Agent skill

Electron Secure Boundary

by muratgur in muratgur/ordinus

Maintain Ordinus Electron security boundaries. An agent skill from muratgur/ordinus.

MITAuto-check passedFrontend & Design

Install Electron Secure Boundary

skills CLI
$ npx skills add muratgur/ordinus --skill electron-secure-boundary -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install muratgur/ordinus electron-secure-boundary --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/muratgur/ordinus.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/electron-secure-boundary .claude/skills/electron-secure-boundary && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
electron-secure-boundary
GitHub stars
113
Token cost
~523 tokens
SKILL.md length
237 words
Files
2
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Maintain Ordinus Electron security boundaries. An agent skill from muratgur/ordinus.

  • Works in 6 steps: Identify which side of the boundary the… → Move privileged behavior to main process… → Add the narrowest preload method needed… → …
  • Changing BrowserWindow options
  • SKILL.md covers Objective, Rules, Workflow and Red Flags
  • Calls npm

What it does

Electron Secure Boundary is an agent skill from muratgur/ordinus. Maintain Ordinus Electron security boundaries. Use when changing BrowserWindow options, main/preload/renderer responsibilities, privileged OS access, filesystem/database/process usage, or anything that could expose Electron or Node capabilities to renderer code.

Its SKILL.md is about 520 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Frontend & Design. It works with SQLite and npm. The repository describes itself as: Your local-first command center for working with AI agents like a real team. The licence is MIT.

When your agent uses it

  • Changing BrowserWindow options
  • Main/preload/renderer responsibilities
  • Privileged OS access
  • Filesystem/database/process usage

Example prompts

  • “/electron-secure-boundary”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Identify which side of the boundary the change touches: main, preload, renderer, or shared contracts.
  2. Move privileged behavior to main process services or IPC handlers.
  3. Add the narrowest preload method needed for renderer.
  4. Keep validation and trust decisions in main/shared, not renderer.
  5. Run npm run typecheck, npm run lint, and npm run build.
  6. For boundary changes, smoke test npm run dev or the packaged app.

What it can do on your machine

Read from SKILL.md and the folder at commit c27f289. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Electron Secure Boundary loads about 523 tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 237 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~523

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from muratgur/ordinus at commit c27f289, republished under its MIT licence (© muratgur). 237 words, ~523 tokens.

Download SKILL.mdSave it as .claude/skills/electron-secure-boundary/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
electron-secure-boundary
description
Maintain Ordinus Electron security boundaries. Use when changing BrowserWindow options, main/preload/renderer responsibilities, privileged OS access, filesystem/database/process usage, or anything that could expose Electron or Node capabilities to renderer code.

Electron Secure Boundary

Objective

Keep Ordinus secure by preserving the separation between privileged desktop code and UI code.

Rules

  • Keep privileged work in Electron main process: filesystem, SQLite, child processes, provider runtimes, secrets, native dialogs, and OS integration.
  • Keep renderer as UI-only React code. Do not import or use Node APIs, Electron APIs, SQLite clients, filesystem modules, or child process modules in renderer.
  • Keep preload small and typed. Expose only purpose-built window.ordinus.* methods.
  • Never expose raw ipcRenderer, electron, filesystem, process, database, or generic command execution APIs to renderer.
  • Preserve nodeIntegration: false, contextIsolation: true, and sandbox: true unless the user explicitly asks for a security model redesign.
  • Avoid third-party runtime imports in preload. In sandboxed preload, prefer type-only imports plus ipcRenderer.invoke.

Workflow

  1. Identify which side of the boundary the change touches: main, preload, renderer, or shared contracts.
  2. Move privileged behavior to main process services or IPC handlers.
  3. Add the narrowest preload method needed for renderer.
  4. Keep validation and trust decisions in main/shared, not renderer.
  5. Run npm run typecheck, npm run lint, and npm run build.
  6. For boundary changes, smoke test npm run dev or the packaged app.

Red Flags

  • Renderer imports from electron, node:*, fs, path, child_process, better-sqlite3, or main-process modules.
  • Preload exposes general-purpose methods such as invoke(channel, payload) or runCommand(command).
  • IPC handlers trust renderer payloads without validation.
  • A UI feature requires relaxing sandbox settings before simpler IPC design has been tried.

© muratgur, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/electron-secure-boundary of muratgur/ordinus.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit c27f289

Compare with similar skills

Electron Secure Boundary next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Electron Secure Boundary compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Electron Secure Boundary this skillmuratgur/ordinus113—~523Automated safety check: PassMIT
Antigravity ManagerDraculabo/AntigravityManager2.4k—~793Automated safety check: PassCustom licence
Bunbrianlovin/agent-config3771 repos~484Automated safety check: NotesNone
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
GSAP for Reactgreensock/gsap-skills16k4 repos~1.6kAutomated safety check: PassMIT
Create Docsvictorgarciaesgi/nuxt-typed-router4132 repos~2.8kAutomated safety check: PassMIT

Similar skills

  • Antigravity Manager

    Draculabo/AntigravityManager

    Comprehensive guide to Antigravity Manager architecture, workflows, and development.

    2.4k GitHub stars~793 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Bun

    brianlovin/agent-config

    Use Bun instead of Node.js, npm, pnpm, or vite. An agent skill from brianlovin/agent-config.

    377 GitHub starsUsed in 1 repo~484 tokens
    Frontend & DesignAuto-check: notes
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • GSAP for React

    greensock/gsap-skills

    Shows how to run GSAP animations in React and Next.js with the useGSAP hook, refs, scoped selectors and automatic cleanup on unmount.

    16k GitHub starsUsed in 4 repos~1.6k tokens
    Frontend & DesignAuto-check passed
  • Create Docs

    victorgarciaesgi/nuxt-typed-router

    Create complete documentation sites for projects. An agent skill from victorgarciaesgi/nuxt-typed-router.

    413 GitHub starsUsed in 2 repos~2.8k tokens
    Frontend & DesignAuto-check passed
  • Sap Extension Creator

    heshengtao/super-agent-party

    Create Super Agent Party (SAP) extensions. An agent skill from heshengtao/super-agent-party.

    2.7k GitHub stars~6k tokensUpdated 1 mo ago
    Frontend & DesignAuto-check passed

More from muratgur/ordinus

  • Shadcn Project Workflow

    muratgur/ordinus

    Work with shadcn/ui in Ordinus. An agent skill from muratgur/ordinus.

    113 GitHub stars~859 tokensUpdated 1 mo ago
    Auto-check passed
  • Ipc Contract Design

    muratgur/ordinus

    Design and maintain Ordinus typed IPC contracts. An agent skill from muratgur/ordinus.

    113 GitHub stars~509 tokensUpdated 1 mo ago
    Auto-check passed
  • Ordinus UI System

    muratgur/ordinus

    Build Ordinus renderer UI in the intended product style. An agent skill from muratgur/ordinus.

    113 GitHub stars~881 tokensUpdated 1 mo ago
    Auto-check passed
  • Provider Runtime Adapter

    muratgur/ordinus

    Design Ordinus provider runtime adapters for local AI CLIs. An agent skill from muratgur/ordinus.

    113 GitHub stars~587 tokensUpdated 1 mo ago
    Auto-check passed
  • Extend Ordinus SQLite persistence conservatively. An agent skill from muratgur/ordinus.

    113 GitHub stars~480 tokensUpdated 1 mo ago
    Auto-check passed
  • Idea Discovery

    muratgur/ordinus

    Explore a new feature, product idea, technical design, workflow change, or ADR candidate before committing to an implementation plan.

    113 GitHub stars~851 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Electron Secure Boundary

What does Electron Secure Boundary do?

Maintain Ordinus Electron security boundaries. An agent skill from muratgur/ordinus. Electron Secure Boundary is an agent skill from muratgur/ordinus. Maintain Ordinus Electron security boundaries.

When should I use Electron Secure Boundary?

Electron Secure Boundary fits situations like: changing BrowserWindow options; main/preload/renderer responsibilities; privileged OS access; filesystem/database/process usage.

How do I install Electron Secure Boundary in Claude Code?

Run `npx skills add muratgur/ordinus --skill electron-secure-boundary -a claude-code`. Or copy the skill folder (.codex/skills/electron-secure-boundary in muratgur/ordinus) into .claude/skills/electron-secure-boundary in your project. Claude Code loads it when a task matches its description.

How do I install Electron Secure Boundary in Codex?

Run `npx skills add muratgur/ordinus --skill electron-secure-boundary -a codex`. Or copy the skill folder (.codex/skills/electron-secure-boundary in muratgur/ordinus) into .agents/skills/electron-secure-boundary in your project. Codex loads it when a task matches its description.

Can I use Electron Secure Boundary in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add muratgur/ordinus --skill electron-secure-boundary -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/electron-secure-boundary, .gemini/skills/electron-secure-boundary, .github/skills/electron-secure-boundary and .opencode/skills/electron-secure-boundary in your project.

What does Electron Secure Boundary need to run?

Going by SKILL.md and its folder, Electron Secure Boundary needs the command-line tools its instructions call (npm).

Does Electron Secure Boundary access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Electron Secure Boundary safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Electron Secure Boundary use?

Electron Secure Boundary is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Electron Secure Boundary use?

About 523 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Electron Secure Boundary?

Skills that share tags, products or a category with Electron Secure Boundary: Antigravity Manager (Draculabo/AntigravityManager, 2.4k stars), Bun (brianlovin/agent-config, 377 stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars) and GSAP for React (greensock/gsap-skills, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Electron Secure Boundary?

muratgur (a GitHub user) maintains it in muratgur/ordinus, which has 113 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on September 3, 2026.

Source: muratgur/ordinus on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.