Agent Skills
› muratgur/ordinus
› electron-secure-boundary
electron-secure-boundary
GitHub维护 Electron 应用安全边界,确保主进程与渲染进程职责分离。适用于修改窗口配置、特权访问或涉及 Node/Electron API 暴露的场景,防止渲染器代码越权。
触发场景
修改 BrowserWindow 选项
调整 main/preload/renderer 职责
涉及特权 OS 访问或文件系统操作
可能将 Electron 或 Node 能力暴露给渲染器的变更
安装
npx skills add muratgur/ordinus --skill electron-secure-boundary -g -y
SKILL.md
Frontmatter
{
"name": "electron-secure-boundary",
"description": "Maintain Ordinus Electron security boundaries. Use when changing BrowserWindow options, main\/preload\/renderer responsibilities, privileged OS access, filesystem\/database\/process usage, or anything that could expose Electron or Node capabilities to renderer code."
}
Electron Secure Boundary
Objective
Keep Ordinus secure by preserving the separation between privileged desktop code and UI code.
Rules
- Keep privileged work in Electron main process: filesystem, SQLite, child processes, provider runtimes, secrets, native dialogs, and OS integration.
- Keep renderer as UI-only React code. Do not import or use Node APIs, Electron APIs, SQLite clients, filesystem modules, or child process modules in renderer.
- Keep preload small and typed. Expose only purpose-built
window.ordinus.*methods. - Never expose raw
ipcRenderer,electron, filesystem, process, database, or generic command execution APIs to renderer. - Preserve
nodeIntegration: false,contextIsolation: true, andsandbox: trueunless the user explicitly asks for a security model redesign. - Avoid third-party runtime imports in preload. In sandboxed preload, prefer type-only imports plus
ipcRenderer.invoke.
Workflow
- Identify which side of the boundary the change touches: main, preload, renderer, or shared contracts.
- Move privileged behavior to main process services or IPC handlers.
- Add the narrowest preload method needed for renderer.
- Keep validation and trust decisions in main/shared, not renderer.
- Run
npm run typecheck,npm run lint, andnpm run build. - For boundary changes, smoke test
npm run devor the packaged app.
Red Flags
- Renderer imports from
electron,node:*,fs,path,child_process,better-sqlite3, or main-process modules. - Preload exposes general-purpose methods such as
invoke(channel, payload)orrunCommand(command). - IPC handlers trust renderer payloads without validation.
- A UI feature requires relaxing sandbox settings before simpler IPC design has been tried.
版本历史
- f507122 当前 2026-07-05 18:19


