skills/oakoss/agent-skills/tauri/Gen Agent Trust Hub

tauri

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides educational content and code examples for the Tauri v2 framework. All external resources, such as GitHub repositories and package registries, are official and associated with the Tauri project.
  • [CREDENTIALS_SAFE]: The documentation references environment variables for code signing (e.g., TAURI_SIGNING_PRIVATE_KEY, APPLE_CERTIFICATE) using descriptive placeholders. It provides correct guidance for managing secrets in CI/CD environments without exposing actual credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture that handles data across an IPC boundary (frontend to Rust).
  • Ingestion points: Commands and events received from the frontend webview (described in references/ipc-commands.md).
  • Boundary markers: The skill extensively documents Tauri's capability-based security model (references/security-model.md), which uses window labels and explicit permission sets to define boundaries.
  • Capability inventory: The skill includes documentation for file system access, shell execution, and network operations via official plugins (references/plugin-system.md).
  • Sanitization: Guidance is provided for configuring Content Security Policy (CSP) to restrict resource loading and script execution (references/security-model.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:51 AM
Security Audit — agent-trust-hub — tauri