tauri

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
references/rust-backend.md

No evidence of intentional malware or supply-chain sabotage is present; this is readable instructional Tauri/Rust sample code. However, the unrestricted filesystem commands permit arbitrary file reads, writes, and directory enumeration within application privileges, and the caller-controlled HTTP request example can enable arbitrary outbound requests. These capabilities should be constrained with Tauri permissions, trusted command callers, application-directory allowlists, path canonicalization, URL allowlists, and production-specific configuration before use.

Confidence: 97%Severity: 72%
Audit Metadata
Analyzed At
Sep 18, 2026, 07:29 PM
Package URL
pkg:socket/skills-sh/stifleur390%2Ffullstack-dev-skills%2Ftauri%2F@fce733c30f776862ff30c78095b0df74a4e58baddd058879a5094b66c2267e31
Security Audit — socket — tauri