winapp-package

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Application Packaging and Signing: The skill facilitates the creation of MSIX packages by invoking the winapp CLI, which coordinates system tools such as makeappx and signtool. These are standard operations for Windows application distribution.
  • Administrative Access Requirements: Certain commands, specifically those involving certificate installation (--install-cert or winapp cert install), are documented to require administrative privileges. This is a standard requirement for modifying the machine's trusted certificate store.
  • Certificate and Secret Handling: The skill manages sensitive assets like PFX certificates and passwords. The documentation suggests secure practices, such as utilizing GitHub Actions secrets to handle these credentials in CI/CD environments.
  • External Resource Integration: The instructions reference the microsoft/setup-winapp GitHub Action for environment configuration. This is a recognized integration for automating Windows application builds within GitHub-hosted runners.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 11:06 AM