron Security

Security audit for Electron desktop applications including context isolation, nodeIntegration, sandbox config, preload scripts, IPC (ipcMain/ipcRenderer/contextBridge), webview tag risks, deep link handling, auto-updater security, and Electron CVE awareness. Use this skill whenever the user mentions Electron, electron-builder, contextBridge, nodeIntegration, preload.js, BrowserWindow webPreferences, ipcMain, ipcRenderer, electron-updater, or asks "audit my Electron app", "Electron security", "is my preload safe". Trigger when the codebase contains `electron` in package.json or `electron.js`/`main.ts` referenced as entry.

hlsitechio 870ab42 8.8 KB Updated

File contents

hlsitechio/claude-skills-security/tree/main/appsec-stack-pack/electron-security commit 870ab42dce

Frequently asked questions

npx skillmds@latest add hlsitechio/electron-security