Agent skill

Breeze Helper

by LanternOps in LanternOps/breeze

Quick reference for the Breeze Helper Tauri desktop app — architecture, Rust backend commands, React frontend, config files, IPC with the Go agent, helper chat API routes, tool approval flow, and…

AGPL-3.0Auto-check passedFrontend & Design

Install Breeze Helper

skills CLI
$ npx skills add LanternOps/breeze --skill breeze-helper -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LanternOps/breeze breeze-helper --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LanternOps/breeze.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/breeze-helper .claude/skills/breeze-helper && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
breeze-helper
GitHub stars
131
Token cost
~3.2k tokens
SKILL.md length
1,026 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Quick reference for the Breeze Helper Tauri desktop app — architecture, Rust backend commands, React frontend, config files, IPC with the Go agent, helper chat API routes, tool approval flow, and…

  • Works in 5 steps: Connection states — connecting, error,… → UsernamePrompt — one-time name entry… → SessionHistory — list past… → …
  • Working on helper code
  • SKILL.md covers Architecture Overview, Tauri Commands (Rust → Frontend), Config Files and Frontend (React + Zustand), plus 10 more sections
  • Calls pnpm; needs VITE_AGENT_TOKEN

What it does

Breeze Helper is an agent skill from LanternOps/breeze. Quick reference for the Breeze Helper Tauri desktop app — architecture, Rust backend commands, React frontend, config files, IPC with the Go agent, helper chat API routes, tool approval flow, and tray integration. Use when working on helper code, debugging helper issues, adding helper features, or understanding how the Helper communicates with the API and agent.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Frontend & Design. It works with Tauri, React and Rust. The repository describes itself as: The open-source IT platform that comes with the workers. RMM + PSA in one system, with a governed AI operator built in. The licence is AGPL-3.0.

When your agent uses it

  • Working on helper code
  • Debugging helper issues
  • Adding helper features
  • Understanding how the Helper communicates with the API and agent

Example prompts

  • “/breeze-helper”

Requirements

  • A credential in VITE_AGENT_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Connection states — connecting, error, disconnected (with retry)
  2. UsernamePrompt — one-time name entry (persists to localStorage, falls back to OS username)
  3. SessionHistory — list past conversations, load by ID
  4. DeviceInfoView — hostname, OS, status, agent version (from GET /devices/by-agent/:agentId)
  5. Chat — messages, markdown rendering, tool indicators, thinking dots, approval popup

What it can do on your machine

Read from SKILL.md and the folder at commit 5a2d714. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • VITE_AGENT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Breeze Helper loads about 3.2k tokens when it runs. Until then it costs about 95 tokens; SKILL.md has 1,026 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LanternOps/breeze at commit 5a2d714, republished under its AGPL-3.0 licence (© LanternOps). 1,026 words, ~3,163 tokens.

Download SKILL.mdSave it as .claude/skills/breeze-helper/SKILL.md (or your agent's skills folder).
name
breeze-helper
description
Quick reference for the Breeze Helper Tauri desktop app — architecture, Rust backend commands, React frontend, config files, IPC with the Go agent, helper chat API routes, tool approval flow, and tray integration. Use when working on helper code, debugging helper issues, adding helper features, or understanding how the Helper communicates with the API and agent.

Breeze Helper Reference

Lightweight Tauri v2 desktop app providing an AI chat assistant, device info, and tool approval interface. Runs in the system tray, spawned by the Go agent on Windows as a SYSTEM process in the user's session.

Architecture Overview

apps/helper/
  src/
    App.tsx                    # Main UI (chat, device info, history, approval popup)
    main.tsx                   # React entry point
    stores/chatStore.ts        # Zustand state (auth, messages, SSE streaming, approvals)
    styles.css                 # Dark-theme styling
  src-tauri/
    src/lib.rs                 # Rust backend (~776 lines): config, HTTP client, tray, streaming
    tauri.conf.json            # App config (380×600 frameless, tray icon, CSP)
    Cargo.toml                 # Rust deps (tauri v2, reqwest, tokio, serde_yaml)
    build.rs                   # Tauri build script
  vite.config.ts               # Frontend build
  package.json                 # React + Zustand + react-markdown

Tauri Commands (Rust → Frontend)

Registered in lib.rs via generate_handler![]:

CommandReturnsPurpose
read_agent_configAgentConfigLoad agent.yaml + secrets.yaml, init HTTP client
helper_fetchHelperFetchResponseAuthenticated HTTP proxy with mTLS + SSRF protection
hide_window—Hide window to tray
minimize_window—Minimize window
get_os_usernameStringOS username (falls back to USERNAME env for SYSTEM context)
get_helper_configHelperConfigLoad helper_config.yaml (tray menu toggles)
update_chat_active—Write helper_status.yaml (agent reads for idle detection)
helper_fetch — Key Design

The central HTTP proxy command. All frontend API calls go through this.

  • SSRF protection: Validates request URL starts with configured api_url
  • Auth injection: Always sets Authorization: Bearer <token>, prevents frontend override
  • mTLS: Builds reqwest::Client with Identity::from_pem if cert+key present in secrets.yaml
  • Streaming: When stream: true, spawns tokio task that emits helper-fetch-stream Tauri events as StreamChunkEvent { stream_id, chunk, done, error }
  • Non-stream: Returns full body inline in HelperFetchResponse

Config Files

All in the agent config directory (same as agent.yaml):

FileWriterReaderPurpose
agent.yamlGo agentHelperserver_url, agent_id
secrets.yamlGo agentHelperauth_token, mtls_cert_pem, mtls_key_pem (0640)
helper_config.yamlGo agentHelperTray menu toggles, portal URL, device name/status
helper_status.yamlHelperGo agentversion, chat_active, last_activity, pid
Config Paths
PlatformPath
macOS/Library/Application Support/Breeze/
Windows%ProgramData%\Breeze\
Linux/etc/breeze/
HelperConfig Fields
yaml
show_tray_icon: true         # Draw the tray icon at all (#3202). Independent of
                             # the three menu-item flags below: with this false
                             # the helper still serves chat, remote-access
                             # consent and PAM dialogs, it just has no tray.
                             # Missing key => TRUE everywhere in the chain.
show_open_portal: true       # Show "Open Breeze Portal" in tray menu
show_device_info: true       # Show "Device Info" in tray menu
show_request_support: true   # Show "Request Support" in tray menu
portal_url: ""               # URL for portal (falls back to api_url)
device_name: ""              # Display name
device_status: ""            # Current status
last_checkin: ""             # Last check-in timestamp

Config reloads every 60s; tray menu rebuilds on change.

Frontend (React + Zustand)

Views (in App.tsx)
  1. Connection states — connecting, error, disconnected (with retry)
  2. UsernamePrompt — one-time name entry (persists to localStorage, falls back to OS username)
  3. SessionHistory — list past conversations, load by ID
  4. DeviceInfoView — hostname, OS, status, agent version (from GET /devices/by-agent/:agentId)
  5. Chat — messages, markdown rendering, tool indicators, thinking dots, approval popup
Chat Store (chatStore.ts)

State: connectionState, agentConfig, sessionId, messages, isStreaming, pendingApproval, sessions, username

Key methods:

  • initialize() — loads agent config via Tauri invoke (or VITE_* env vars for dev)
  • sendMessage(content) — creates session if needed, POSTs via SSE stream
  • loadSessions() / loadSession(id) — session history
  • approveExecution(executionId, approved) — tool approval
  • clearMessages() — closes session, resets state
HTTP Layer (Tauri vs Dev)

Two helper functions abstract Tauri invoke vs native fetch:

  • helperRequest(config, url, options) — non-streaming requests
  • helperStreamRequest(config, url, options, onChunk, onDone) — SSE streaming

In Tauri: calls helper_fetch (Rust mTLS client). In browser dev: uses native fetch() with VITE_API_URL / VITE_AGENT_TOKEN / VITE_AGENT_ID.

Stream listener race fix: Event listener registered BEFORE helper_fetch invoke to avoid missing chunks when proxy buffers the full response.

SSE Event Processing

processSSELines() handles: message_start, content_delta, tool_use_start, tool_result, message_end, approval_required, error, done. Plan events (plan_approval_required, etc.) are received but not yet rendered.

Helper Chat API Routes

apps/api/src/routes/helper/index.ts — mounted at /api/v1/helper/*

Auth: Agent bearer token (brz_ prefix) via helperAuth middleware (SHA-256 hash lookup against devices.agentTokenHash). Creates synthetic AuthContext scoped to device's org.

MethodPathPurpose
POST/chat/sessionsCreate session (optional helperUser, permissionLevel)
POST/chat/sessions/:id/messagesSend message + SSE response stream
GET/chat/sessionsList device sessions (filterable by ?helperUser=)
GET/chat/sessions/:id/messagesLoad message history
DELETE/chat/sessions/:idClose session
POST/chat/sessions/:id/approve/:executionIdApprove/reject tool execution
GET/configReturn helper config (permission level, screen capture)
POST/screenshotsUpload screenshot (base64, 24h retention)
Pre-flight Checks (per message)
  1. Session exists and belongs to device
  2. Session not expired (24h max age)
  3. Turn limit not exceeded
  4. Rate limit: 30 msg/60s per device (Redis)
  5. Org budget check (fail-closed)
  6. Input sanitization
Permission Levels
LevelDescription
basicRead-only tools
standardDefault — read + some write tools
extendedAll tools including destructive operations

Configured via helperToolFilter.ts → getHelperAllowedMcpToolNames(level).

Tool Approval Flow

  1. AI invokes a restricted tool → approval_required SSE event
  2. ToolApprovalPopup renders with description, device badge, parameters
  3. 5-minute auto-deny countdown timer
  4. User clicks Allow/Deny → POST /chat/sessions/:id/approve/:executionId
  5. Hidden input keys filtered from display: deviceId, orgId, siteId, sessionId
Show full SKILL.md (403 more words)Show less

Agent IPC Integration

The Go agent spawns Helper in user sessions. Key IPC types from agent/internal/ipc/message.go:

TypeDirectionPurpose
auth_request/responseHelper → AgentAuthentication on connect
capabilitiesHelper → AgentReport features (notify, tray, capture, clipboard)
desktop_start/stopAgent → HelperWebRTC session lifecycle
desktop_inputAgent → HelperKeyboard/mouse relay
clipboard_get/set/dataBidirectionalClipboard sync
sas_request/responseHelper → AgentCtrl+Alt+Del (Windows)
launch_processAgent → HelperExecute as logged-in user

Helper roles: system (SYSTEM token, desktop capture) or user (logged-in user, script execution).

Windows SYSTEM Context
  • Agent service (Session 0) spawns Helper via CreateProcessAsUser with SYSTEM token + session ID override
  • Helper detects SYSTEM context in lib.rs setup: checks LOCALAPPDATA for "systemprofile"
  • Redirects WebView2 data dir to %ProgramData%\Breeze\helper-webview\ to avoid access issues
  • get_os_username() falls back to USERNAME env var when whoami returns "SYSTEM"

Tray Menu

Built dynamically from HelperConfig flags:

Menu ItemAction
Request SupportShow chat window
Open Breeze PortalOpen portal URL in browser
Device InfoEmit show-device-info event, show device info view
Exitapp.exit(0)

Left-click on tray icon → show chat window. Right-click → context menu.

Security

  • SSRF prevention: helper_fetch validates URL starts with configured API URL
  • Auth header protection: Authorization always set by Rust, frontend can't override
  • mTLS: Client certificate from secrets.yaml (optional, for Cloudflare mTLS)
  • Token hashing: Agent token validated via SHA-256 hash comparison
  • Device scoping: All session queries include deviceId filter
  • Input sanitization: sanitizeUserMessage() applied to all chat input
  • Rate limiting: 30 msg/min per device via Redis sliding window
  • Budget enforcement: Org budget checked before every message (fail-closed)

Build & Development

bash
# Dev mode (Vite hot-reload + Tauri)
cd apps/helper && pnpm tauri dev

# Build distributable
cd apps/helper && pnpm tauri build

# Frontend-only dev (without Tauri, needs VITE_* env vars)
cd apps/helper && pnpm dev

Dev env vars (for browser-only development without Tauri):

VITE_API_URL=http://localhost:3001
VITE_AGENT_TOKEN=brz_<token>
VITE_AGENT_ID=<device-uuid>
Bundle Targets
PlatformFormat
macOSDMG (/Applications/Breeze Helper.app)
WindowsMSI via WiX (C:\Program Files\Breeze Helper\breeze-helper.exe)
LinuxAppImage (/usr/local/bin/breeze-helper)

Key Dependencies

Rust: tauri v2, reqwest (mTLS), tokio, serde/serde_yaml, chrono, whoami TypeScript: React 18.3, Zustand 4.5, react-markdown 10, @tauri-apps/api 2.0

Data Flow: Chat Message

1. User types in chat input (App.tsx)
2. chatStore.sendMessage(content)
   → Creates session via POST /helper/chat/sessions (if needed)
   → Adds optimistic user message
   → helperStreamRequest() to POST /helper/chat/sessions/:id/messages
3. In Tauri: helper_fetch (Rust) → mTLS HTTP request → SSE response
   → Rust spawns tokio task → emits helper-fetch-stream events
   → Frontend listener → processSSELines() → Zustand state updates
4. API: helperAuth → runHelperPreFlight → streamingSessionManager
   → Claude API call with org-scoped tools
   → SSE events: message_start → content_delta → tool_use_start → tool_result → done
5. Tool approval (if Tier 3): approval_required event → ToolApprovalPopup
   → User Allow/Deny → POST /approve/:executionId → tool executes or rejects

Logging

Helper logs to helper.log in the config directory (alongside agent.yaml). In SYSTEM service context, stderr isn't connected to anything visible, so log_helper_error() appends timestamped lines to this file.

Gotchas

  • WebView2 data dir: On Windows SYSTEM, must redirect to %ProgramData%\Breeze\helper-webview\ or WebView2 init fails
  • Stream listener race: Must register Tauri event listener BEFORE invoking helper_fetch — reverse proxies (Caddy) can buffer entire SSE response and deliver at once
  • Tray click events: Only match Left + Up — matching all click variants steals focus from context menu on Windows
  • 409 on concurrent messages: streamingSessionManager.tryTransitionToProcessing prevents parallel processing; frontend removes optimistic message on 409
  • Plan events: plan_approval_required, plan_step_start, etc. received but not rendered yet

© LanternOps, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/breeze-helper of LanternOps/breeze.

Open the folder on GitHubat commit 5a2d714

Compare with similar skills

Breeze Helper next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Breeze Helper compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Breeze Helper this skillLanternOps/breeze131—~3.2kAutomated safety check: PassAGPL-3.0
Reactflow Workflowveloxbase/veloxdb646—~897Automated safety check: PassMIT
I18nhuoshen80/ReinaManager693—~177Automated safety check: PassAGPL-3.0
Frontend Testhuoshen80/ReinaManager693—~180Automated safety check: PassAGPL-3.0
Store Managementbkywksj/knowledge-base330—~1.2kAutomated safety check: PassCustom licence
Electronmajiayu000/claude-skill-registry6661 repos~2.9kAutomated safety check: PassMIT

Similar skills

  • Reactflow Workflow

    veloxbase/veloxdb

    Build and harden React Flow diagram surfaces in VeloxDB using @xyflow/react patterns (nodes, edges, viewport, controls, interactions, performance).

    646 GitHub stars~897 tokensUpdated 8 days ago
    Frontend & DesignAuto-check passed
  • I18n

    huoshen80/ReinaManager

    使用 i18next-cli 检查、同步和整理本项目的国际化资源。涉及新增、修改、删除翻译键或国际化字符串,以及修复缺失翻译时使用。

    693 GitHub stars~177 tokensUpdated 5 days ago
    Frontend & DesignAuto-check passed
  • Frontend Test

    huoshen80/ReinaManager

    在 ReinaManager 项目内进行隔离前端验证,复用测试目录并回收测试资源。需要模拟批量数据、延迟、失败或交互回归时使用。

    693 GitHub stars~180 tokensUpdated 5 days ago
    Frontend & DesignAuto-check passed
  • Store Management

    bkywksj/knowledge-base

    Tauri 状态管理技能,覆盖 React 前端状态和 Rust 后端状态管理. An agent skill from bkywksj/knowledge-base.

    330 GitHub stars~1.2k tokensUpdated 6 days ago
    Frontend & DesignAuto-check passed
  • Electron

    majiayu000/claude-skill-registry

    A skill your agent uses when building, hardening, or shipping a cross-platform Electron desktop app — main/renderer/preload process model, typed contextBridge IPC, locking down…

    666 GitHub starsUsed in 1 repo~2.9k tokens
    Frontend & DesignAuto-check passed
  • Cut Release

    delexw/claude-code-trace

    Cuts a new versioned release of claude-code-trace end-to-end without asking any questions.

    377 GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed

More from LanternOps/breeze

All 14 skills in this repo
  • Agent Info

    LanternOps/breeze

    Quick reference for the Breeze RMM Go agent architecture, commands, configuration, build process, and data flows.

    131 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Agent Log Debugging

    LanternOps/breeze

    A skill your agent uses when debugging agent issues, investigating agent errors, checking agent connectivity, or reviewing agent diagnostic logs.

    131 GitHub stars~1.6k tokensUpdated today
    Auto-check: notes
  • AI Agent

    LanternOps/breeze

    Quick reference for the Breeze RMM AI Agent system architecture, MCP tools, streaming chat, cost tracking, guardrails, and MCP server.

    131 GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • E2E Coverage

    LanternOps/breeze

    A skill your agent uses when running a broad manual/AI-driven end-to-end verification of Breeze RMM across many merged PRs or commits — "test everything since the last release", release-readiness…

    131 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Feature Delivery

    LanternOps/breeze

    A skill your agent uses when orchestrating Breeze implementation work from this seat — dispatching waves or issue fixes to background sessions, deciding whether an open PR gets merged, handling a…

    131 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Gh Queue

    LanternOps/breeze

    A skill your agent uses when reviewing, triaging, or managing the incoming GitHub backlog on the Breeze repo — PRs, Discussions, AND Issues.

    131 GitHub stars~5k tokensUpdated today
    Auto-check passed

Works with

Questions about Breeze Helper

What does Breeze Helper do?

Quick reference for the Breeze Helper Tauri desktop app — architecture, Rust backend commands, React frontend, config files, IPC with the Go agent, helper chat API routes, tool approval flow, and…. Breeze Helper is an agent skill from LanternOps/breeze. Quick reference for the Breeze Helper Tauri desktop app — architecture, Rust backend commands, React frontend, config files, IPC with the Go agent, helper chat API routes, tool approval flow, and tray integration.

When should I use Breeze Helper?

Breeze Helper fits situations like: working on helper code; debugging helper issues; adding helper features; understanding how the Helper communicates with the API and agent.

How do I install Breeze Helper in Claude Code?

Run `npx skills add LanternOps/breeze --skill breeze-helper -a claude-code`. Or copy the skill folder (.claude/skills/breeze-helper in LanternOps/breeze) into .claude/skills/breeze-helper in your project. Claude Code loads it when a task matches its description.

How do I install Breeze Helper in Codex?

Run `npx skills add LanternOps/breeze --skill breeze-helper -a codex`. Or copy the skill folder (.claude/skills/breeze-helper in LanternOps/breeze) into .agents/skills/breeze-helper in your project. Codex loads it when a task matches its description.

Can I use Breeze Helper in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LanternOps/breeze --skill breeze-helper -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/breeze-helper, .gemini/skills/breeze-helper, .github/skills/breeze-helper and .opencode/skills/breeze-helper in your project.

What does Breeze Helper need to run?

Going by SKILL.md and its folder, Breeze Helper needs the command-line tools its instructions call (pnpm) and credentials named VITE_AGENT_TOKEN. Our summary lists: A credential in VITE_AGENT_TOKEN.

Does Breeze Helper access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Breeze Helper safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Breeze Helper use?

Breeze Helper is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Breeze Helper use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Breeze Helper?

Skills that share tags, products or a category with Breeze Helper: Reactflow Workflow (veloxbase/veloxdb, 646 stars), I18n (huoshen80/ReinaManager, 693 stars), Frontend Test (huoshen80/ReinaManager, 693 stars) and Store Management (bkywksj/knowledge-base, 330 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Breeze Helper?

LanternOps (a GitHub organization) maintains it in LanternOps/breeze, which has 131 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 8, 2026.

Source: LanternOps/breeze on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.