Part 1 - Cobalt, accessed March 9, 2026,
cobalt.io/blog/common-miscon…
Electron Security - Best Practices, CSP, Sandboxing - Emad Ibrahim, accessed March 9, 2026,
emadibrahim.com/electron-gui…
Security | Electron, accessed March 9, 2026,
electronjs.org/docs/latest/t…
Context isolation is disabled in Electron (JS-S1020) ・ JavaScript - DeepSource, accessed March 9, 2026,
deepsource.com/directory/jav…
security-patterns | Skills Marketplace - LobeHub, accessed March 9, 2026,
lobehub.com/skills/andyngdz-…
electron-best-practices | Skills Mar... - LobeHub, accessed March 9, 2026,
lobehub.com/skills/jwynia-ag…
Process Sandboxing | Electron, accessed March 9, 2026,
electronjs.org/docs/latest/t…
awesome-cursor-rules-mdc/rules-mdc/electron.mdc at main - GitHub, accessed March 9, 2026,
github.com/sanjeed5/awesome-…
Electron 'contextBridge' - javascript - Stack Overflow, accessed March 9, 2026,
stackoverflow.com/questions/…
contextBridge - Electron, accessed March 9, 2026,
electronjs.org/docs/latest/a…
Untitled document,
drive.google.com/open?id=1Rj…
CVE-2023-32689 Detail - NVD - NIST, accessed March 9, 2026,
nvd.nist.gov/vuln/detail/CVE…
CVSS v3.1 Specification Document - Forum of Incident Response and Security Teams, accessed March 9, 2026,
first.org/cvss/v3.1/specific…
CVE-2024-3082 Detail - NVD, accessed March 9, 2026,
nvd.nist.gov/vuln/detail/CVE…
Move from keytar to Electron's safeStorage API. · Issue #1656 · CheckerNetwork/desktop, accessed March 9, 2026,
github.com/CheckerNetwork/de…
safeStorage | Electron, accessed March 9, 2026,
electronjs.org/docs/latest/a…
Replacing Keytar with Electron's safeStorage in Ray |
freek.dev, accessed March 9, 2026,
freek.dev/2103-replacing-key…
Cross Site Scripting Prevention - OWASP Cheat Sheet Series, accessed March 9, 2026,
cheatsheetseries.owasp.org/c…
React Server Components Face New Security Challenges: What Developers Need to Know, accessed March 9, 2026,
dataalgo.medium.com/react-se…
Critical Vulnerabilities in React and Next.js - Information Security Office, accessed March 9, 2026,
security.berkeley.edu/news/c…
React2Shell (CVE-2025-55182): Critical React Vulnerability | Wiz Blog, accessed March 9, 2026,
wiz.io/blog/critical-vulnera…
Critical Security Vulnerability in React Server Components, accessed March 9, 2026,
react.dev/blog/2025/12/03/cr…
Fixing the script: Journey to reduce XSS exposure - Microsoft, accessed March 9, 2026,
microsoft.com/en-us/msrc/blo…
Trusting AI Output? Why Improper Output Handling is the New XSS - Auth0, accessed March 9, 2026,
auth0.com/blog/owasp-llm05-i…
What Is Cross-Site Scripting (XSS)? - Palo Alto Networks, accessed March 9, 2026,
paloaltonetworks.com/cyberpe…
OWASP Top 10 for Large Language Model Applications, accessed March 9, 2026,
owasp.org/www-project-top-10…
OWASP Top 10 for Agentic Applications for 2026, accessed March 9, 2026,
genai.owasp.org/resource/owa…
AI Prompt Injection in Healthcare: Hidden Cybersecurity Risk - Clearwater, accessed March 9, 2026,
clearwatersecurity.com/blog/…
Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild, accessed March 9, 2026,
unit42.paloaltonetworks.com/…
Update Script Tools API to include WebMCP proposed methods [445637567] - Chromium, accessed March 9, 2026,
issues.chromium.org/issues/4…
WebMCP Early Preview,
drive.google.com/open?id=1rt…