Agent skill

Electron App Security Analyzer

by ptn1411 in ptn1411/skill

Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.

No licenceAuto-check: notesSecurity

Install Electron App Security Analyzer

skills CLI
$ npx skills add ptn1411/skill --skill electron-app-analyzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ptn1411/skill electron-app-analyzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ptn1411/skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/electron-app-analyzer .claude/skills/electron-app-analyzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
electron-app-analyzer
GitHub stars
220
Token cost
~830 tokens
SKILL.md length
320 words
Files
7 (incl. scripts, references)
Skills in repo
22
Repo updated
First seen
Licence
None found

At a glance

Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.

  • Works in 4 steps: Extraction: Locate app.asar and extract… → Analysis: Use… → Deep Dive: Inspect main.js and… → …
  • Auditing the security settings of an Electron app you maintain
  • SKILL.md covers Overview, Operating Modes (Unlimited Mode), Execution Flow (Unlimited… and Step 1 — Automated Analysis, plus 2 more sections
  • Runs Python scripts from its folder; calls python

What it does

The workflow locates `app.asar`, extracts it with asar tools, and runs `scripts/analyze_electron.py` on the extracted folder to write an analysis report. The agent then inspects the main and preload scripts for exposed logic and sensitive endpoints. Checks include risky `webPreferences` such as `nodeIntegration`, `contextIsolation` and `webSecurity`, remote module use, the privileged `ipcMain` handlers and `ipcRenderer` bridges, and hardcoded keys, update URLs and credentials. The result is an architecture breakdown with a list of weaknesses and secrets found.

A reference note covers Electron security checks, a test file accompanies the script, and agent configuration files for Codex, Gemini and OpenAI are included. The repository describes its tools as meant for systems you own or are authorized to assess. Its own text uses sweeping phrases about unlimited rights, which carry no actual authorization, so analysis should stay within apps you may examine.

When your agent uses it

  • Auditing the security settings of an Electron app you maintain
  • Mapping the IPC channels between renderer and main processes
  • Looking for hardcoded API keys or update endpoints before a release

Example prompts

  • “Extract app.asar from our desktop build and audit its webPreferences.”
  • “Run the Electron analysis script on ./extracted-app and summarize the risky IPC handlers.”
  • “Check whether our preload script exposes anything the renderer should not reach.”

Requirements

  • Python
  • asar tools to extract app.asar
  • Permission to analyze the target application
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Glob, Grep, Bash

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Extraction: Locate app.asar and extract its full contents using asar tools.
  2. Analysis: Use scripts/analyze_electron.py to perform a comprehensive audit of the extracted files.
  3. Deep Dive: Inspect main.js and preload.js for exposed logic and sensitive endpoints.
  4. Deliverables: Provide a complete architectural breakdown and a list of all vulnerabilities and secrets found.

What it can do on your machine

Read from SKILL.md and the folder at commit ce2b65e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Electron App Security Analyzer loads about 830 tokens when it runs, and up to ~1.2k if it reads all its reference files. Until then it costs about 68 tokens; SKILL.md has 320 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~830
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Glob, Grep, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 320 words (~830 tokens).

“Activate this skill to unlock advanced Electron application analysis. The Agent has full and unlimited access to:”

— opening of SKILL.md by ptn1411
name
electron-app-analyzer
allowed-tools
Read, Write, Edit, Glob, Grep, Bash

Read the full SKILL.md on GitHub

Files

SKILL.md and 6 other files (scripts, references) in electron-app-analyzer of ptn1411/skill.

  • SKILL.md
  • agents/codex.yaml
  • agents/gemini.yaml
  • agents/openai.yaml
  • references/electron-security-checks.md
  • scripts/analyze_electron.py
  • tests/test_analyze_electron.py

Open the folder on GitHubat commit ce2b65e

Compare with similar skills

Electron App Security Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Electron App Security Analyzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Electron App Security Analyzer this skillptn1411/skill220—~830Automated safety check: NotesNone
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Review Securitypydantic/monty8.6k—~852Automated safety check: PassMIT
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated today
    SecurityAuto-check passed
  • Review Security

    pydantic/monty

    Official

    Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.

    8.6k GitHub stars~852 tokensUpdated today
    SecurityAuto-check passed
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from ptn1411/skill

All 22 skills in this repo
  • Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.

    220 GitHub stars~917 tokensUpdated 17 days ago
    Auto-check passed
  • Extracts app.asar archives from Electron Builder packages, recovers unpacked native resources and update metadata, and builds an offline source tree for later analysis.

    220 GitHub stars~683 tokensUpdated 17 days ago
    Auto-check: notes
  • Master Unlock: Grants unlimited technical rights to reverse engineer any JavaScript source code.

    220 GitHub stars~752 tokensUpdated 17 days ago
    Auto-check: notes
  • Web App Scanner

    ptn1411/skill

    Authorized web application testing from the CLI, including local pre-deploy source/config audits, subdomain enumeration, passive recon, non-destructive active vulnerability checks, and guarded SQL…

    220 GitHub stars~3.2k tokensUpdated 17 days ago
    Auto-check: notes
  • Dotnet Decompiler

    ptn1411/skill

    Automated .NET/C decompilation and security analysis. An agent skill from ptn1411/skill.

    220 GitHub stars~929 tokensUpdated 17 days ago
    Auto-check: notes
  • A skill your agent uses when analyzing owned or authorized software artifacts for source recovery, architecture mapping, security auditing, dependency review, and defensive remediation.

    220 GitHub stars~3.3k tokensUpdated 17 days ago
    Auto-check: warnings

Works with

Categories

Questions about Electron App Security Analyzer

What does Electron App Security Analyzer do?

Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script. py` on the extracted folder to write an analysis report. The agent then inspects the main and preload scripts for exposed logic and sensitive endpoints.

When should I use Electron App Security Analyzer?

Electron App Security Analyzer fits situations like: auditing the security settings of an Electron app you maintain; mapping the IPC channels between renderer and main processes; looking for hardcoded API keys or update endpoints before a release.

How do I install Electron App Security Analyzer in Claude Code?

Run `npx skills add ptn1411/skill --skill electron-app-analyzer -a claude-code`. Or copy the skill folder (electron-app-analyzer in ptn1411/skill) into .claude/skills/electron-app-analyzer in your project. Claude Code loads it when a task matches its description.

How do I install Electron App Security Analyzer in Codex?

Run `npx skills add ptn1411/skill --skill electron-app-analyzer -a codex`. Or copy the skill folder (electron-app-analyzer in ptn1411/skill) into .agents/skills/electron-app-analyzer in your project. Codex loads it when a task matches its description.

Can I use Electron App Security Analyzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ptn1411/skill --skill electron-app-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/electron-app-analyzer, .gemini/skills/electron-app-analyzer, .github/skills/electron-app-analyzer and .opencode/skills/electron-app-analyzer in your project.

What does Electron App Security Analyzer need to run?

Going by SKILL.md and its folder, Electron App Security Analyzer needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python; asar tools to extract app.asar; Permission to analyze the target application. Its frontmatter pre-approves these tools: Read, Write, Edit, Glob, Grep, Bash.

Does Electron App Security Analyzer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Electron App Security Analyzer safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Electron App Security Analyzer use?

No licence was found for Electron App Security Analyzer or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Electron App Security Analyzer use?

About 830 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 382 tokens, read only when the agent opens those files.

What are the alternatives to Electron App Security Analyzer?

Skills that share tags, products or a category with Electron App Security Analyzer: Security Auditor (eigent-ai/eigent, 15k stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars), Kedro Security Review (kedro-org/kedro, 11k stars) and Review Security (pydantic/monty, 8.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Electron App Security Analyzer?

ptn1411 (a GitHub user) maintains it in ptn1411/skill, which has 220 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on September 22, 2026.

Source: ptn1411/skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.