Multi-engine AI coding desktop client (Tauri). Claude Code, Codex, Gemini, OpenCode, DeepSeek Harness and more in one GUI.
# Add to your Claude Code skills
git clone https://github.com/zhukunpenglinyutong/desktop-cc-guiGuides for using cli tools skills like desktop-cc-gui.
Last scanned: 8/17/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@chevrotain/cst-dts-gen: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@chevrotain/gast: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@excalidraw/excalidraw: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@excalidraw/mermaid-to-excalidraw: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@hono/node-server: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@mermaid-js/parser: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xmldom/xmldom: xmldom: Uncontrolled recursion in XML serialization leads to DoS",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "high"
},
{
"type": "npm-audit",
"message": "chevrotain: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "dompurify: DOMPurify contains a Cross-site Scripting vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to host confusion via literal backslash authority delimiter",
"severity": "high"
},
{
"type": "npm-audit",
"message": "flatted: flatted vulnerable to unbounded recursion DoS in parse() revive phase",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono: ReDoS in CORS middleware via Access-Control-Request-Headers",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "immutable: Immutable.js `List` 32-bit trie overflow → unrecoverable DoS",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
"severity": "high"
},
{
"type": "npm-audit",
"message": "langium: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "lodash-es: lodash vulnerable to Code Injection via `_.template` imports key names",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mermaid: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "nanoid: Predictable results in nanoid generation when given non-integer values",
"severity": "high"
},
{
"type": "npm-audit",
"message": "pdfjs-dist: PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF ",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "high"
},
{
"type": "npm-audit",
"message": "rollup: Rollup 4 has Arbitrary File Write via Path Traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "undici: undici vulnerable to downstream response desynchronization via retry interceptor",
"severity": "high"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vitest: When Vitest UI server is listening, arbitrary file can be read and executed",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "high"
},
{
"type": "npm-audit",
"message": "xlsx: Prototype Pollution in sheetJS",
"severity": "high"
}
],
"status": "FAILED",
"scannedAt": "2026-08-17T04:40:47.280Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how desktop-cc-gui compares with popular alternatives.
desktop-cc-gui is an open-source cli tools skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by zhukunpenglinyutong. Multi-engine AI coding desktop client (Tauri). Claude Code, Codex, Gemini, OpenCode, DeepSeek Harness and more in one GUI. It has 4,188 GitHub stars.
desktop-cc-gui failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/zhukunpenglinyutong/desktop-cc-gui" and add it to your Claude Code skills directory (see the Installation section above).
desktop-cc-gui is primarily written in TypeScript. It is open-source under zhukunpenglinyutong on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other CLI Tools skills you can browse and compare side by side. Open the CLI Tools category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh desktop-cc-gui against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
English · 简体中文
![][github-contributors-shield] ![][github-forks-shield] ![][github-stars-shield] ![][github-issues-shield]
ccgui is an open-source multi-engine AI coding desktop client. In plain words: it brings command-line AI coding runtimes — Claude Code, Codex CLI, Kimi CLI, Grok CLI, Pi CLI, OMP CLI, and DeepSeek Harness (DSH) — into one graphical interface.
No more staring at a black terminal. Open ccgui, pick a project, and chat with AI to write code, fix bugs, and commit to Git. Streaming output, thinking traces, and tool calls are visible as they happen; token usage appears when the engine reports it.
The app is built with Tauri 2 + React 18 + TypeScript + Rust and runs on macOS, Windows, and Linux. Settings and state are persisted locally. Content sent to an AI provider follows the boundary of the channel you configured for that CLI.
.gitignore-aware project file index; file links in replies handle URL-encoded paths and have a right-click menu.@ccgui/plugin-sdk) plus an in-app runtime, manager UI, and trust boundary.Grab the installer for your platform from the Releases page:
| Platform | Installer |
|---|---|
| macOS (Apple Silicon, signed) | aarch64.dmg |
| Windows | .exe (NSIS) |
| Linux | .AppImage |
After installing, open Settings, configure a provider channel for the CLI you want (or sign in), add a project folder, and start chatting.
dsh web host or auto-start one.Want to build it yourself or contribute? Three steps.
| Tool | Version | What for |
|---|---|---|
| Node.js | 20 or newer | Runs the frontend toolchain |
| pnpm | 10 (pinned via packageManager) |
Installs dependencies |
| Rust | stable (install via rustup) | Compiles the backend |
Each OS also needs the standard Tauri prerequisites — see the official Tauri guide:
xcode-select --install.webkit2gtk and friends — copy the commands from the Tauri docs.git clone https://github.com/zhukunpenglinyutong/desktop-cc-gui.git
cd desktop-cc-gui
pnpm install
Note: this is a pnpm workspace (the plugin SDK lives in packages/plugin-sdk); the lockfile is pnpm-lock.yaml.
pnpm dev
A few tips:
1420.pnpm build:mac # macOS signed build (scripts/build-signed-macos.sh)
pnpm build:mac:skip-notarize # same, skipping notarization
Windows and Linux installers are produced by the CI workflows under .github/workflows/ (release.yml, build-windows-artifact.yml).
| Part | Technology |
|---|---|
| UI | React 18 + TypeScript + Tailwind CSS 4 + zustand |
| Build | Vite 6 |
| Desktop shell | Tauri 2 (Rust backend: git2, rusqlite, portable-pty, axum) |
| Tests | Vitest (frontend) + cargo test (Rust) |
desktop-cc-gui/
├── src/ # Frontend code
│ ├── features/ # ★ Feature modules: chat / files / git / terminal /
│ │ # settings / plugins / commands / update / open-app
│ ├── components/ # Shared UI components (incl. engine brand icons)
│ ├── i18n/ # zh + en locale bundles
│ ├── styles/ # Global styles
│ └── lib/ utils/ # Utility functions
├── src-tauri/ # Rust backend
│ └── src/ # engine/ (one module per CLI), history/, plugins/,
│ # git.rs, terminal.rs, web.rs (LAN bridge), ...
├── packages/plugin-sdk/ # @ccgui/plugin-sdk — plugin authoring kit
├── tests/ # Frontend integration-style tests (Vitest)
├── scripts/ # Build and packaging scripts
└── docs/ # Plugin development guide, engine mode notes
src/features/ and edit there. New components live inside that feature's own folder.#[tauri::command] in the matching src-tauri/src/ module and call it from the frontend via the Tauri API.src/i18n/zh.ts, src/i18n/en.ts) synchronized — hardcoded UI text is not allowed.| Command | What it does |
|---|---|
pnpm dev |
Start the full app (Tauri dev mode) |
pnpm build |
TypeScript check + frontend production build |
pnpm test |
Run the Vitest suite |
pnpm preview |
Preview the production frontend build |
cargo test --manifest-path src-tauri/Cargo.toml |
Run Rust tests |
xxx.test.ts(x) files next to the source, plus heavier suites under tests/.cargo test --manifest-path src-tauri/Cargo.toml.Not many rules, but each exists for a reason:
pnpm build (typecheck) and pnpm test green locally, plus cargo test if you touched Rust.src/i18n/, and both shipped locale bundles must stay synchronized.src/components/ only once they're genuinely reused across features.