🔛 attacker origin — loaded inside the Lifen trusted main window

This page is served from an attacker-controlled web origin designed to fail Lifen’s navigation guard, and it runs inside the desktop app’s main window with the preload IPC bridge attached.

1 · the origin this page actually runs on
...
2 · is the native IPC bridge exposed here?
...
3 · reading a medical document from the Lifen outbox
...
4 · lifting the read base beyond the outbox (watchPath pivot)
...
5 · deleting a pending outbox delivery on disk
...
6 · file-existence oracle (any local path)
...