tauri-v2

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [SAFE]: The skill serves as a technical guide for Tauri v2 development, providing correct code patterns for Rust commands, IPC, and security configuration. It actively encourages security best practices, such as the Principle of Least Privilege and mandatory code signing for production updates.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents architectural patterns for ingesting data from a web frontend to a Rust backend, which represents an indirect injection attack surface.
  • Ingestion points: Rust commands in src-tauri/src/lib.rs and IPC listeners described in references/ipc-patterns.md receive input from the frontend webview.
  • Boundary markers: The instructions mandate the use of serde for typed deserialization and the Tauri v2 capability model to restrict API access.
  • Capability inventory: Documents the use of file system access, shell execution, and network requests via official plugins.
  • Sanitization: Recommends using Tauri's path APIs and directory-specific scopes in capability files to sanitize and restrict access.
  • [DYNAMIC_EXECUTION]: The skill describes the integration of plugins that enable the execution of external binaries and runtime application updates.
  • Evidence: references/plugin-reference.md and references/advanced-runtime-reference.md detail the shell:allow-execute permission for sidecars. references/updater-distribution-reference.md documents the tauri-plugin-updater for installing signed binaries.
  • Context: These capabilities are presented as core framework features, with documentation highlighting the necessity of strict permission scoping and secure signing keys.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:37 PM
Security Audit — agent-trust-hub — tauri-v2