winapp-signing

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • Privileged System Modification: The skill describes the use of commands that require administrator privileges to modify the machine's Trusted Root Certification Authorities store. This is a standard administrative task for enabling local app testing, but users should be aware that modifying the system trust store is a high-privilege operation.
  • Indirect Prompt Injection Surface: The skill ingests data from application manifest files (Ingestion Point) without explicit boundary markers. This data is processed by tools that possess capabilities including system-level certificate management and network operations (Capability Inventory). Without specified sanitization (Sanitization not specified), there is a potential risk that malformed manifest data could affect tool execution.
  • Hardcoded Default Credentials: The skill uses a simple default password ('password') for generated development certificates. While the documentation provides guidance on overriding this value, the use of a hardcoded default is a potential security consideration if users do not follow the recommended override procedures.
  • External Resource Dependencies: The skill references external URLs and services for runtimes, cloud signing, and timestamping. These downloads and network operations are essential for standard code signing workflows but represent dependencies on external infrastructure and system-level software installers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:17 PM
Security Audit — agent-trust-hub — winapp-signing