Tauri Config Ipc
ifer47/markeron
Extend MarkerOn settings, persisted config, or Tauri IPC commands.
A skill your agent uses when building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC, streaming to the frontend…
$ npx skills add ericrisco/rsc-harness --skill tauri -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness tauri --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tauri .claude/skills/tauri && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "tauri" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tauri into .claude/skills/tauri/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tauri", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/tauriType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill tauri -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness tauri --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/tauri .agents/skills/tauri && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "tauri" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tauri into .agents/skills/tauri/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tauri", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill tauri -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness tauri --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/tauri .cursor/skills/tauri && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "tauri" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tauri into .cursor/skills/tauri/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tauri", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/tauri--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill tauri -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness tauri --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/tauri .gemini/skills/tauri && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "tauri" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tauri into .gemini/skills/tauri/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tauri", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness tauriInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill tauri -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/tauri .github/skills/tauri && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "tauri" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tauri into .github/skills/tauri/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tauri", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill tauri -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness tauri --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/tauri .opencode/skills/tauri && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "tauri" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tauri into .opencode/skills/tauri/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tauri", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
tauriA skill your agent uses when building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC, streaming to the frontend…
Tauri is an agent skill from ericrisco/rsc-harness. Use when building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC, streaming to the frontend, the default-deny capabilities/permissions ACL, bundling and signed auto-updates. NOT a Chromium+Node shell needing Node APIs in a main process (that is electron).
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/bundling-distribution.md`).
It sits in Frontend & Design. It works with Tauri and Rust. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
npmnpxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Tauri loads about 2.6k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 86 tokens; SKILL.md has 1,040 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,040 words, ~2,649 tokens.
.claude/skills/tauri/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Tauri builds a desktop (and, since v2, mobile) app from a Rust core plus the operating system's own WebView — not a bundled browser. That is the whole value proposition: ~12MB installers and 30-50MB idle RAM, versus Electron's ~180MB installers and 150-300MB because it ships Chromium + Node. You write your UI in any web framework, expose privileged work as Rust commands, and the WebView talks to Rust over a sandboxed IPC bridge.
Always target v2. Tauri 2.0 went stable in October 2024; the current line is 2.x
(2.11.x as of mid-2026). v1 docs use a tauri > allowlist config that no longer exists —
if you see allowlist, you are reading the wrong era. v2 also adds iOS/Android targets,
so the same Rust core can ship to mobile.
This skill owns the shell: commands, IPC, the security ACL, the bundler, the updater.
It does not own the Rust language itself (that is the rust skill), the web UI inside
the window (the react/nextjs skills), a Chromium+Node shell (../electron/SKILL.md), or
app-code hardening beyond the IPC boundary (../secure-coding/SKILL.md).
| Situation | Do this |
|---|---|
| Greenfield app, no UI yet | npm create tauri-app@latest — pick your frontend, get src-tauri/ wired |
| You already have a web app (Vite/Next/etc.) | npx @tauri-apps/cli@latest init inside it; point build.frontendDist at your build output |
| Add mobile to an existing desktop app | tauri ios init / tauri android init; gate native bits behind #[cfg(mobile)] |
You see tauri.conf.json > tauri > allowlist | You are on v1 — migrate to v2 capabilities before adding anything |
src-tauri/ is its own Cargo crate: Cargo.toml, tauri.conf.json, src/lib.rs
(the run() entry point), and capabilities/. The frontend is a sibling directory the
bundler reads from frontendDist.
A command is a Rust function the frontend can call. Each rule below has a one-line why.
#[tauri::command] on the fn, then list it in
tauri::generate_handler![...] inside invoke_handler. Unregistered commands are not a
compile error — they fail at runtime when JS calls them.invoke('read_config', { filePath }) maps to Rust
read_config(file_path: String). Command names stay snake_case; args auto-map
camelCase (JS) ⇄ snake_case (Rust).Result<T, E> where E: Serialize. An Err becomes a
rejected JS promise; a panic instead crashes the command thread silently.async command or a
spawned task. Commands run on a shared IPC thread pool — a blocking call freezes other
IPC, which users see as a frozen UI..manage(x) + State<'_, T>. If a guard is held across an
.await, use tokio::sync::Mutex, not std::sync::Mutex — the std guard is not Send
and will not compile in an async command.// src-tauri/src/lib.rs
use tauri::State;
use tokio::sync::Mutex;
#[derive(Default)]
struct AppState { counter: u64 }
#[tauri::command] // registered below or it 404s at runtime
async fn read_config(file_path: String) -> Result<String, String> {
tokio::fs::read_to_string(&file_path) // async I/O — does not block the IPC pool
.await
.map_err(|e| e.to_string()) // Err -> rejected JS promise
}
#[tauri::command]
async fn bump(state: State<'_, Mutex<AppState>>) -> Result<u64, String> {
let mut s = state.lock().await; // tokio Mutex: guard is held across .await
s.counter += 1;
Ok(s.counter)
}
#[cfg_attr(mobile, tauri::mobile_entry_point)] // same core compiles for iOS/Android
pub fn run() {
tauri::Builder::default()
.manage(Mutex::new(AppState::default()))
.invoke_handler(tauri::generate_handler![read_config, bump])
.run(tauri::generate_context!())
.expect("error while running tauri application");
}// frontend
import { invoke } from '@tauri-apps/api/core';
const text = await invoke('read_config', { filePath: '/app/config.toml' });
// throws (rejected promise) if the command returns Err — wrap in try/catchBad → Good, the failure people hit most:
// Bad: std Mutex held across .await — won't compile in an async command, or you
// "fix" it by dropping the guard early and create a race.
async fn save(state: State<'_, std::sync::Mutex<AppState>>) { /* ... */ }
// Good: async-aware lock.
async fn save(state: State<'_, tokio::sync::Mutex<AppState>>) -> Result<(), String> { Ok(()) }Two ways to push from Rust to the frontend — pick by ordering needs:
Channel<T> for ordered streaming. Download progress, file chunks, an HTTP body.
Messages arrive in send order on one typed channel — the right tool for "report
progress as it happens."emit / listen events for fire-and-forget pub/sub. App-wide notifications, "data
refreshed," a tray action. No ordering or backpressure guarantees; many listeners, no
reply.use tauri::ipc::Channel;
#[derive(Clone, serde::Serialize)]
struct Progress { downloaded: u64, total: u64 }
#[tauri::command]
async fn download(url: String, on_progress: Channel<Progress>) -> Result<(), String> {
// ... as bytes arrive:
on_progress.send(Progress { downloaded: 4096, total: 1_000_000 })
.map_err(|e| e.to_string())?;
Ok(())
}import { Channel, invoke } from '@tauri-apps/api/core';
const onProgress = new Channel();
onProgress.onmessage = (p) => updateBar(p.downloaded / p.total);
await invoke('download', { url, onProgress });Tauri v2's IPC is an Access Control List, default-deny. The chain:
capabilities (group windows/webviews) → grant permissions (named command sets) → permissions map scopes (what data/paths a command may touch). A webview that matches no capability has zero IPC access. This is the opposite of v1's opt-out allowlist — you grant exactly what each window needs.
// src-tauri/capabilities/default.json — grant only what the main window uses
{
"$schema": "../gen/schemas/desktop-schema.json",
"identifier": "main-capability",
"windows": ["main"],
"permissions": [
"core:default",
{
"identifier": "fs:allow-read-text-file",
"allow": [{ "path": "$APPCONFIG/*" }] // scope: app config dir only, nothing else
}
]
}Three more rules that bite real apps:
tauri.conf.json > app > security > csp.
No CSP = the WebView runs whatever it loads; local scripts are hashed, external ones get
a per-load nonce only once a CSP exists.Full capabilities/permissions/scope JSON, fs/http scope globs, CSP dev-vs-prod recipes, and
isolation-pattern setup live in references/security.md.
tauri build produces native installers per OS — but unsigned binaries trigger
"unidentified developer" / SmartScreen warnings, so signing is not optional for distribution.
.exe/MSI/NSIS or SmartScreen warns..deb / .rpm; no central signing authority, but ship checksums.tauri signer generate);
the private key signs releases, the public key ships in config. Without it the updater
refuses unsigned updates — by design.bundle.externalBin to call it at runtime
(e.g. ship a CLI your app shells out to).Per-OS flags, notarization steps, updater config, sidecar setup, and a CI release matrix
live in references/bundling-distribution.md. The CI runner matrix that runs those builds
across three OSes is the github-actions skill's job; this skill defines what to build and sign.
| Anti-pattern | Why it's wrong | Do instead |
|---|---|---|
| One capability granting broad permissions to all windows | Any XSS gets the full IPC surface | Per-window capability, scoped to the commands that window needs |
Permission with no allow/scope on fs/http | Command can touch any path/host | Add an allow glob ($APPCONFIG/*) and deny the rest |
Blocking call (std::fs, sync HTTP) in a command | Freezes the IPC pool → frozen UI | async fn + tokio / spawn the work |
.unwrap() instead of returning Result<T, E> | Panic crashes the command thread silently | Return Result, map_err to a serializable error |
| API keys/tokens in the frontend bundle | Ships to every user; trivially extracted | Keep secrets and privileged calls in Rust |
| No CSP set in config | WebView runs any loaded script | Set app.security.csp; isolation pattern if deps are untrusted |
Copying a v1 tauri.conf.json > allowlist | That key does not exist in v2 | Use capabilities/*.json (ACL) |
| Assuming bundled Chromium | It's the OS WebView (WebKit/WebView2) | Test rendering on each OS's engine; avoid Chromium-only CSS/JS |
scripts/verify.sh is an advisory static lint over an src-tauri/ tree that catches several of
these: capabilities present, registered commands exist, no v1 allowlist, fallible-looking
commands return Result.
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in skills/tauri of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
Tauri next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Tauri this skillericrisco/rsc-harness | 156 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Tauri Config Ipcifer47/markeron | 1.2k | — | ~1k | Automated safety check: Pass | MIT | |
| Reactflow Workflowveloxbase/veloxdb | 646 | — | ~897 | Automated safety check: Pass | MIT | |
| Worklog Designregisx001/Worklog | 258 | — | ~3.3k | Automated safety check: Pass | MIT | |
| I18nhuoshen80/ReinaManager | 693 | — | ~177 | Automated safety check: Pass | AGPL-3.0 | |
| Tv Remote UIventic/ventic | 174 | — | ~4.2k | Automated safety check: Pass | MIT |
ifer47/markeron
Extend MarkerOn settings, persisted config, or Tauri IPC commands.
veloxbase/veloxdb
Build and harden React Flow diagram surfaces in VeloxDB using @xyflow/react patterns (nodes, edges, viewport, controls, interactions, performance).
regisx001/Worklog
Design and UI skill for the Worklog desktop project manager.
huoshen80/ReinaManager
使用 i18next-cli 检查、同步和整理本项目的国际化资源。涉及新增、修改、删除翻译键或国际化字符串,以及修复缺失翻译时使用。
ventic/ventic
How this app stays usable from a TV remote (Android TV / Google TV).
drewnekota/cetus
A skill your agent uses when building any web page, HTML artifact, landing page, dashboard, slide deck, report, email, or UI component the user will look at.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Categories
A skill your agent uses when building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC, streaming to the frontend…. Tauri is an agent skill from ericrisco/rsc-harness. Use when building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC, streaming to the frontend, the default-deny capabilities/permissions ACL, bundling and signed auto-updates.
Tauri fits situations like: building a lightweight cross-platform desktop (or v2 mobile) app with Tauri — a Rust core plus the OS-native WebView: Rust commands and IPC; streaming to the frontend; the default-deny capabilities/permissions ACL; bundling and signed auto-updates.
Run `npx skills add ericrisco/rsc-harness --skill tauri -a claude-code`. Or copy the skill folder (skills/tauri in ericrisco/rsc-harness) into .claude/skills/tauri in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill tauri -a codex`. Or copy the skill folder (skills/tauri in ericrisco/rsc-harness) into .agents/skills/tauri in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill tauri -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tauri, .gemini/skills/tauri, .github/skills/tauri and .opencode/skills/tauri in your project.
Going by SKILL.md and its folder, Tauri needs a shell for the scripts in its folder and the command-line tools its instructions call (npm and npx). Our summary lists: Node.js; A Bash shell.
SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Tauri is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Tauri: Tauri Config Ipc (ifer47/markeron, 1.2k stars), Reactflow Workflow (veloxbase/veloxdb, 646 stars), Worklog Design (regisx001/Worklog, 258 stars) and I18n (huoshen80/ReinaManager, 693 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.