Agent skill

Desktop

by gridaco in gridaco/grida

Grida Desktop Electron shell and release-impact work: BrowserWindow, preload, window.grida, menus, protocol/deep links, file associations, Forge, path-scoped bridge security, Electron-only UI bugs…

Apache-2.0Auto-check: notesTesting & QA

Install Desktop

skills CLI
$ npx skills add gridaco/grida --skill desktop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gridaco/grida desktop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gridaco/grida.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/desktop .claude/skills/desktop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
desktop
GitHub stars
2.7k
Token cost
~3.2k tokens
SKILL.md length
1,096 words
Files
2 (incl. scripts)
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Grida Desktop Electron shell and release-impact work: BrowserWindow, preload, window.grida, menus, protocol/deep links, file associations, Forge, path-scoped bridge security, Electron-only UI bugs…

  • Works in 4 steps: pnpm dev in desktop/ does not serve the… → The preload is path-scoped. Outside… → Keep contextIsolation: true,… → …
  • Editor/app/desktop/
  • SKILL.md covers When to use this skill, Shape, Running Locally and CDP / Playwright Verification, plus 6 more sections
  • Runs Shell scripts from its folder; calls pnpm and curl; reaches grida.co

What it does

Desktop is an agent skill from gridaco/grida. Grida Desktop Electron shell and release-impact work: BrowserWindow, preload, window.grida, menus, protocol/deep links, file associations, Forge, path-scoped bridge security, Electron-only UI bugs, and CDP / Playwright verification. Use for desktop/, editor/app/desktop/, editor/scaffolds/desktop/, editor/lib/desktop/, /desktop/ CSP, GRIDA-SEC-004, and deciding whether linked-package or hosted-renderer changes require a native Desktop version bump or coordinated release. For implementing daemon/agent-tenant core…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/audit-release-impact.sh`).

It sits in Testing & QA, covering Project scaffolding and Browser testing. It works with Playwright and React. The licence is Apache-2.0.

When your agent uses it

  • Editor/app/desktop/
  • Editor/scaffolds/desktop/
  • Editor/lib/desktop/
  • Deciding whether linked-package

Example prompts

  • “/desktop”

Requirements

  • A Bash shell

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. pnpm dev in desktop/ does not serve the renderer. Run the editor dev
  2. The preload is path-scoped. Outside /desktop/*, window.grida is
  3. Keep contextIsolation: true, nodeIntegration: false, and
  4. Electron code adapts and supervises native shell behavior. Core behavior

What it can do on your machine

Read from SKILL.md and the folder at commit 165496f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • pnpm
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • grida.co

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Desktop loads about 3.2k tokens when it runs. Until then it costs about 145 tokens; SKILL.md has 1,096 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~145
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:94
    `editor/.env.local`. Do not point the editor at hosted Supabase unless

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from gridaco/grida at commit 165496f, republished under its Apache-2.0 licence (© gridaco). 1,096 words, ~3,175 tokens.

Download SKILL.mdSave it as .claude/skills/desktop/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
desktop
description
Grida Desktop Electron shell and release-impact work: BrowserWindow, preload, `window.grida`, menus, protocol/deep links, file associations, Forge, path-scoped bridge security, Electron-only UI bugs, and CDP / Playwright verification. Use for `desktop/`, `editor/app/desktop/**`, `editor/scaffolds/desktop/**`, `editor/lib/desktop/**`, `/desktop/*` CSP, GRIDA-SEC-004, and deciding whether linked-package or hosted-renderer changes require a native Desktop version bump or coordinated release. For implementing daemon/agent-tenant core behavior, use `agent-system` as well.

Grida Desktop - Electron Shell

This skill is for the Electron shell only: main process, windows, menus, preload, native protocol/file entry points, and the renderer bridge surface. The renderer is still the editor's Next.js app under editor/app/desktop/; Electron URL-loads it from http://localhost:3000/desktop/* in dev and https://grida.co/desktop/* in prod.

Use agent-system for the daemon + agent-tenant core, sessions, workspaces, providers, tool execution, HTTP routes, and tests in packages/grida-daemon and packages/grida-ai-agent.

Adjacent: security for the GRIDA-SEC-004 trust boundary, code-react for React code under editor/app/desktop/** and editor/scaffolds/desktop/**.

When to use this skill

  • Editing desktop/src/**, desktop/forge.config.ts, desktop/Info.plist, or desktop packaging/dev-server wiring.
  • Changing desktop/src/main.ts, window.ts, menu.ts, preload, bridge contract, app branding, host-app integration, deep links, file associations, single-instance behavior, or multi-window routing.
  • Touching editor/app/desktop/**, editor/scaffolds/desktop/**, or editor/lib/desktop/** because the UI depends on window.grida.
  • Debugging "works in browser but not in desktop" or "only repros in Electron" issues.
  • Verifying the desktop app through CDP / Playwright.
  • Touching CSP or proxy behavior for /desktop/*.
  • Auditing whether linked-package or hosted Desktop renderer changes require a native version bump or coordinated release.

Use agent-system to implement core agent behavior that can be tested without Electron: packages/grida-daemon/**, packages/grida-ai-agent/**, daemon HTTP routes, sessions, files/workspaces, providers, tools, runtime, skills, and BYOK/secrets. Also use this skill when auditing whether that work changes the packaged Desktop payload or its compatibility with the hosted renderer.


Shape

Electron main (desktop/src/main.ts)
  - single-instance lock
  - BrowserWindow.loadURL(`${EDITOR_BASE_URL}/desktop/welcome`)
  - grida:// protocol router, open-file/argv queue
  - starts/supervises the AgentSidecar adapter
        |
        | contextBridge.exposeInMainWorld("grida", ...)
        | only for /desktop or /desktop/*
        v
Renderer (editor/app/desktop/**)
  - DesktopBridgeGate renders desktop UI only when bridge is present
  - web visitors get OpenInDesktopCta
  - CSP strict, no analytics, no third-party scripts
        |
        v
AgentSidecar loopback service
  - owned by the agent-system skill

Four invariants:

  1. pnpm dev in desktop/ does not serve the renderer. Run the editor dev server on :3000 separately.
  2. The preload is path-scoped. Outside /desktop/*, window.grida is intentionally undefined.
  3. Keep contextIsolation: true, nodeIntegration: false, and sandbox: true.
  4. Electron code adapts and supervises native shell behavior. Core behavior that can be tested without Electron belongs in agent-system.

Running Locally

Authenticated renderer flows use the repository's default local development setup: local Supabase plus NEXT_PUBLIC_GRIDA_USE_INSIDERS_AUTH=1 in editor/.env.local. Do not point the editor at hosted Supabase unless authentication itself is under test.

The editor flag selects the insiders sign-in path. The Electron dev:insiders command selects Insiders app branding; it does not configure renderer authentication.

Use two terminals:

sh
# Terminal 1 - renderer
pnpm --filter editor dev

# Terminal 2 - Electron shell
pnpm --dir desktop dev
# Optional Insiders-branded shell:
pnpm --dir desktop dev:insiders

EDITOR_BASE_URL lives in desktop/src/env.ts. It resolves to http://localhost:3000 in development and https://grida.co otherwise.

electron-forge start can return the shell prompt while Electron stays alive. Confirm with:

sh
lsof -iTCP:9222 -sTCP:LISTEN
ps -A | grep grida/desktop/node_modules/electron

Kill cleanly:

sh
pkill -f "grida/desktop/node_modules/electron"
pkill -f "grida/desktop/node_modules/.bin/electron-forge"

CDP / Playwright Verification

Launch with CDP enabled:

sh
cd desktop && pnpm dev -- --remote-debugging-port=9222

The -- is required so Forge forwards the flag to Electron.

Probe targets:

sh
curl -s http://127.0.0.1:9222/json/version
curl -s http://127.0.0.1:9222/json

Preferred client:

  • One-off probe: direct CDP with Node's built-in WebSocket and fetch.
  • Scripted verification: chromium.connectOverCDP("http://127.0.0.1:9222").
  • Owned Electron lifecycle or native menus/dialogs: Playwright _electron plus electron-playwright-helpers.

Minimal probe:

js
import { chromium } from "playwright-core";

const browser = await chromium.connectOverCDP("http://127.0.0.1:9222");
const page = browser.contexts()[0].pages()[0];
console.log("url:", page.url());
console.log("hasBridge:", await page.evaluate(() => typeof window.grida));
await page.screenshot({ path: "/tmp/grida-desktop.png" });
await browser.close();

If playwright-core does not resolve at repo root, run the probe from editor/, import the package from pnpm's .pnpm path, or add Playwright to desktop/package.json.

Inspect main process:

sh
cd desktop && pnpm dev -- --inspect-electron

Then open chrome://inspect/#devices, add localhost:5858, and inspect.


Bridge

The renderer's native-capability surface is the typed client in editor/lib/desktop/bridge.ts. React code reads it via useDesktopBridge(), an SSR-safe useSyncExternalStore wrapper.

Hard gate:

tsx
const bridge = useDesktopBridge();
if (!bridge) return null;
return <Button onClick={() => bridge.dialog.open(...)} />;

Soft branch:

tsx
const bridge = useDesktopBridge();
const onSave = bridge
  ? () => bridge.files.write(docId, svg)
  : () => downloadAsBlob(svg);

DesktopBridgeGate in editor/scaffolds/desktop/ gates whole desktop pages.

Verify from CDP:

js
await page.evaluate(() => ({
  bridge: typeof window.grida,
  version: window.grida?.app?.version,
  caps: window.grida?.caps,
}));

The preload runs after Next.js streams the first HTML. A screenshot taken immediately after load can catch the temporary CTA before hydration observes window.grida; wait for a post-hydration element or a short timeout before judging the bridge state.


Boundaries

ConcernLives inNotes
Window/menu/dialog wiringdesktop/src/main/**Native shell behavior
Protocol and file routingdesktop/src/main/**, desktop/Info.plistgrida:// (prod) / grida-dev:// (dev, #955), open-file, argv queue
Agent sidecar supervisiondesktop/src/main/**, desktop/src/agent-sidecar.tsAdapter only; core is agent-system
Preload bridgedesktop/src/preload.tsPath-scoped window.grida, auth held in closure
Renderer desktop routeseditor/app/desktop/**No server actions, no next/headers
Renderer scaffoldseditor/scaffolds/desktop/**UI using @/lib/desktop/*
Typed bridge clienteditor/lib/desktop/**Pure TS client, no server-only imports

Do not put OPFS or IndexedDB desktop storage in editor/app/desktop/**. Desktop storage goes through the bridge and agent host.

Do not add core behavior in Electron main/preload. If it is testable without Electron, move it to the agent-system package.


Show full SKILL.md (471 more words)Show less

Security Boundary: GRIDA-SEC-004

When changing the bridge or navigation rules, review SECURITY.md and the security skill. The relevant desktop layers are:

  1. Path-scoped preload: window.grida only on /desktop or /desktop/* at document load time.
  2. Navigation allowlist in desktop/src/window.ts.
  3. CSP-strict /desktop/* route group.
  4. Per-launch bridge credentials held in the preload closure, never exposed on window.grida.
  5. No bridge method may exfiltrate secrets or run arbitrary local code.

Release impact and versioning

Production Desktop has two independently shipped halves: the renderer loaded from https://grida.co/desktop/*, and the native app containing Electron plus the bundled daemon/agent sidecar. A change can require a Desktop release without touching desktop/src/**.

At the start and before handoff, run the bundled audit from the repository root. It reports the release-scoped diff, uncommitted paths, and whether the current Desktop version already has a GitHub release:

sh
.agents/skills/desktop/scripts/audit-release-impact.sh

Decide from the shipped boundary, not the directory name:

  • A change to desktop/**, skills/**, or a linked package reported by the audit changes the native payload. Bump desktop/package.json before publishing a new native build when its current v<version> is already published, including as a prerelease. The release assembler deliberately refuses to modify any published release.
  • A renderer-only change needs no native version bump when it remains compatible with the latest published sidecar.
  • A release workflow or assembler change is release-impacting but does not by itself change the native payload; review its version/tag semantics directly.
  • A renderer change that sends a new model id, provider id, protocol field, route, or bridge call that the published sidecar rejects is release-coupled. Compare the validation code at the published tag and bump the Desktop version, but block the incompatible hosted behavior until affected clients are required to run that compatible version. Publishing or auto-update notification alone does not update installed clients.

When the scoped diff is non-empty, record one line in the PR description or handoff: Desktop release impact: none, Desktop release impact: version bump included, or Desktop release impact: follow-up release required.


Verification

For non-trivial desktop changes:

  1. Run both the editor dev server and Electron shell.
  2. Use CDP / Playwright to touch the changed surface.
  3. Cold reload or relaunch Electron once to exercise preload and hydration.
  4. Run owner checks:
    • Electron adapter: pnpm --dir desktop typecheck and pnpm --dir desktop test.
    • Renderer desktop UI: pnpm --filter editor typecheck.
    • Agent core changes: switch to agent-system.

Pointers

  • Electron main: desktop/src/main.ts
  • Window and navigation policy: desktop/src/window.ts
  • Preload bridge: desktop/src/preload.ts
  • Forge config: desktop/forge.config.ts
  • File associations: desktop/Info.plist
  • Deep-link scheme + router: desktop/src/env.ts (DEEP_LINK_SCHEME) + desktop/src/main/protocol-router.ts — per-environment grida:// (prod) / grida-dev:// (dev + insiders), so a dev build never fights an installed prod Grida over one OS handler. Dev registration is CFBundleURLTypes via scripts/prepare-dev-electron-branding.mjs (macOS setAsDefaultProtocolClient no-ops unpackaged). Full context: #955.
  • Renderer routes: editor/app/desktop/
  • Renderer scaffolds: editor/scaffolds/desktop/
  • Typed bridge client: editor/lib/desktop/bridge.ts
  • CSP for /desktop/*: editor/proxy.ts
  • Threat model: SECURITY.md (GRIDA-SEC-004 bridge · GRIDA-SEC-005 sign-in deep link)

© gridaco, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in .agents/skills/desktop of gridaco/grida.

  • SKILL.md
  • scripts/audit-release-impact.sh

Open the folder on GitHubat commit 165496f

Compare with similar skills

Desktop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Desktop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Desktop this skillgridaco/grida2.7k—~3.2kAutomated safety check: NotesApache-2.0
Senior QAalirezarezvani/claude-skills28k1 repos~2.1kAutomated safety check: PassMIT
Senior QAborghei/Claude-Skills881—~1.6kAutomated safety check: PassMIT
Electron Best Practicesjwynia/agent-skills166—~3.1kAutomated safety check: PassMIT
Playwright Component Testingmellowagain/gitarena1151 repos~2.6kAutomated safety check: PassMIT
Playwright Coretestdino-hq/playwright-skill3861 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Senior QA

    alirezarezvani/claude-skills

    Generates unit tests, integration tests, and E2E tests for React/Next.js applications.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Testing & QAAuto-check passed
  • Senior QA

    borghei/Claude-Skills

    Testing for React/Next.js with Jest, React Testing Library, and Playwright.

    881 GitHub stars~1.6k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Electron Best Practices

    jwynia/agent-skills

    Guide AI agents through Electron app development with React including security patterns, type-safe IPC, React integration, packaging with code signing, and testing.

    166 GitHub stars~3.1k tokensUpdated 7 mo ago
    MobileAuto-check passed
  • Playwright Component Testing

    mellowagain/gitarena

    Set up component testing with Playwright using a story gallery — scaffold stories and a gallery dev page driven by the built-in mount fixture, no dedicated component-testing runtime.

    115 GitHub starsUsed in 1 repo~2.6k tokens
    Testing & QAAuto-check passed
  • Playwright Core

    testdino-hq/playwright-skill

    Battle-tested Playwright patterns for writing and debugging reliable E2E, API, component, visual, accessibility, and security tests.

    386 GitHub starsUsed in 1 repo~1.4k tokens
    Testing & QAAuto-check passed
  • UI Regression Recorder

    xuxh21/ui-regression-recorder-skill

    A skill your agent uses when the user says to initialize the current project for UI regression, record an operation, convert Playwright codegen recordings into stable tests, extract shared helpers…

    112 GitHub stars~4.4k tokensUpdated 4 mo ago
    Testing & QAAuto-check passed

More from gridaco/grida

All 29 skills in this repo
  • Io Figma

    gridaco/grida

    Guides work on the Figma I/O package (@grida/io-figma, packages/grida-canvas-io-figma/).

    2.7k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • Opt Library

    gridaco/grida

    Set up, download, verify, and seed the optional Grida Library developer corpus into local Supabase.

    2.7k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Vision

    gridaco/grida

    Query images with a local Ollama vision model without loading the image into the main agent context.

    2.7k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Models

    gridaco/grida

    Research, compare, and update shared AI model JSON for TypeScript, web, and Rust consumers.

    2.7k GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed
  • Agent System

    gridaco/grida

    Grida AI agent system work: @grida/daemon (DaemonServer, loopback HTTP perimeter, files/workspaces, secrets store, daemon discovery) and @grida/agent (the agent tenant: sessions, providers/BYOK…

    2.7k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Database

    gridaco/grida

    Use BEFORE editing any file in supabase/migrations/ or supabase/schemas/, OR when the user runs a /database subcommand (compact local migration, rls scenarios, align).

    2.7k GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Desktop

What does Desktop do?

Grida Desktop Electron shell and release-impact work: BrowserWindow, preload, window.grida, menus, protocol/deep links, file associations, Forge, path-scoped bridge security, Electron-only UI bugs…. Desktop is an agent skill from gridaco/grida.grida, menus, protocol/deep links, file associations, Forge, path-scoped bridge security, Electron-only UI bugs, and CDP / Playwright verification.

When should I use Desktop?

Desktop fits situations like: editor/app/desktop/; editor/scaffolds/desktop/; editor/lib/desktop/; deciding whether linked-package.

How do I install Desktop in Claude Code?

Run `npx skills add gridaco/grida --skill desktop -a claude-code`. Or copy the skill folder (.agents/skills/desktop in gridaco/grida) into .claude/skills/desktop in your project. Claude Code loads it when a task matches its description.

How do I install Desktop in Codex?

Run `npx skills add gridaco/grida --skill desktop -a codex`. Or copy the skill folder (.agents/skills/desktop in gridaco/grida) into .agents/skills/desktop in your project. Codex loads it when a task matches its description.

Can I use Desktop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gridaco/grida --skill desktop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/desktop, .gemini/skills/desktop, .github/skills/desktop and .opencode/skills/desktop in your project.

What does Desktop need to run?

Going by SKILL.md and its folder, Desktop needs a shell for the scripts in its folder and the command-line tools its instructions call (pnpm and curl). Our summary lists: A Bash shell.

Does Desktop access the network?

SKILL.md names 1 domain. In commands or code: grida.co; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Desktop safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Desktop use?

Desktop is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Desktop use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Desktop?

Skills that share tags, products or a category with Desktop: Senior QA (alirezarezvani/claude-skills, 28k stars), Senior QA (borghei/Claude-Skills, 881 stars), Electron Best Practices (jwynia/agent-skills, 166 stars) and Playwright Component Testing (mellowagain/gitarena, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Desktop?

gridaco (a GitHub organization) maintains it in gridaco/grida, which has 2,659 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 7, 2026.

Source: gridaco/grida on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.