← Products

Developer tools
⚙ Needs: a Tauri v2 project whose plugin permissions need tig…

Tauri Security — capabilities, scope and ACL permission control

Least-privilege design: translate features into plugin capabilities, define scoped access rules, generate and validate capabilities/default.json, and audit runtime permissions

At a glance
What
Least-privilege design: translate features into plugin capabilities, define scoped access rules, generate and validate capabilities/default.json, and audit runtime permissions
Cost
Free
Needs
a Tauri v2 project whose plugin permissions need tightening for production
Install
Copy the installer prompt below into your Muse — your agent does the rest.

Version:

@
Created by: @full-stack-skills
⌁

Install

Prerequisites: a Tauri v2 project whose plugin permissions need tightening for production Install "Tauri Security — capabilities, scope and ACL permission control" for me. It gives my agent @full-stack-skills' permission workflow: detect capability/scope/ACL intent via trigger phrases, translate features into plugin capabilities, define scoped access rules per capability, generate and validate capabilities/default.json, and verify runtime behavior matches a minimum-privilege policy, with the official Tauri v2 security docs (capabilities, scope, ACL) as references. Apache-2.0 licensed. Repository: https://github.com/full-stack-skills/tauri-skills/blob/main/skills/tauri-security/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "tauri-security". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. describe which features the app needs so the agent can map them to capabilities and scopes; nothing else — it's a guidance skill). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.

?

Questions

How do I install a build?

Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.

Where does my money go?

Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.

What does the ✓ next to a creator’s name mean?

It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.