TauriBLOCK
A Model Context Protocol (MCP) server and plugin for Tauri v2 development
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Give your AI assistant superpowers for Tauri development
[](https://www.npmjs.com/package/@hypothesi/tauri-mcp-server) [](https://crates.io/crates/tauri-plugin-mcp-bridge) [](LICENSE) [](https://v2.tauri.app)
Documentation · Getting Started · Available Tools
A Model Context Protocol (MCP) server that enables AI assistants like Claude, Cursor, and Windsurf to build, test, and debug Tauri® v2 applications. Screenshots, DOM state, and console logs from your running app give the AI rich context to understand what's happening—and tools to interact with it.
✨ Features
Disclaimer: This MCP was developed using agentic coding tools. It may contain bugs.
🚀 Quick Start
Prerequisites
- Node.js 20+ and npm
- Rust and Cargo (for Tauri development)
- Tauri CLI:
npm install -g @tauri-apps/cli@next - For mobile: Xcode (macOS) or Android SDK
1. Configure Your AI Assistant
Use aix
62706a7fc780OBSERVED · 2026-10-05Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add tauri-mcp-server -- npx -y @hypothesi/tauri-mcp-server@None
Exposed tools (23)
18 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
driver_session | write | [Tauri Apps Only] Start/stop automation session to connect to a RUNNING Tauri app. |
fix-webview-errors | read | [Tauri Apps Only] Find and fix JavaScript errors in a running Tauri app. |
get_setup_instructions | read | Get instructions for setting up or updating the MCP Bridge plugin in a Tauri project. |
ipc_emit_event | read | [Tauri Apps Only] Emit a Tauri event to test event handlers. |
ipc_execute_command | write | [Tauri Apps Only] Execute Tauri IPC commands (invoke Rust backend functions). |
ipc_get_backend_state | read | [Tauri Apps Only] Get Tauri backend state: app metadata, Tauri version, environment. |
ipc_get_captured | read | [Tauri Apps Only] Get captured Tauri IPC traffic (requires ipc_monitor started). |
ipc_monitor | read | [Tauri Apps Only] Monitor Tauri IPC calls between frontend and Rust backend. |
list_devices | read | [Tauri Mobile Apps Only] List Android emulators/devices and iOS simulators. |
manage_window | read | [Tauri Apps Only] Manage Tauri windows. Actions: |
message | read | What you want to discuss or do with the selected element |
read_logs | read | [Tauri Apps Only] Read logs from various sources: |
select | read | Visually select an element in the running Tauri app. |
setup | write | Set up or update the MCP Bridge plugin in a Tauri project. |
webview_dom_snapshot | read | [Tauri Apps Only] Get a structured DOM snapshot of a Tauri app\ |
webview_execute_js | write | [Tauri Apps Only] Execute JavaScript in a Tauri app\ |
webview_find_element | read | [Tauri Apps Only] Find elements in a running Tauri app\ |
webview_get_pointed_element | read | [Tauri Apps Only] Retrieves element metadata for an element the user previously |
webview_interact | read | [Tauri Apps Only] Click, hover, right-click, scroll, swipe, focus, or perform gestures in a Tauri app webview. |
webview_keyboard | write | [Tauri Apps Only] Type text or send keyboard events in a Tauri app. |
webview_screenshot | read | [Tauri Apps Only] Screenshot a running Tauri app\ |
webview_select_element | read | [Tauri Apps Only] Activates an element picker overlay in the Tauri app. |
webview_wait_for | read | [Tauri Apps Only] Wait for elements, text, or IPC events in a Tauri app. |
Trust audit
BLOCKgrade D · trust 64/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (15)
exec(`git add ${pkg.path}/Cargo.toml ${pkg.path}/package.json ${pkg.path}/CHANGELOG.md`, rootDir);exec(`git commit -m "chore(${pkg.githubTag}): release v${version}"`, rootDir);exec(`git tag -a ${tag} -m "Release ${pkg.name} v${version}"`, rootDir);gradle-wrapper.jar
icon.icns
.browserslistrc
import { getTestAppPort } from '../../mcp-server/tests/test-utils.js';const rootReadmePath = path.join(currentDirPath, '../../../README.md');
import { manageDriverSession } from '../../src/driver/session-manager';import { domSnapshot } from '../../src/driver/webview-interactions';import { manageDriverSession } from '../../src/driver/session-manager';@silvermine/eslint-config
@tanstack/intent
@tauri-apps/api, typescript
@tauri-apps/api, @tauri-apps/plugin-dialog, @tauri-apps/plugin-opener
Gates applied: no_behavioural_pass.
62706a7fc780full audit observations/trust-audit/mcp-server/hypothesi__tauri.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | 62706a7fc780 | BLOCK | D | 64 | first audit |
Questions
What is the Tauri MCP server?
A Model Context Protocol (MCP) server and plugin for Tauri v2 development
What tools does Tauri expose?
23 in total: 18 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Tauri safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (64/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Tauri need?
No credential environment variables were found in its source, so it appears to need none.
How does Tauri run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as test-app at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (62706a7fc780), read on 2026-10-05. The repository is watched and re-audited when it changes.