AgentStack
SKILL verified MIT Self-run

Tauri Engineering

skill-galaxyruler-galactic-skills-tauri-engineering · by GalaxyRuler

Production-grade Tauri v2 engineering guidelines — guest-host architecture, IPC commands, state management, ACL security, plugins, testing, performance optimization, auto-updates, and CI/CD. Use when building Tauri desktop or mobile apps, configuring tauri.conf.json, writing Tauri commands/plugins, setting up Tauri permissions/capabilities, debugging Webview issues, optimizing Tauri binary size,…

No reviews yet
0 installs
11 views
0.0% view→install

Install

$ agentstack add skill-galaxyruler-galactic-skills-tauri-engineering

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README — it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-galaxyruler-galactic-skills-tauri-engineering)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
17d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Tauri Engineering? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Tauri Engineering

Strict operational guidelines for building, securing, and shipping Tauri v2 applications. For Rust-side patterns (ownership, error handling, async, testing), see [rust-engineering](../rust-engineering/SKILL.md).

Architecture

  • Guest-host model: multi-process — TAO for window management, WRY for rendering via OS-native Webview (not bundled Chromium).
  • No SSR: configure frameworks for SPA or SSG mode. SvelteKit → @sveltejs/adapter-static.
  • Vite: strictPort: true, mobile HMR via TAURI_DEV_HOST, build targets chrome105 (Windows) / safari13 (macOS/iOS).

IPC & commands

  • Custom Protocol (JSON-RPC styled) replaces JSON string injection in v2.
  • Raw byte streaming via tauri::ipc::Response for large payloads — bypasses JSON serialization.
  • Async commands can't accept &str or State — use owned types (String) or wrap in Result.
  • Commands in lib.rs must not be pub; register with tauri::generate_handler!.

State management

  • Register with app.manage() during setup.
  • Shared mutable state → std::sync::Mutex or RwLock.
  • Async: use std::sync::Mutex unless guard held across .await → then tokio::sync::Mutex.

Security

  • ACL: define Permissions (commands + scopes) and Capabilities (map to windows/webviews). Identifiers: lowercase ASCII, max 116 chars.
  • Isolation Pattern: required for high security — sandboxed ``, AES-GCM encrypted IPC payloads.
  • CSP: always enforce. Tauri calculates script hashes and appends nonces.
  • Filesystem: tauri-plugin-fs enforces Base Directory containment. Block ../ traversal.
  • Shell: pre-configure allowed processes, args, and paths in capabilities.

Testing & performance

Testing checklist, binary optimization (lto, codegen-units, strip), cross-platform bundling (Linux/macOS/Windows), and CI/CD with tauri-apps/tauri-action: [TESTING-PERF.md](TESTING-PERF.md).

Auto-updates & anti-patterns

Updater signature enforcement, key management, server response contracts, platform-specific deployment, and critical anti-patterns to avoid: [UPDATES-DEPLOY.md](UPDATES-DEPLOY.md).

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.