hecate-tauri

hecate-tauri is a skill for Claude Code, Codex from hecatehq/hecate. It costs 49 tokens per session (10,183 once invoked), scanned A, original, MIT.

A project-specific guide for the Hecate native desktop app and its Tauri 2.x code. It covers the Rust desktop layer, companion-process lifecycle, platform packaging, and communication between the local gateway and the embedded web view.

In plain words
What is it for?
Use it when working inside the Hecate app's tauri/ directory, especially for Rust changes, packaging, process startup, or gateway-to-interface integration.
Why use it?
It gives developers the project context needed to change the desktop app without breaking how its native and web parts start and connect.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it when working inside the Hecate app's tauri/ directory, especially for…

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/hecatehq/hecate/tauri
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add hecatehq/hecate --skill tauri
Clone the repo
git clone --depth 1 https://github.com/hecatehq/hecate

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for hecate-tauri

README.md
[![agentmods](https://agentmods.dev/badge/skills/hecatehq/hecate/tauri.svg)](https://agentmods.dev/skills/hecatehq/hecate/tauri)
Your own site
<a href="https://agentmods.dev/skills/hecatehq/hecate/tauri"><img src="https://agentmods.dev/badge/skills/hecatehq/hecate/tauri.svg" alt="Measured on agentmods" height="20"></a>
Per session 49 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 10,183 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00049 $0.10183
Opus 5 $0.00024 $0.05091
Sonnet 5 $0.00010 $0.02037
Haiku 4.5 $0.00005 $0.01018

Measured 7d ago against content hash f4b30545bc91, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

hecate-tauri scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

docs-ai/skills/tauri/SKILL.md · 469 lines

How it starts

The opening of the file, as written. The whole thing — 469 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Hecate Tauri skill

Use this skill for any work inside tauri/. Gateway changes use ../backend/SKILL.md; UI changes use ../ui/SKILL.md.

Operator-facing companion: ../../../docs/operator/desktop-app.md — distribution, current state, roadmap, footguns. When this skill grows a footgun an end user might hit, mirror it there.

Canonical guidance lives here

Architecture in one paragraph

The Tauri app is a thin chrome-frame around the main Hecate runtime running in gateway mode. On launch the Rust layer allocates a free loopback port, spawns the hecate binary as a companion process (not a Tauri shell-plugin sidecar — see gotchas), polls /healthz until the gateway is healthy, then navigates the webview to http://127.0.0.1:{port}/. The gateway serves its own embedded React UI. No second frontend build, no API bridge, no Vite dev server required.

Why we keep //go:embed instead of frontendDist

Most Tauri apps point tauri.conf.jsonfrontendDist: "../ui/dist" and let the webview load UI files directly from the bundled app. We don't, on purpose:

  • Same-origin loopback surface. The webview loads from http://127.0.0.1:{port}/ and the API is at http://127.0.0.1:{port}/v1/.... Same origin means no CORS dance and no Tauri IPC bridge. Splitting UI (tauri://localhost) from API (127.0.0.1:{port}) breaks that property and requires a meaningful security refactor to restore.
  • Hecate-sidecar property. The same hecate runtime binary ships through Docker, the goreleaser tarballs, and the Tauri sidecar. The embed makes that work without conditional builds or runtime path resolution. Reading ui/dist from disk inside a bundled .app would require a working-dir-independent resolver and a new "UI files missing" failure mode.
  • Bundle-size cost is negligible. The built UI is ~730 KB on disk (~200 KB gzipped over the wire). Embedding it adds ~2% to the hecate binary (32 MB → 33 MB) and ~1 MB to the .dmg. Desktop apps routinely ship at 100+ MB; this isn't even close to a constraint, and any "ship a UI-less variant" optimization would save kilobytes for a meaningful maintenance cost.

Read the full file on GitHub · 469 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 7d ago First seen · 469 lines · 49 tokens per session scan A f4b30545bc91

Subscribe to this mod's changes

hecate-tauri is a skill published in the GitHub repository hecatehq/hecate (22 stars, last pushed 4d ago), licensed MIT. It adds 49 tokens to every session and 10,183 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

trulens-instrumentation

Instrument LLM apps with TruLens OTEL-based tracing - from setup to debugging and optimization.

truera/trulens · 25 tokens

self-host-studio

Install and self-host deco Studio (the open-source control plane) on the user's own infrastructure. Use when the user wants to install, run, self-host, or deploy Studio locally (Docker, Rancher Desktop, kind, minikube) or on Kubernetes (managed or self-managed), or asks to "install Studio", "self-host decocms"…

decocms/studio · 117 tokens

slides

Create and edit presentation decks as single self-contained HTML files with a live, editable preview and print-to-PDF export. Use when the user wants slides, a deck, or a presentation.

decocms/studio · 40 tokens

brand

Create and maintain an org's brand as a folder the whole platform reads: colors, type, voice, logo and a deck theme. Use this whenever someone asks to "set up our brand", "make a brand kit", "apply our colors/fonts", or before producing branded artifacts (decks, pages, emails). One brand = one folder; everything that…

decocms/studio · 0 tokens

decocms-ui

Build or style React UI with the decocms product design system (@decocms/ui). Use when creating interfaces, pages, or components in a project that should look like decocms products, when the user mentions "design system", "@decocms/ui", "decocms style", or asks to make UI consistent with Studio. Covers installation…

decocms/studio · 91 tokens

templating

Render any text file (HTML, markdown, config, SQL, email) from a mustache template plus JSON data. Use when an output's shape is fixed ahead of time and only the values change.

decocms/studio · 44 tokens