Tauri app shell — secure command execution and open behavior
Guidance for the Tauri v2 shell plugin — allow-execute/allow-open capabilities, strict command allowlists and argument control; flagged as high-risk, requiring strict permission control
- What
- Guidance for the Tauri v2 shell plugin — allow-execute/allow-open capabilities, strict command allowlists and argument control; flagged as high-risk, requiring strict permission control
- Cost
- Free
- Needs
- a Tauri v2 project needing command execution or external link opening — the skill is a workflow guide the agent follows, not software
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @full-stack-skills' tauri-app-shell skill: guidance for the Tauri v2 shell plugin — identifying command and open requirements with allowed targets, configuring allow-execute and allow-open capabilities, applying strict allowlist or regex constraints for arguments, and validating behavior across platforms and error handling, with links to the official v2.tauri.app shell docs. It produces a shell capability allowlist plan and a safe execution/open policy, with a declared boundary (shell plugin capability and usage patterns only) — and the skill itself flags the shell plugin as high-risk, requiring strict permission control. Honest caveats: guidance sections are bilingual English/Chinese and distinct per skill; the gotchas/workflow tail is a shared template across the tauri-app-* series; misconfigured shell capabilities are genuinely dangerous — review the generated capability files yourself. Apache-2.0 licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: a Tauri v2 project needing command execution or external link opening — the skill is a workflow guide the agent follows, not software Install "Tauri app shell — secure command execution and open behavior" for me. It gives my agent @full-stack-skills' shell guidance: identify command and open requirements with allowed targets, configure allow-execute and allow-open capabilities, apply strict allowlist or regex constraints for arguments, and validate cross-platform behavior and error handling — producing a shell capability allowlist plan and a safe execution/open policy, with links to the official v2.tauri.app shell docs. The shell plugin is high-risk: strict permission control required; review generated capability files myself. Apache-2.0 licensed. Repository: https://github.com/full-stack-skills/tauri-skills/blob/main/skills/tauri-app-shell/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "tauri-app-shell". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. review the capability allowlist the agent generates for my project — shell capabilities are high-risk; nothing else — it's a methodology). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.