skills/hairyf/skills/tauri/Gen Agent Trust Hub

tauri

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents an architecture for building applications that ingest untrusted data from multiple sources including frontend IPC messages, deep-link URLs, and CLI arguments (references/core-ipc.md, references/features-deep-linking.md).
  • Ingestion points: Untrusted data enters the agent context via WebView message passing (IPC), custom URL schemes, and command-line arguments.
  • Boundary markers: The framework provides strict boundary markers through its Runtime Authority and Capabilities model, which resides in the Core process (references/security-runtime-authority.md, references/security-capabilities.md).
  • Capability inventory: The skill documents powerful capabilities including file system access (tauri-plugin-fs), shell execution (tauri-plugin-shell), and sidecar binaries (references/develop-sidecar.md).
  • Sanitization: The documentation explicitly mandates that developers 'validate and sanitize all inputs in Rust commands' and 'treat the frontend as untrusted' (references/best-practices-security-lifecycle.md).
  • [EXTERNAL_DOWNLOADS]: The skill contains instructions for downloading development prerequisites from well-known and official services. Evidence: Fetching the Rust toolchain from rustup.rs (references/start-prerequisites.md) and Edge WebDriver components from microsoft.com (references/develop-tests-webdriver.md). These are legitimate setup requirements from recognized vendors.
  • [COMMAND_EXECUTION]: The skill documents standard CLI operations for project management and build cycles. Evidence: Use of cargo, npm/pnpm, and the tauri CLI for tasks like project initialization, compilation, and bundling (references/reference-cli.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:56 PM