Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

security: the renderer can start a shell and edit instructions without a native confirmation

Open
#157 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
48/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
electron, typescript
Domain
desktop, security

Research direction

Start by reading src/main/index.ts:350-356 for terminal IPC and index.ts:279 for instruction edits, then inspect settings_confirm.ts to understand how autoConfirmed is persisted. The issue proposes native confirmation or a main-process-visible user gesture for terminal startup, confirmation for instruction edits, and a fresh prompt whenever Auto mode is enabled. Done means all three paths require the described native user confirmation; runtime IPC validation is tracked separately in #32.

Written by the indexing model from the issue text.

Description

enhancement priority: low security severity: low

Found in the 2026-10-07 security audit. No XSS path was found, so this is defense in depth.

Problem

The renderer is effectively fully trusted:

  • terminal:start/terminal:write give any renderer script a real, unsandboxed shell (src/main/index.ts:350-356).
  • project:set-instructions writes text into the system prompt without native confirmation (index.ts:279).
  • settings_confirm.ts remembers autoConfirmed, so the renderer can turn Auto mode back on later in the same session without a new dialog.

Runtime IPC argument validation is tracked in #32.

Fix

  • Start the terminal only after a user gesture the main process can see (for example a native menu item or an accelerator), or confirm the first terminal:start of each project natively.
  • Confirm instruction edits, or show them in a native dialog.
  • Ask again whenever Auto mode is turned on.
Dominant language
TypeScript
Stars
2
Forks
2
Avg merge
5h 28m
Merged PRs (30d)
24

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from PierrunoYT/patch

All issues in PierrunoYT/patch

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.