Agent skill

Tauri

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC, streaming to the frontend…

MITAuto-check passedFrontend & Design

Install Tauri

skills CLI
$ npx skills add ericrisco/rsc-harness --skill tauri -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness tauri --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tauri .claude/skills/tauri && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tauri
GitHub stars
156
Token cost
~2.6k tokens
SKILL.md length
1,040 words
Files
6 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC, streaming to the frontend…

  • Building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC
  • SKILL.md covers Pick your starting shape, Commands & IPC — the core…, Stream vs notify and Security — the part people skip, plus 2 more sections
  • Runs Shell scripts from its folder; calls npm and npx
  • Streaming to the frontend

What it does

Tauri is an agent skill from ericrisco/rsc-harness. Use when building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC, streaming to the frontend, the default-deny capabilities/permissions ACL, bundling and signed auto-updates. NOT a Chromium+Node shell needing Node APIs in a main process (that is electron).

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/bundling-distribution.md`).

It sits in Frontend & Design. It works with Tauri and Rust. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC
  • Streaming to the frontend
  • The default-deny capabilities/permissions ACL
  • Bundling and signed auto-updates

Example prompts

  • “/tauri”

Requirements

  • Node.js
  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tauri loads about 2.6k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 86 tokens; SKILL.md has 1,040 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,040 words, ~2,649 tokens.

Download SKILL.mdSave it as .claude/skills/tauri/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
tauri
description
Use when building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC, streaming to the frontend, the default-deny capabilities/permissions ACL, bundling and signed auto-updates. NOT a Chromium+Node shell needing Node APIs in a main process (that is electron).
tags
tauri, desktop, rust, cross-platform, ipc, webview
recommends
rust, electron, react, secure-coding, github-actions
origin
risco

Tauri — Rust core, OS WebView, locked-down IPC, tiny binaries

Tauri builds a desktop (and, since v2, mobile) app from a Rust core plus the operating system's own WebView — not a bundled browser. That is the whole value proposition: ~12MB installers and 30-50MB idle RAM, versus Electron's ~180MB installers and 150-300MB because it ships Chromium + Node. You write your UI in any web framework, expose privileged work as Rust commands, and the WebView talks to Rust over a sandboxed IPC bridge.

Always target v2. Tauri 2.0 went stable in October 2024; the current line is 2.x (2.11.x as of mid-2026). v1 docs use a tauri > allowlist config that no longer exists — if you see allowlist, you are reading the wrong era. v2 also adds iOS/Android targets, so the same Rust core can ship to mobile.

This skill owns the shell: commands, IPC, the security ACL, the bundler, the updater. It does not own the Rust language itself (that is the rust skill), the web UI inside the window (the react/nextjs skills), a Chromium+Node shell (../electron/SKILL.md), or app-code hardening beyond the IPC boundary (../secure-coding/SKILL.md).

Pick your starting shape

SituationDo this
Greenfield app, no UI yetnpm create tauri-app@latest — pick your frontend, get src-tauri/ wired
You already have a web app (Vite/Next/etc.)npx @tauri-apps/cli@latest init inside it; point build.frontendDist at your build output
Add mobile to an existing desktop apptauri ios init / tauri android init; gate native bits behind #[cfg(mobile)]
You see tauri.conf.json > tauri > allowlistYou are on v1 — migrate to v2 capabilities before adding anything

src-tauri/ is its own Cargo crate: Cargo.toml, tauri.conf.json, src/lib.rs (the run() entry point), and capabilities/. The frontend is a sibling directory the bundler reads from frontendDist.

Commands & IPC — the core contract

A command is a Rust function the frontend can call. Each rule below has a one-line why.

  • Annotate and register. #[tauri::command] on the fn, then list it in tauri::generate_handler![...] inside invoke_handler. Unregistered commands are not a compile error — they fail at runtime when JS calls them.
  • Naming crosses the bridge. JS invoke('read_config', { filePath }) maps to Rust read_config(file_path: String). Command names stay snake_case; args auto-map camelCase (JS) ⇄ snake_case (Rust).
  • Fallible commands return Result<T, E> where E: Serialize. An Err becomes a rejected JS promise; a panic instead crashes the command thread silently.
  • Never block the command thread. Long or I/O work goes in an async command or a spawned task. Commands run on a shared IPC thread pool — a blocking call freezes other IPC, which users see as a frozen UI.
  • Share state with .manage(x) + State<'_, T>. If a guard is held across an .await, use tokio::sync::Mutex, not std::sync::Mutex — the std guard is not Send and will not compile in an async command.
rust
// src-tauri/src/lib.rs
use tauri::State;
use tokio::sync::Mutex;

#[derive(Default)]
struct AppState { counter: u64 }

#[tauri::command]                                   // registered below or it 404s at runtime
async fn read_config(file_path: String) -> Result<String, String> {
    tokio::fs::read_to_string(&file_path)           // async I/O — does not block the IPC pool
        .await
        .map_err(|e| e.to_string())                 // Err -> rejected JS promise
}

#[tauri::command]
async fn bump(state: State<'_, Mutex<AppState>>) -> Result<u64, String> {
    let mut s = state.lock().await;                 // tokio Mutex: guard is held across .await
    s.counter += 1;
    Ok(s.counter)
}

#[cfg_attr(mobile, tauri::mobile_entry_point)]      // same core compiles for iOS/Android
pub fn run() {
    tauri::Builder::default()
        .manage(Mutex::new(AppState::default()))
        .invoke_handler(tauri::generate_handler![read_config, bump])
        .run(tauri::generate_context!())
        .expect("error while running tauri application");
}
javascript
// frontend
import { invoke } from '@tauri-apps/api/core';

const text = await invoke('read_config', { filePath: '/app/config.toml' });
// throws (rejected promise) if the command returns Err — wrap in try/catch

Bad → Good, the failure people hit most:

rust
// Bad: std Mutex held across .await — won't compile in an async command, or you
// "fix" it by dropping the guard early and create a race.
async fn save(state: State<'_, std::sync::Mutex<AppState>>) { /* ... */ }

// Good: async-aware lock.
async fn save(state: State<'_, tokio::sync::Mutex<AppState>>) -> Result<(), String> { Ok(()) }

Stream vs notify

Two ways to push from Rust to the frontend — pick by ordering needs:

  • Channel<T> for ordered streaming. Download progress, file chunks, an HTTP body. Messages arrive in send order on one typed channel — the right tool for "report progress as it happens."
  • emit / listen events for fire-and-forget pub/sub. App-wide notifications, "data refreshed," a tray action. No ordering or backpressure guarantees; many listeners, no reply.
rust
use tauri::ipc::Channel;

#[derive(Clone, serde::Serialize)]
struct Progress { downloaded: u64, total: u64 }

#[tauri::command]
async fn download(url: String, on_progress: Channel<Progress>) -> Result<(), String> {
    // ... as bytes arrive:
    on_progress.send(Progress { downloaded: 4096, total: 1_000_000 })
        .map_err(|e| e.to_string())?;
    Ok(())
}
javascript
import { Channel, invoke } from '@tauri-apps/api/core';

const onProgress = new Channel();
onProgress.onmessage = (p) => updateBar(p.downloaded / p.total);
await invoke('download', { url, onProgress });

Security — the part people skip

Tauri v2's IPC is an Access Control List, default-deny. The chain:

capabilities (group windows/webviews) → grant permissions (named command sets) → permissions map scopes (what data/paths a command may touch). A webview that matches no capability has zero IPC access. This is the opposite of v1's opt-out allowlist — you grant exactly what each window needs.

json
// src-tauri/capabilities/default.json — grant only what the main window uses
{
  "$schema": "../gen/schemas/desktop-schema.json",
  "identifier": "main-capability",
  "windows": ["main"],
  "permissions": [
    "core:default",
    {
      "identifier": "fs:allow-read-text-file",
      "allow": [{ "path": "$APPCONFIG/*" }]   // scope: app config dir only, nothing else
    }
  ]
}

Three more rules that bite real apps:

  • CSP is only enforced if you set it in tauri.conf.json > app > security > csp. No CSP = the WebView runs whatever it loads; local scripts are hashed, external ones get a per-load nonce only once a CSP exists.
  • Use the isolation pattern when frontend code may be untrusted (third-party deps, plugins). It injects a sandboxed iframe that can inspect/modify every IPC message before it reaches Rust; messages are encrypted with SubtleCrypto using a key regenerated each app start.
  • Treat the WebView as hostile. Anything in the frontend bundle ships to the user — no API keys, tokens, or secrets in JS. Privileged work and secrets stay in Rust.

Full capabilities/permissions/scope JSON, fs/http scope globs, CSP dev-vs-prod recipes, and isolation-pattern setup live in references/security.md.

Show full SKILL.md (333 more words)Show less

Bundle & ship

tauri build produces native installers per OS — but unsigned binaries trigger "unidentified developer" / SmartScreen warnings, so signing is not optional for distribution.

  • macOS: sign with a Developer ID cert, then notarize — Gatekeeper blocks un-notarized apps.
  • Windows: Authenticode-sign the .exe/MSI/NSIS or SmartScreen warns.
  • Linux: AppImage / .deb / .rpm; no central signing authority, but ship checksums.
  • Auto-update: the updater plugin needs a signing keypair (tauri signer generate); the private key signs releases, the public key ships in config. Without it the updater refuses unsigned updates — by design.
  • Sidecar: embed an external binary via bundle.externalBin to call it at runtime (e.g. ship a CLI your app shells out to).

Per-OS flags, notarization steps, updater config, sidecar setup, and a CI release matrix live in references/bundling-distribution.md. The CI runner matrix that runs those builds across three OSes is the github-actions skill's job; this skill defines what to build and sign.

Anti-patterns

Anti-patternWhy it's wrongDo instead
One capability granting broad permissions to all windowsAny XSS gets the full IPC surfacePer-window capability, scoped to the commands that window needs
Permission with no allow/scope on fs/httpCommand can touch any path/hostAdd an allow glob ($APPCONFIG/*) and deny the rest
Blocking call (std::fs, sync HTTP) in a commandFreezes the IPC pool → frozen UIasync fn + tokio / spawn the work
.unwrap() instead of returning Result<T, E>Panic crashes the command thread silentlyReturn Result, map_err to a serializable error
API keys/tokens in the frontend bundleShips to every user; trivially extractedKeep secrets and privileged calls in Rust
No CSP set in configWebView runs any loaded scriptSet app.security.csp; isolation pattern if deps are untrusted
Copying a v1 tauri.conf.json > allowlistThat key does not exist in v2Use capabilities/*.json (ACL)
Assuming bundled ChromiumIt's the OS WebView (WebKit/WebView2)Test rendering on each OS's engine; avoid Chromium-only CSS/JS

scripts/verify.sh is an advisory static lint over an src-tauri/ tree that catches several of these: capabilities present, registered commands exist, no v1 allowlist, fallible-looking commands return Result.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/tauri of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/bundling-distribution.md
  • references/security.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Tauri next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tauri compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tauri this skillericrisco/rsc-harness156—~2.6kAutomated safety check: PassMIT
Tauri Config Ipcifer47/markeron1.2k—~1kAutomated safety check: PassMIT
Reactflow Workflowveloxbase/veloxdb646—~897Automated safety check: PassMIT
Worklog Designregisx001/Worklog258—~3.3kAutomated safety check: PassMIT
I18nhuoshen80/ReinaManager693—~177Automated safety check: PassAGPL-3.0
Tv Remote UIventic/ventic174—~4.2kAutomated safety check: PassMIT

Similar skills

  • Tauri Config Ipc

    ifer47/markeron

    Extend MarkerOn settings, persisted config, or Tauri IPC commands.

    1.2k GitHub stars~1k tokensUpdated 8 days ago
    Frontend & DesignAuto-check passed
  • Reactflow Workflow

    veloxbase/veloxdb

    Build and harden React Flow diagram surfaces in VeloxDB using @xyflow/react patterns (nodes, edges, viewport, controls, interactions, performance).

    646 GitHub stars~897 tokensUpdated 7 days ago
    Frontend & DesignAuto-check passed
  • Worklog Design

    regisx001/Worklog

    Design and UI skill for the Worklog desktop project manager.

    258 GitHub stars~3.3k tokensUpdated 1 mo ago
    Frontend & DesignAuto-check passed
  • I18n

    huoshen80/ReinaManager

    使用 i18next-cli 检查、同步和整理本项目的国际化资源。涉及新增、修改、删除翻译键或国际化字符串,以及修复缺失翻译时使用。

    693 GitHub stars~177 tokensUpdated 4 days ago
    Frontend & DesignAuto-check passed
  • Tv Remote UI

    ventic/ventic

    How this app stays usable from a TV remote (Android TV / Google TV).

    174 GitHub stars~4.2k tokensUpdated 3 days ago
    Frontend & DesignAuto-check passed
  • Web Design

    drewnekota/cetus

    A skill your agent uses when building any web page, HTML artifact, landing page, dashboard, slide deck, report, email, or UI component the user will look at.

    146 GitHub stars~2.1k tokensUpdated 2 days ago
    Frontend & DesignAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Works with

Questions about Tauri

What does Tauri do?

A skill your agent uses when building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC, streaming to the frontend…. Tauri is an agent skill from ericrisco/rsc-harness. Use when building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC, streaming to the frontend, the default-deny capabilities/permissions ACL, bundling and signed auto-updates.

When should I use Tauri?

Tauri fits situations like: building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC; streaming to the frontend; the default-deny capabilities/permissions ACL; bundling and signed auto-updates.

How do I install Tauri in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill tauri -a claude-code`. Or copy the skill folder (skills/tauri in ericrisco/rsc-harness) into .claude/skills/tauri in your project. Claude Code loads it when a task matches its description.

How do I install Tauri in Codex?

Run `npx skills add ericrisco/rsc-harness --skill tauri -a codex`. Or copy the skill folder (skills/tauri in ericrisco/rsc-harness) into .agents/skills/tauri in your project. Codex loads it when a task matches its description.

Can I use Tauri in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill tauri -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tauri, .gemini/skills/tauri, .github/skills/tauri and .opencode/skills/tauri in your project.

What does Tauri need to run?

Going by SKILL.md and its folder, Tauri needs a shell for the scripts in its folder and the command-line tools its instructions call (npm and npx). Our summary lists: Node.js; A Bash shell.

Does Tauri access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Tauri safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Tauri use?

Tauri is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tauri use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Tauri?

Skills that share tags, products or a category with Tauri: Tauri Config Ipc (ifer47/markeron, 1.2k stars), Reactflow Workflow (veloxbase/veloxdb, 646 stars), Worklog Design (regisx001/Worklog, 258 stars) and I18n (huoshen80/ReinaManager, 693 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tauri?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.