Install
$ agentstack add skill-galaxyruler-galactic-skills-tauri-engineering ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README — it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Tauri Engineering
Strict operational guidelines for building, securing, and shipping Tauri v2 applications. For Rust-side patterns (ownership, error handling, async, testing), see [rust-engineering](../rust-engineering/SKILL.md).
Architecture
- Guest-host model: multi-process — TAO for window management, WRY for rendering via OS-native Webview (not bundled Chromium).
- No SSR: configure frameworks for SPA or SSG mode. SvelteKit →
@sveltejs/adapter-static. - Vite:
strictPort: true, mobile HMR viaTAURI_DEV_HOST, build targetschrome105(Windows) /safari13(macOS/iOS).
IPC & commands
- Custom Protocol (JSON-RPC styled) replaces JSON string injection in v2.
- Raw byte streaming via
tauri::ipc::Responsefor large payloads — bypasses JSON serialization. - Async commands can't accept
&strorState— use owned types (String) or wrap inResult. - Commands in
lib.rsmust not bepub; register withtauri::generate_handler!.
State management
- Register with
app.manage()during setup. - Shared mutable state →
std::sync::MutexorRwLock. - Async: use
std::sync::Mutexunless guard held across.await→ thentokio::sync::Mutex.
Security
- ACL: define Permissions (commands + scopes) and Capabilities (map to windows/webviews). Identifiers: lowercase ASCII, max 116 chars.
- Isolation Pattern: required for high security — sandboxed ``, AES-GCM encrypted IPC payloads.
- CSP: always enforce. Tauri calculates script hashes and appends nonces.
- Filesystem:
tauri-plugin-fsenforces Base Directory containment. Block../traversal. - Shell: pre-configure allowed processes, args, and paths in capabilities.
Testing & performance
Testing checklist, binary optimization (lto, codegen-units, strip), cross-platform bundling (Linux/macOS/Windows), and CI/CD with tauri-apps/tauri-action: [TESTING-PERF.md](TESTING-PERF.md).
Auto-updates & anti-patterns
Updater signature enforcement, key management, server response contracts, platform-specific deployment, and critical anti-patterns to avoid: [UPDATES-DEPLOY.md](UPDATES-DEPLOY.md).
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: GalaxyRuler
- Source: GalaxyRuler/Galactic-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.