desktop-tauri

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Security
SecurityMEDIUM
references/tauri-architecture.md

No explicit backdoor/malware behaviors (e.g., shell execution, credential harvesting, or direct covert exfiltration) are shown in the provided fragment. However, the module exposes two especially dangerous, attacker-influenced capabilities via IPC: (1) write_file performs an apparent unrestricted filesystem write to an attacker-supplied path, and (2) fetch_data performs an unrestricted server-side HTTP GET to an attacker-supplied URL (SSRF/data retrieval risk). read_user_file attempts traversal protection but its robustness is unclear without canonicalization/symlink-safe handling. Combined with weaker CSP hardening (unsafe-inline for styles), the security posture is high risk and should be reviewed for strict permission gating and strong input/path/network validation before use.

Confidence: 66%Severity: 78%
Audit Metadata
Analyzed At
Jul 8, 2026, 12:20 PM
Package URL
pkg:socket/skills-sh/j4flmao%2Fagent-skills%2Fdesktop-tauri%2F@9fc3e4550b4669c7a4b8ace6e7f399c8d7e4d749cf691babacf96fd0ce92177f
Security Audit — socket — desktop-tauri