Skip to content
Back to skills

Electron Development

ASecurity

Electron development guidelines for building cross-platform desktop applications with JavaScript/TypeScript

  • 248 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added February 10, 2026
developmentjavascripttypescriptjavanodetestingapisecurityperformance

Works with

  • api

Security analysis

A100/100

Scanned February 12, 2026

npx -y skills add Mindrally/skills --skill electron-development --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Electron Development?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Electron Development
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/mindrally-electron-development/badge)](https://www.skillsdirectory.com/skills/mindrally-electron-development)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: electron-development
description: Electron development guidelines for building cross-platform desktop applications with JavaScript/TypeScript
---

# Electron Development Guidelines

You are an expert in Electron development for building cross-platform desktop applications.

## Core Principles

- Follow security best practices for Electron apps
- Separate main and renderer process concerns
- Use IPC for process communication
- Implement proper window management

## Project Structure

```
src/
├── main/              # Main process code
│   ├── index.ts      # Entry point
│   ├── ipc/          # IPC handlers
│   └── utils/        # Utilities
├── renderer/          # Renderer process code
│   ├── components/   # UI components
│   ├── pages/        # Application pages
│   └── styles/       # Stylesheets
├── preload/          # Preload scripts
│   └── index.ts     # Expose APIs to renderer
└── shared/           # Shared types and utilities
```

## Security Best Practices

### Context Isolation
```javascript
// main.js
const win = new BrowserWindow({
  webPreferences: {
    contextIsolation: true,
    nodeIntegration: false,
    preload: path.join(__dirname, 'preload.js')
  }
});
```

### Preload Scripts
```javascript
// preload.js
const { contextBridge, ipcRenderer } = require('electron');

contextBridge.exposeInMainWorld('electronAPI', {
  sendMessage: (channel, data) => {
    const validChannels = ['toMain'];
    if (validChannels.includes(channel)) {
      ipcRenderer.send(channel, data);
    }
  },
  onMessage: (channel, callback) => {
    const validChannels = ['fromMain'];
    if (validChannels.includes(channel)) {
      ipcRenderer.on(channel, (event, ...args) => callback(...args));
    }
  }
});
```

### Content Security Policy
```html
<meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src 'self'">
```

## IPC Communication

### Main Process
```javascript
const { ipcMain } = require('electron');

ipcMain.handle('read-file', async (event, filePath) => {
  const content = await fs.promises.readFile(filePath, 'utf-8');
  return content;
});

ipcMain.on('save-file', (event, { path, content }) => {
  fs.writeFileSync(path, content);
  event.reply('file-saved', { success: true });
});
```

### Renderer Process
```javascript
// Using exposed API from preload
const content = await window.electronAPI.readFile('/path/to/file');
```

## Window Management

```javascript
const { BrowserWindow } = require('electron');

function createWindow() {
  const win = new BrowserWindow({
    width: 1200,
    height: 800,
    minWidth: 800,
    minHeight: 600,
    webPreferences: {
      contextIsolation: true,
      preload: path.join(__dirname, 'preload.js')
    }
  });

  // Handle window events
  win.on('closed', () => {
    // Cleanup
  });

  // Load content
  if (process.env.NODE_ENV === 'development') {
    win.loadURL('http://localhost:3000');
    win.webContents.openDevTools();
  } else {
    win.loadFile('dist/index.html');
  }
}
```

## Auto Updates

```javascript
const { autoUpdater } = require('electron-updater');

autoUpdater.on('update-available', () => {
  // Notify user
});

autoUpdater.on('update-downloaded', () => {
  autoUpdater.quitAndInstall();
});

app.whenReady().then(() => {
  autoUpdater.checkForUpdatesAndNotify();
});
```

## Native Modules

- Use electron-rebuild for native dependencies
- Consider node-addon-api for custom modules
- Test native modules on all platforms
- Handle architecture differences (x64, arm64)

## Performance

- Minimize main process blocking
- Use web workers for heavy computation
- Implement lazy loading
- Profile with DevTools

## Testing

- Use Spectron or Playwright for E2E tests
- Unit test main process logic
- Test IPC handlers
- Test on all target platforms

## Building and Distribution

- Use electron-builder for packaging
- Configure proper app signing
- Set up auto-update infrastructure
- Test installers on all platforms

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…