PluginBench
Skill
Review
Audit score 70

baoyu-electron-extract

jimliu/baoyu-skills

Extract and decompile Electron apps: restore original sources from source maps or format minified code with Prettier.

What is baoyu-electron-extract?

Extracts resources and JavaScript from installed Electron apps by unpacking `.asar` bundles. Restores original source files from `.js.map` files when available, or formats minified code with Prettier otherwise. Use this when you need to inspect how a desktop Electron app is built or access its source code.

  • Unpacks `.asar` bundles from installed Electron applications on macOS and Windows
  • Restores original source files from embedded `.js.map` source maps with proper directory structure
  • Formats minified JavaScript with Prettier when source maps are unavailable
  • Resolves source-map paths relative to their location, collapsing bundler paths into readable project trees
  • Automatically skips `node_modules` and bundler runtime noise to focus on app code
  • Supports both app names (e.g., Codex) and absolute paths to `.app`, install directories, or `.asar` files

How to install baoyu-electron-extract

npx skills add https://github.com/jimliu/baoyu-skills --skill baoyu-electron-extract
Prerequisites
  • Bun or Node.js (npx) installed
  • The target Electron application must be installed on your system
  • Read access to the application's installation directory
Claude Code
Cursor
Windsurf
Cline

How to use baoyu-electron-extract

  1. 1.Provide the app name (e.g., 'Codex') or absolute path to the installed application
  2. 2.Optionally specify a custom output directory with `--output`; default is `~/Downloads/<AppName>-electron-extract/`
  3. 3.Run the extraction script; use `--dry-run` first to preview what will be discovered without writing files
  4. 4.Check the output: `restored/` contains reconstructed sources from source maps; `extracted/` contains formatted code when maps are unavailable
  5. 5.If multiple app matches are found, select the correct one and re-run with its absolute path

Use cases

Good for
  • Inspect the source code of popular Electron apps like VS Code, Discord, Slack, or Notion
  • Understand how a specific desktop application is structured and built
  • Debug or analyze minified code from an Electron app you have installed
  • Restore original TypeScript/JavaScript sources from a production Electron bundle
  • Compare different versions of an app by extracting and examining their source
Who it's for
  • Security researchers analyzing Electron applications
  • Developers learning how popular desktop apps are structured
  • Engineers debugging or reverse-engineering installed Electron software
  • Anyone curious about the internals of a desktop application

baoyu-electron-extract FAQ

What's the difference between 'restored' and 'extracted' directories?

'restored/' contains original source files reconstructed from `.js.map` source maps with proper directory structure. 'extracted/' contains the raw unpacked code from the `.asar` bundle, formatted with Prettier if no source maps were found. Check 'restored/' first if it exists.

Can I use this on apps I don't have installed?

No, the app must be installed on your system. The script discovers the installation path and accesses the bundled `.asar` file. If you know the exact path to a `.asar` file, you can pass it with `--asar /path/to/app.asar`.

What if the script finds multiple matches for an app name?

The script will list all candidates and ask you to choose. Provide the absolute path to the correct installation and re-run, or use `--asar` with the specific `.asar` file path.

Will this overwrite my existing output directory?

By default, the script refuses to write into a non-empty output directory. Use `--force` to overwrite, or specify a different output path with `--output`.

Does this work on Windows?

Yes, the skill supports both macOS and Windows. On Windows, provide paths like `C:\Users\you\AppData\Local\Programs\appname` or use app names for auto-discovery.

Full instructions (SKILL.md)

Source of truth, from jimliu/baoyu-skills.


name: baoyu-electron-extract description: Extracts resources and JavaScript from any installed Electron app (.asar bundle), restoring original sources from .js.map files when available or formatting minified code with Prettier otherwise. Use when user wants to "extract Electron app", "decompile Electron", "get the source code of <app>", "inspect app.asar", "看 Electron 应用源码", "提取 .asar", or asks how a desktop Electron app is built. Skips node_modules and supports both macOS and Windows. version: 1.119.0 metadata: openclaw: homepage: https://github.com/JimLiu/baoyu-skills#baoyu-electron-extract requires: anyBins: - bun - npx

Electron App Extract

Extracts resources and code from an installed Electron app's app.asar. When a .js.map is present, restores the original source files from the embedded sourcesContent; otherwise formats the minified code with Prettier. Source-map paths are resolved relative to the .js.map file first, so bundled paths like ../../src/main.ts restore to readable paths such as restored/src/main.ts instead of hashed placeholders. Always skips node_modules. Works on macOS and Windows.

User Input Tools

When this skill prompts the user, follow this tool-selection rule (priority order):

  1. Prefer built-in user-input tools exposed by the current agent runtime — e.g., AskUserQuestion, request_user_input, clarify, ask_user, or any equivalent.
  2. Fallback: if no such tool exists, emit a numbered plain-text message and ask the user to reply with the chosen number/answer for each question.
  3. Batching: if the tool supports multiple questions per call, combine all applicable questions into a single call; if only single-question, ask them one at a time in priority order.

Concrete AskUserQuestion references below are examples — substitute the local equivalent in other runtimes.

Script Directory

Scripts in scripts/ subdirectory. {baseDir} = this SKILL.md's directory path. Resolve ${BUN_X} runtime: if bun installed → bun; if npx available → npx -y bun; else suggest installing bun. Replace {baseDir} and ${BUN_X} with actual values.

ScriptPurpose
scripts/main.tsApp discovery + asar extraction + source-map restoration + Prettier formatting

When to use

Use this skill whenever the user wants to look inside an installed Electron application or inspect its bundled code. Trigger phrases include:

  • "extract Electron app", "decompile this Electron app", "unpack app.asar"
  • "show me the source of <app>", "look inside <app>", "how is <app> built"
  • "get the source code of Codex / Cursor / Discord / Slack / VS Code / Notion / Obsidian / ChatGPT desktop"
  • "提取 Electron 应用", "看 <app> 的源码", "反编译 Electron", "解包 app.asar", "还原 source map"

Both app name (e.g., Codex) and absolute path (e.g., /Applications/Codex.app, a .asar file, or a Windows install dir) are accepted. The script handles discovery for both platforms.

Workflow

1. Determine the input. Ask the user for the app name or path if they haven't given one. If they want a custom output directory, ask for that too.

2. Run the script.

${BUN_X} {baseDir}/scripts/main.ts "<app>" [--output <dir>] [--asar <path>] [--force]

Start with --dry-run first if you're unsure whether discovery will find the right bundle — it prints the resolved paths and exits without touching the filesystem.

3. Handle the result.

  • Success → report the output paths and the counts (extracted / restored / formatted).
  • Multiple matches → the script lists candidates and exits non-zero. Show the user the candidates, ask which one to use (via AskUserQuestion or the runtime equivalent), then re-run with the chosen absolute path.
  • Existing non-empty output dir → the script refuses without --force. Ask the user whether to overwrite (--force) or pick a new --output path.
  • Unsupported platform / no match → suggest passing --asar /full/path/to/app.asar if the user knows where the bundle lives.

4. Point the user at the result. The default output dir is ~/Downloads/<AppName>-electron-extract/. The most interesting subdirectory depends on what was found:

  • restored/ exists → the original source tree was reconstructed from .js.map files; this is what to read first.
  • Only extracted/ exists (no maps) → the JS/CSS in extracted/ was Prettier-formatted in place; read from there.

Source-map path restoration

The script should preserve original source names and directory structure as much as the source map allows:

  • Resolve each sources[] entry with sourceRoot when present, then relative to the .js.map file's directory inside extracted/.
  • Collapse normal bundler-relative paths into the restored project tree. For example, .vite/main/index.js.map + ../../src/main.ts becomes restored/src/main.ts.
  • If a source path climbs above extracted/, keep the readable remaining path under restored/ instead of hashing it. For example, .vite/main/index.js.map + ../../../shared/src/lib/foo.ts becomes restored/shared/src/lib/foo.ts.
  • Strip URL/query decorations from source names, including common webpack://, file://, and ?loader suffixes.
  • Use restored/__unknown/<hash>.<ext> only when the source name is empty or cannot be reduced to a safe file path.
  • Continue skipping node_modules and webpack/runtime/* entries; these are bundler/runtime noise, not app sources.

Usage

# Extract by app name (default output: ~/Downloads/Codex-electron-extract/)
${BUN_X} {baseDir}/scripts/main.ts Codex

# Extract by absolute path (works for .app bundles, install dirs, or .asar files)
${BUN_X} {baseDir}/scripts/main.ts "/Applications/Visual Studio Code.app"
${BUN_X} {baseDir}/scripts/main.ts "C:\Users\you\AppData\Local\Programs\codex"
${BUN_X} {baseDir}/scripts/main.ts --asar /Applications/Codex.app/Contents/Resources/app.asar Codex

# Custom output
${BUN_X} {baseDir}/scripts/main.ts Codex --output ~/work/codex-source

# Preview discovery without writing anything
${BUN_X} {baseDir}/scripts/main.ts Codex --dry-run

# Overwrite an existing output dir
${BUN_X} {baseDir}/scripts/main.ts Codex --force

# Machine-readable result (one JSON line on stdout)
${BUN_X} {baseDir}/scripts/main.ts Codex --json

Options

OptionShortDescriptionDefault
<app>App name or absolute path. Required unless --asar is given.
--output-oOutput directory~/Downloads/<AppName>-electron-extract
--asarOverride the resolved .asar pathauto-discovered
--force-fAllow writing into a non-empty existing output dirfalse
--skip-formatSkip Prettier formattingfalse
--skip-restoreSkip source-map restorationfalse
--no-unpackedDon't copy app.asar.unpacked/ alongsidefalse
--dry-runPrint resolved paths and exit without writingfalse
--jsonEmit one JSON-line summary on stdout (suppresses normal output)false

Output layout

~/Downloads/<AppName>-electron-extract/
├── extract-report.json          # JSON summary: counts, warnings, resolved paths
├── extracted/                   # raw asar contents (JS/CSS Prettier-formatted when no map)
│   └── ...                      # node_modules left untouched (skipped from format)
├── extracted.unpacked/          # copied from <asar>.unpacked/ if present
│   └── ...                      # native modules (.node), large assets
└── restored/                    # only present if at least one .js.map was usable
    └── <original/source/tree>   # rebuilt from sourcesContent in each .js.map

Notes

  • node_modules is always skipped — both for source-map restoration and Prettier formatting — because vendored dependencies are noise when inspecting an app.
  • Source-map restoration only works when the .js.map embeds sourcesContent. This is the common case for modern bundlers (webpack, esbuild, Vite, rollup). If a map references external .ts/.js files without embedding them, that map is skipped and the corresponding .js is Prettier-formatted instead. Skipped maps are listed in extract-report.json under warnings.
  • Readable paths over hashes — don't treat ../ segments in source-map paths as automatically unsafe. First resolve them from the map location and then sanitize the final output path so it still stays under restored/. Hash fallback is only for unusable source names.
  • App discovery searches /Applications + ~/Applications on macOS, and %LOCALAPPDATA%\Programs, %PROGRAMFILES%, %PROGRAMFILES(X86)%, %APPDATA% on Windows. If discovery finds multiple matches, the script exits and lists them — re-run with an absolute path. On Linux or other platforms, pass --asar /path/to/app.asar explicitly.
  • Safety — the script refuses to write to /, the user home directly, or the current working directory, and refuses to populate an existing non-empty output dir without --force.
  • No global installs@electron/asar and prettier are resolved on-the-fly via npx -y. First run will be slower while npx caches them.