desktop-signing

Installation
SKILL.md

Desktop Code Signing & Notarization (Windows + macOS)

Unsigned desktop apps trigger scary OS warnings — SmartScreen ("Windows protected your PC") on Windows and Gatekeeper ("cannot be opened because the developer cannot be verified") on macOS. Signing (and, on macOS, notarization) is what makes an app install cleanly for end users distributed outside an app store.

This skill is framework-agnostic. The certificate/notarization mechanics are identical whether the binary comes from Electron Forge, Flutter desktop, Tauri, or Swift — only the config file that invokes them differs. Examples below lead with Electron Forge (the most common pipeline) and note the equivalent for other stacks.

When to invoke

  • During /app-gtm-release:ship-flutter (macOS/Windows desktop targets), /app-gtm-release:ship-swift (macOS), or any Electron/Tauri desktop release
  • When the user asks: "sign my Windows app", "notarize my Mac app", "get rid of the SmartScreen warning", "Azure Trusted Signing", "Developer ID", "hardened runtime"
  • Before shipping a desktop binary through alt-distribution (direct download, MSIX sideload, Deno desktop) — signing is what makes those channels trustworthy

Not needed for store-signed paths. If you ship through the Microsoft Store (MSIX) or the Mac App Store, the store signs for you — see msstore-submission. This skill is for everything distributed outside a store.

Windows Signing

Option A — Azure Trusted Signing (recommended, modern)

Azure Trusted Signing is Microsoft's cloud signing service and the modern replacement for buying an EV certificate. It's the cheapest option, keeps the private key in Azure (nothing on the build machine), and eliminates SmartScreen warnings by building reputation under Microsoft's trusted CA.

Installs
2
GitHub Stars
3
First Seen
Jul 17, 2026