Atlas / MCP servers / hypothesi / Tauri

TauriBLOCK

mcp/hypothesi/tauri

A Model Context Protocol (MCP) server and plugin for Tauri v2 development

Verdict
BLOCK
Grade
D
Trust score
64 /100
Exposed tools
23 18r · 5w · 0d
Transport
stdio
License
MIT
Stars
315
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Give your AI assistant superpowers for Tauri development

[](https://www.npmjs.com/package/@hypothesi/tauri-mcp-server) [](https://crates.io/crates/tauri-plugin-mcp-bridge) [](LICENSE) [](https://v2.tauri.app)

Documentation · Getting Started · Available Tools

A Model Context Protocol (MCP) server that enables AI assistants like Claude, Cursor, and Windsurf to build, test, and debug Tauri® v2 applications. Screenshots, DOM state, and console logs from your running app give the AI rich context to understand what's happening—and tools to interact with it.

✨ Features

Disclaimer: This MCP was developed using agentic coding tools. It may contain bugs.

🚀 Quick Start

Prerequisites

  • Node.js 20+ and npm
  • Rust and Cargo (for Tauri development)
  • Tauri CLI: npm install -g @tauri-apps/cli@next
  • For mobile: Xcode (macOS) or Android SDK

1. Configure Your AI Assistant

Use aix

Read from source at commit 62706a7fc780OBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add tauri-mcp-server -- npx -y @hypothesi/tauri-mcp-server@None
03

Exposed tools (23)

18 read · 5 write · 0 destructive.

ToolRiskDescription
driver_sessionwrite[Tauri Apps Only] Start/stop automation session to connect to a RUNNING Tauri app.
fix-webview-errorsread[Tauri Apps Only] Find and fix JavaScript errors in a running Tauri app.
get_setup_instructionsreadGet instructions for setting up or updating the MCP Bridge plugin in a Tauri project.
ipc_emit_eventread[Tauri Apps Only] Emit a Tauri event to test event handlers.
ipc_execute_commandwrite[Tauri Apps Only] Execute Tauri IPC commands (invoke Rust backend functions).
ipc_get_backend_stateread[Tauri Apps Only] Get Tauri backend state: app metadata, Tauri version, environment.
ipc_get_capturedread[Tauri Apps Only] Get captured Tauri IPC traffic (requires ipc_monitor started).
ipc_monitorread[Tauri Apps Only] Monitor Tauri IPC calls between frontend and Rust backend.
list_devicesread[Tauri Mobile Apps Only] List Android emulators/devices and iOS simulators.
manage_windowread[Tauri Apps Only] Manage Tauri windows. Actions:
messagereadWhat you want to discuss or do with the selected element
read_logsread[Tauri Apps Only] Read logs from various sources:
selectreadVisually select an element in the running Tauri app.
setupwriteSet up or update the MCP Bridge plugin in a Tauri project.
webview_dom_snapshotread[Tauri Apps Only] Get a structured DOM snapshot of a Tauri app\
webview_execute_jswrite[Tauri Apps Only] Execute JavaScript in a Tauri app\
webview_find_elementread[Tauri Apps Only] Find elements in a running Tauri app\
webview_get_pointed_elementread[Tauri Apps Only] Retrieves element metadata for an element the user previously
webview_interactread[Tauri Apps Only] Click, hover, right-click, scroll, swipe, focus, or perform gestures in a Tauri app webview.
webview_keyboardwrite[Tauri Apps Only] Type text or send keyboard events in a Tauri app.
webview_screenshotread[Tauri Apps Only] Screenshot a running Tauri app\
webview_select_elementread[Tauri Apps Only] Activates an element picker overlay in the Tauri app.
webview_wait_forread[Tauri Apps Only] Wait for elements, text, or IPC events in a Tauri app.
04

Trust audit

BLOCKgrade D · trust 64/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/release-package.js:161
exec(`git add ${pkg.path}/Cargo.toml ${pkg.path}/package.json ${pkg.path}/CHANGELOG.md`, rootDir);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/release-package.js:163
exec(`git commit -m "chore(${pkg.githubTag}): release v${version}"`, rootDir);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/release-package.js:168
exec(`git tag -a ${tag} -m "Release ${pkg.name} v${version}"`, rootDir);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
packages/test-app/src-tauri/gen/android/gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
packages/test-app/src-tauri/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.browserslistrc
.browserslistrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/tests/cli.test.ts:5
import { getTestAppPort } from '../../mcp-server/tests/test-utils.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/scripts/generate-tools-docs.ts:45
const rootReadmePath = path.join(currentDirPath, '../../../README.md');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/tests/e2e/dom-snapshot.test.ts:2
import { manageDriverSession } from '../../src/driver/session-manager';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/tests/e2e/dom-snapshot.test.ts:3
import { domSnapshot } from '../../src/driver/webview-interactions';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/tests/e2e/driver.test.ts:4
import { manageDriverSession } from '../../src/driver/session-manager';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@silvermine/eslint-config
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/cli/package.json
@tanstack/intent
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/tauri-plugin-mcp-bridge/package.json
@tauri-apps/api, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/test-app/package.json
@tauri-apps/api, @tauri-apps/plugin-dialog, @tauri-apps/plugin-opener
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha 62706a7fc780full audit observations/trust-audit/mcp-server/hypothesi__tauri.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0562706a7fc780BLOCKD64first audit
06

Questions

What is the Tauri MCP server?

A Model Context Protocol (MCP) server and plugin for Tauri v2 development

What tools does Tauri expose?

23 in total: 18 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Tauri safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (64/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Tauri need?

No credential environment variables were found in its source, so it appears to need none.

How does Tauri run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as test-app at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (62706a7fc780), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement