selkies/skills/xdg-portal/SKILL.md
XDG Desktop Portal infrastructure for Sway containers — the portal daemon, the wlroots backend (xdg-desktop-portal-wlr), and the GTK fallback — enabling screen sharing, portal screenshots, and file dialogs. Use when working with XDG desktop portals, screen-sharing, or file-dialog support inside a container.
npx skillsauth add overthinkos/overthink-plugins xdg-portalInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Provides XDG Desktop Portal support for Sway containers. Installs the portal daemon, the wlroots-specific backend (xdg-desktop-portal-wlr), and the GTK fallback backend. Enables screen sharing, screenshots via portal API, and file dialogs for applications running inside the container.
require:
- dbus
- sway
- pipewire
env:
XDG_CURRENT_DESKTOP: "sway"
rpm:
packages:
- xdg-desktop-portal
- xdg-desktop-portal-wlr
- xdg-desktop-portal-gtk
- slurp
| Property | Value |
|----------|-------|
| Depends | dbus, sway, pipewire |
| Packages | xdg-desktop-portal, xdg-desktop-portal-wlr, xdg-desktop-portal-gtk, slurp |
| Env | XDG_CURRENT_DESKTOP=sway |
| Service | None (D-Bus activation on demand) |
| Ports | None |
~/.config/sway/config.d/portal.conf which runs dbus-update-activation-environment to export WAYLAND_DISPLAY, XDG_RUNTIME_DIR, XDG_CURRENT_DESKTOP, and SWAYSOCK to the D-Bus activation environment. Without this, portal daemons can't find the Wayland display.~/.config/xdg-desktop-portal-wlr/config with chooser_type=none for headless automation (no user dialog for screen sharing).| Interface | Backend | Status | |-----------|---------|--------| | Screenshot | xdg-desktop-portal-wlr | Supported | | ScreenCast (PipeWire) | xdg-desktop-portal-wlr | Supported | | RemoteDesktop | — | NOT supported on wlroots | | File dialogs | xdg-desktop-portal-gtk | Supported (fallback) | | Settings | xdg-desktop-portal-gtk | Supported (fallback) |
sway-desktop metalayer (default for all desktop boxes)/charly-selkies:sway-browser-vnc (via sway-desktop metalayer)/charly-selkies:sway-desktop — Desktop metalayer that includes this candy/charly-infrastructure:dbus-layer — D-Bus session bus (required dependency)/charly-selkies:pipewire — PipeWire (required for ScreenCast)/charly-selkies:sway — Sway compositor (required)/charly-image:layer — candy authoring reference (charly.yml schema, task verbs, service declarations)/charly-check:check — declarative testing (check: block, charly check box, charly check live)tools
Use when authoring or modifying a charly PLUGIN — a candy with a `plugin:` block that contributes Providers (verbs/kinds/deploy-targets/steps/builders/commands), its own CUE schema, builtin (compiled-in) or external (out-of-tree git repo). Covers the unified Provider model, the per-plugin CUE-schema contract (single source → Go params for dev + schema-over-Describe RPC for runtime), the SDK, and the loader.
tools
The CUE data-validation / configuration CLI (cue), pinned to v0.16.1. Use when working with the cue candy, installing the cue binary into a box or onto a target:local dev host, or running the offline schema-vendoring pipeline that feeds charly's egress validation.
tools
CUE EGRESS validation — validating (and, where it adds value, generating) the config files charly WRITES to a system BEFORE the bytes hit disk. MUST be invoked before working on charly/egress.go, the vendored schemas under candy/plugin-egress/egress-schemas/vendor/, the ValidateEgress / registerVendoredEgressKind path, the offline `task cue:vendor` pipeline, or adding an egress schema for any written artifact (cloud-init, k8s manifests, traefik routes, runtime config, install ledger, systemd/quadlet units, ssh_config, libvirt XML).
tools
Kubernetes cluster-probe declarative check verb — the `kube:` check verb (nodes, pods, ingress, storage class, addon health, apply/delete, and arbitrary resource GETs) served out-of-process by the candy/plugin-kube plugin (vendored client-go; no external kubectl required).