Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Desktop Shell

ASecurity

Use for the Quickshell QML/JavaScript UI and Python helper under symlinks/config/quickshell/: bars, popups, workspace layout, shared state, and network actions. Not for Rust CLI output, shell bootstrap, or unrelated application configuration.

3 stars
0 votes
0 copies
0 views
Added 9/20/2026
developmentjavascriptpythonrustjavashellreacttesting

Works with

cli

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add sneivandt/dotfiles --skill desktop-shell --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Desktop Shell?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Desktop Shell
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/sneivandt-desktop-shell/badge)](https://www.skillsdirectory.com/skills/sneivandt-desktop-shell)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: desktop-shell
description: >
  Use for the Quickshell QML/JavaScript UI and Python helper under
  symlinks/config/quickshell/: bars, popups, workspace layout, shared state,
  and network actions. Not for Rust CLI output, shell bootstrap, or unrelated
  application configuration.
---

# Desktop Shell

## Find the owner

Paths below are relative to
[`symlinks/config/quickshell/`](../../../symlinks/config/quickshell/).

| Change | Start with |
|---|---|
| screen instances, shared services, open-menu coordination | `shell.qml` |
| per-monitor bar and service bindings | `Bar.qml` |
| workspace visibility, title sizing | `WorkspaceGroup.qml` and `tests/tst_WorkspaceGroup.qml` |
| calendar layout, local/UTC selection | `CalendarContent.qml`, `CalendarMenu.qml` |
| volume thumb, track, and input behavior | `VolumeSlider.qml`, `VolumeMenu.qml` |
| palette, typography, spacing, animation | `Theme.js` |
| popup geometry, focus, dismissal | `ShellPopup.qml` |
| reusable controls | `BarBlock.qml`, `MenuButton.qml`, `MenuIconButton.qml` |
| service queries and actions | `AudioState.qml`, `NetworkState.qml`, `MarketState.qml` |
| NetworkManager protocol and parsing | `network_helper.py`, `network_helper_test.py` |

## Preserve reactive behavior

- Reuse shared state objects instead of starting a poller for every screen or
  popup. Keep service logic out of presentation delegates.
- Calendar and bar clocks receive the shared date from `shell.qml`. Keep
  calendar highlighting and month arithmetic in the selected local/UTC zone.
- Pass dependencies through declared properties; keep extracted visual components
  independent of the live compositor where practical.
- Preserve per-monitor workspace behavior, transient missing model entries, and
  null service objects. Derive geometry from state rather than adding timers to
  hide deferred-layout glitches.
- Reuse the popup's stable Wayland buffer and animation/focus lifecycle. Preserve
  Escape, outside-click dismissal, menu switching, screen bounds, and scrolling.
- Use theme tokens and existing controls. Keep accessible names, keyboard
  activation, focus indication, and disabled/busy behavior when changing controls.

## Keep actions explicit

- Use argument-vector processes, not shell interpolation of device names, SSIDs,
  window titles, or other external values.
- Keep the network helper's structured JSON protocol in sync with QML consumers.
  Preserve `ok`/error handling, subprocess timeouts, and escaped `nmcli` fields.
- Send credentials through the existing stdin path, not command arguments or
  logs. Use only synthetic credentials in fixtures; never expose real ones in
  screenshots. Clear transient credential state after use.
- Distinguish unavailable state from disconnected or empty state; show failures
  rather than claiming an action succeeded. Prevent overlapping actions and
  refresh after completion.

## Validate without disrupting the session

Use the offscreen QML and mocked Python commands in
[Desktop shell testing](../../../docs/TESTING.md#desktop-shell), choosing only
the affected suite. Cover long/empty labels, narrow screens, multi-monitor and
out-of-order model updates for layout changes.

Offscreen tests do not prove live Wayland rendering or focus behavior. Do not
switch real workspaces, change connectivity, or restart the shell just to test a
patch without permission. Editing a symlinked source may itself trigger reload;
keep changes coherent and avoid temporary broken configurations.

Attribution

sneivandtsneivandt
View sourceMore from sneivandt →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

281612 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2132 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

9881 votes

Pentest

PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

5491 votes
View all in development →