tauri-mcp-bridge
Warn
Audited by Socket on Mar 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The MCP bridge documentation describes a powerful remote-control surface for a running Tauri app, with significant supply-chain and operational risk if deployed in production without proper safeguards. Key gaps include lack of authentication/authorization for WebSocket access, potential exposure of sensitive data via webview and logs, and default binding to all interfaces. Recommend limiting exposure (localhost binding, explicit auth), enforcing production guards, and providing a secure, auditable workflow before any deployment beyond development environments.
Confidence: 61%Severity: 68%
Audit Metadata