since this is for security: I'm quite uncomfortable with the way APIs are exposed to the browser instance that does the UI rendering. As far as I can see from the code, extremely sensitive functions such as 'execute' are attached directly to the window [1][4], then they are invoked by postMessaging into the topmost window [2][3]. This makes XSS in essence immediate remote code execution, but more pointedly it voids some of the security guarantees about iframes, which can assumedly use window.top.postMessage() to post the 'execute' call directly to the browser. If you're developing, e.g. a chat app, you might use iframes to support, for example OEMBED -- and then even codepen oembeds may well be able to execute code.
I like this direction for applications, but browser security protocols are a nightmare to replicate properly.
I recommend using pre-existing interfaces for launching apps like custom scheme URIs, or if really necessary writing individual handlers for the heavy lifting. I think the postMessage approach is great, too but it's vital that the caller `origin` is checked. The web app shouldn't need to run arbitrary commands on the computer.
[1]: https://github.com/tauri-apps/tauri/blob/2681ad361b4295756be...
[2]: https://github.com/tauri-apps/tauri/blob/015474657c955c7ad29...
[3]: https://github.com/tauri-apps/tauri/blob/c8f430297f95df16216...
[4]: https://github.com/tauri-apps/tauri/blob/c8f430297f95df16216...