Agent Skillsopenchamber/openchamber › desktop-shell

desktop-shell

GitHub

规范 Electron 桌面端开发,涵盖主进程与预加载脚本修改、IPC 安全边界、后台进程管理及打包生命周期。指导如何正确处理原生窗口、菜单、更新及深度链接,确保渲染层不获取本地特权,并提供验证步骤。

.agents/skills/desktop-shell/SKILL.md openchamber/openchamber

Trigger Scenarios

修改 Electron main/preload 代码 实现桌面 IPC 通信 处理原生窗口、菜单或对话框 配置应用更新行为 管理深度链接或 SSH 隧道 启动子进程或处理 Windows 进程生成

Install

npx skills add openchamber/openchamber --skill desktop-shell -g -y
More Options

Non-standard path

npx skills add https://github.com/openchamber/openchamber/tree/main/.agents/skills/desktop-shell -g -y

Use without installing

npx skills use openchamber/openchamber@desktop-shell

指定 Agent (Claude Code)

npx skills add openchamber/openchamber --skill desktop-shell -a claude-code -g -y

安装 repo 全部 skill

npx skills add openchamber/openchamber --all -g -y

预览 repo 内 skill

npx skills add openchamber/openchamber --list

SKILL.md

Frontmatter
{
    "name": "desktop-shell",
    "description": "Use when changing Electron main\/preload code, desktop IPC, native windows, menus, dialogs, notifications, updater behavior, deep links, SSH or tunnels, child processes, packaged startup, or Windows process spawning."
}

Desktop Shell

Required Context

Read packages/electron/README.md and nearby packages/electron code before editing. Context gathering is complete when each changed behavior is assigned to main, preload, renderer/shared UI, or web/runtime ownership.

Load ui-api-decoupling when a native change adds or alters a renderer-facing capability, RuntimeAPIs, runtime auth/URL behavior, or shared bridge contract. This skill owns the Electron privilege boundary; ui-api-decoupling owns the shared UI/runtime contract.

Runtime Boundary

  • Electron boots @openchamber/web in the same Node process and loads the UI over loopback. Do not introduce a sidecar server process.
  • Keep renderer contracts and domain logic in packages/ui, server behavior in packages/web, and Electron focused on inherently native behavior: windows, menus, dialogs, notifications, updater, deep links, runtime host switching, privileged IPC, SSH, and tunnel lifecycle.
  • Electron is the desktop release target.

IPC And Security

  1. Add a preload bridge shape only when renderer-facing capability changes.
  2. Handle the native operation in main.mjs.
  3. Gate privileged commands in the main process; renderer checks are not security boundaries.
  4. Expose the narrowest payload and never expose filesystem, shell, tokens, or host secrets to remote pages.
  5. Do not import Electron from shared UI code.

Remote runtime pages must not gain local desktop privileges. Treat deep links, host imports, stored credentials, and runtime switching as trust-boundary operations.

Windows Background Processes

Non-user-visible child processes must never flash a console window.

  • Spawn the target executable directly with windowsHide: true.
  • Use stdio: 'ignore' for detached/background helpers and call unref() when they must outlive Electron.
  • Avoid cmd.exe /c, batch shims, taskkill, ping delays, and pipelines that create console grandchildren. windowsHide reliably controls only the directly spawned process.
  • Prefer native Node/Electron APIs when available.
  • For delayed work that must survive app exit, spawn one first-level hidden helper, such as powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -EncodedCommand ...; perform delay and work inside that process with cmdlets.
  • Omit hidden-process behavior only for intentionally user-visible terminals or applications.

Packaging And Lifecycle

  • Keep native/external modules configured according to packages/electron/README.md and bundle-main.mjs.
  • Preserve startup, quit, updater, notification, and deep-link behavior across development and packaged builds.
  • Ensure cleanup tolerates partial startup and repeated shutdown signals.
  • Do not infer readiness from stdout when an in-process callback or returned server handle exists.

Validation

Run focused Electron tests and package checks. For startup, preload, routing, or packaging changes, completion requires both HMR development and bundled UI validation. For Windows process work, completion requires inspection of the complete process tree with no console flash; command success alone is insufficient.

Version History

  • 2db90f7 Current 2026-08-20 04:54

    细化上下文获取要求,明确运行时边界与 UI API 解耦规范,补充验证流程。

  • 74b1bd8 2026-07-25 10:36

Same Skill Collection

.agents/skills/changelog-authoring/SKILL.md
.agents/skills/clack-cli-patterns/SKILL.md
.agents/skills/communication-style/SKILL.md
.agents/skills/drag-to-reorder/SKILL.md
.agents/skills/locale-ui-patterns/SKILL.md
.agents/skills/openchamber-change-discipline/SKILL.md
.agents/skills/performance-engineering/SKILL.md
.agents/skills/pr-review/SKILL.md
.agents/skills/relay-transport/SKILL.md
.agents/skills/serve-sim/SKILL.md
.agents/skills/settings-ui-patterns/SKILL.md
.agents/skills/sync-state-invariants/SKILL.md
.agents/skills/theme-system/SKILL.md
.agents/skills/triage-prs/SKILL.md
.agents/skills/ui-api-decoupling/SKILL.md
.agents/skills/writing-for-agents/SKILL.md

Metadata

Files
0
Version
fb7119a
Hash
683a93d2
Indexed
2026-07-25 10:36

Home - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-29 03:13
浙ICP备14020137号-1 $Map of visitor$