Multi-engine AI coding desktop client (Tauri). Claude Code, Codex, Gemini, OpenCode, DeepSeek Harness and more in one GUI.
# Add to your Claude Code skills
git clone https://github.com/zhukunpenglinyutong/desktop-cc-guiGuides for using cli tools skills like desktop-cc-gui.
Last scanned: 8/17/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@chevrotain/cst-dts-gen: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@chevrotain/gast: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@excalidraw/excalidraw: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@excalidraw/mermaid-to-excalidraw: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@hono/node-server: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@mermaid-js/parser: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xmldom/xmldom: xmldom: Uncontrolled recursion in XML serialization leads to DoS",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "high"
},
{
"type": "npm-audit",
"message": "chevrotain: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "dompurify: DOMPurify contains a Cross-site Scripting vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to host confusion via literal backslash authority delimiter",
"severity": "high"
},
{
"type": "npm-audit",
"message": "flatted: flatted vulnerable to unbounded recursion DoS in parse() revive phase",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono: ReDoS in CORS middleware via Access-Control-Request-Headers",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "immutable: Immutable.js `List` 32-bit trie overflow → unrecoverable DoS",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
"severity": "high"
},
{
"type": "npm-audit",
"message": "langium: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "lodash-es: lodash vulnerable to Code Injection via `_.template` imports key names",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mermaid: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "nanoid: Predictable results in nanoid generation when given non-integer values",
"severity": "high"
},
{
"type": "npm-audit",
"message": "pdfjs-dist: PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF ",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "high"
},
{
"type": "npm-audit",
"message": "rollup: Rollup 4 has Arbitrary File Write via Path Traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "undici: undici vulnerable to downstream response desynchronization via retry interceptor",
"severity": "high"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vitest: When Vitest UI server is listening, arbitrary file can be read and executed",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "high"
},
{
"type": "npm-audit",
"message": "xlsx: Prototype Pollution in sheetJS",
"severity": "high"
}
],
"status": "FAILED",
"scannedAt": "2026-08-17T04:40:47.280Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}desktop-cc-gui is an open-source cli tools skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by zhukunpenglinyutong. Multi-engine AI coding desktop client (Tauri). Claude Code, Codex, Gemini, OpenCode, DeepSeek Harness and more in one GUI. It has 4,011 GitHub stars.
desktop-cc-gui failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/zhukunpenglinyutong/desktop-cc-gui" and add it to your Claude Code skills directory (see the Installation section above).
desktop-cc-gui is primarily written in TypeScript. It is open-source under zhukunpenglinyutong on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other CLI Tools skills you can browse and compare side by side. Open the CLI Tools category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh desktop-cc-gui against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
English · 简体中文
![][github-contributors-shield] ![][github-forks-shield] ![][github-stars-shield] ![][github-issues-shield]
ccgui is an open-source multi-engine AI coding desktop client. In plain words: it brings command-line AI coding runtimes such as Claude Code, Codex CLI, Gemini CLI, OpenCode, and DeepSeek Harness (DSH) into one graphical interface.
It is not a DSH Web UI shell and not a dsh-plugin. DSH is one of several native engines; models and API keys for DSH still live in the DSH host / Web UI, while ccgui provides the unified chat, files, Git, and project intelligence surface.
No more staring at a black terminal. Open ccgui, pick a project, and chat with AI to write code, fix bugs, and commit to Git. File and tool activity is visible as it happens; token usage and estimated cost appear when the selected runtime supplies the required metadata.
The app is built with Tauri 2 + React 19 + TypeScript + Rust and runs on macOS, Windows, and Linux. App settings, workspace indexes, and client state are persisted locally by default. Content sent to an AI provider, Browser Agent, email service, or an optional remote/web service follows the boundary of that configured service.
dsh-host-rpc): ccgui can adopt a running local dsh web host or start one, then create / resume / fork DSH sessions in the same GUI as the other engines. Models and credentials stay in DSH — this repo is not installable via dsh plugin add.@ file references, slash commands, pasted images, and attachments.@@ or explicitly enable Memory Reference retrieval for the current turn.For what changed in each release, see CHANGELOG.md.
Grab the installer for your platform from the Releases page:
| Platform | Installer |
|---|---|
| macOS (Apple Silicon) | aarch64.dmg |
| macOS (Intel) | x64.dmg |
| Windows | .exe (NSIS) |
| Linux | .AppImage |
After installing, configure your AI engine in Settings (e.g. a Claude Code API key or local CLI), add a project folder, and you're good to go.
npm i -g @deepseek-ai/dsh, or use a local binary you already have).ccgui is a multi-engine desktop client for DSH, not a plugin package and not a re-skinned official Web UI.
Want to build it yourself or contribute? Three steps.
You need these three things:
| Tool | Version | What for |
|---|---|---|
| Node.js | 20 or newer | Runs the frontend |
| Rust | stable (install via rustup) | Compiles the backend |
| CMake | any recent version | Builds some dependencies |
Each OS needs a bit of extra prep (these are Tauri framework requirements — see the official Tauri prerequisites):
xcode-select --install; get CMake via brew install cmake.webkit2gtk and friends — just copy the commands from the Tauri docs.git clone https://github.com/zhukunpenglinyutong/desktop-cc-gui.git
cd desktop-cc-gui
npm install
Note: you must use npm. pnpm and yarn are blocked by a script (so everyone gets identical dependency versions).
# macOS / Linux
npm run tauri:dev
# Windows
npm run tauri:dev:win
A few tips:
npm run doctor by itself — it tells you what's missing and how to install it.1420. Don't worry if the port is taken; the script cleans it up automatically.npm run dev runs the frontend alone in a browser (backend-dependent features won't work there).npm run build:mac-arm64 # macOS Apple Silicon
npm run build:mac-x64 # macOS Intel
npm run build:mac-universal # macOS Universal
npm run build:win-x64 # Windows x64
npm run build:linux-x64 # Linux x64
npm run build:linux-arm64 # Linux arm64
| Part | Technology |
|---|---|
| UI | React 19 + TypeScript + Tailwind CSS 4 |
| Build | Vite 7 |
| Desktop shell | Tauri 2 (Rust backend) |
| Tests | Vitest (frontend) + cargo test (Rust) |
desktop-cc-gui/
├── src/ # Frontend code
│ ├── features/ # ★ Feature modules (50+), one folder per feature — where most work happens
│ │ ├── composer/ # Input box
│ │ ├── messages/ # Message stream
│ │ ├── git/ # Git panel
│ │ ├── project-map/ # Project knowledge map
│ │ └── ... # Each folder is a self-contained feature
│ ├── components/ # Shared UI components used across features
│ ├── services/ # Business logic; services/tauri/* contains frontend↔Rust wrappers
│ ├── i18n/ # 10 shipped WebView locale bundles
│ ├── styles/ # Global styles
│ └── lib/ utils/ # Utility functions
├── src-tauri/ # Rust backend
│ └── src/ # Organized by module: engine / codex / git / terminal / files ...
├── scripts/ # Build, check, and diagnostic scripts
└── docs/ # Architecture docs, performance baselines
src/features/ and edit there. New com