winapp-signing

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • Administrative Privilege Requirement: The winapp cert install command requires administrative elevation to add certificates to the machine's Trusted Root Certification Authorities store. This is a standard system operation necessary for Windows to trust self-signed MSIX packages during development.
  • Default Development Passwords: The skill references a default password ('password') for generated PFX files. As noted in the documentation, this is intended for local testing only, and the instructions appropriately recommend using secure passwords and secret management for production and CI/CD environments.
  • Standard External Services: The skill mentions the use of an external timestamping service from DigiCert. This is a well-known and expected service used in code signing to ensure that signatures remains valid after the signing certificate has expired.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 11:06 AM