tauri-v2
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [SAFE]: The skill serves as a technical guide for Tauri v2 development, providing correct code patterns for Rust commands, IPC, and security configuration. It actively encourages security best practices, such as the Principle of Least Privilege and mandatory code signing for production updates.
- [INDIRECT_PROMPT_INJECTION]: The skill documents architectural patterns for ingesting data from a web frontend to a Rust backend, which represents an indirect injection attack surface.
- Ingestion points: Rust commands in
src-tauri/src/lib.rsand IPC listeners described inreferences/ipc-patterns.mdreceive input from the frontend webview. - Boundary markers: The instructions mandate the use of
serdefor typed deserialization and the Tauri v2 capability model to restrict API access. - Capability inventory: Documents the use of file system access, shell execution, and network requests via official plugins.
- Sanitization: Recommends using Tauri's path APIs and directory-specific scopes in capability files to sanitize and restrict access.
- [DYNAMIC_EXECUTION]: The skill describes the integration of plugins that enable the execution of external binaries and runtime application updates.
- Evidence:
references/plugin-reference.mdandreferences/advanced-runtime-reference.mddetail theshell:allow-executepermission for sidecars.references/updater-distribution-reference.mddocuments thetauri-plugin-updaterfor installing signed binaries. - Context: These capabilities are presented as core framework features, with documentation highlighting the necessity of strict permission scoping and secure signing keys.
Audit Metadata