tauri

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/ipc-commands.md

No malicious behavior or supply-chain attack indicators are present. The fragment is legitimate IPC documentation. However, if the shown commands are used with untrusted frontend content, `fetch_data` may enable SSRF and `read_file` may enable arbitrary local file disclosure because neither input is restricted. These are application-level security risks requiring validation, allowlists, and appropriate Tauri capability controls.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Ftauri%2F@5255f91de54e05c2ec64981b5598fbe2b672f3da3e35691c5cac05a27ca0b11b
Security Audit — socket — tauri