AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Winui Packaging

skill-microsoft-win-dev-skills-winui-packaging · by microsoft

MSIX packaging, code signing, and distribution for WinUI 3 apps — build for release, certificate generation (winapp cert generate), certificate trust, code signing (winapp sign), self-contained deployment, CI/CD with GitHub Actions, and Microsoft Store submission. Use when preparing for release, creating MSIX installers, managing certificates, setting up CI/CD packaging, or publishing to the Micr…

No reviews yet
0 installs
20 views
0.0% view→install

Install

$ agentstack add skill-microsoft-win-dev-skills-winui-packaging

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-microsoft-win-dev-skills-winui-packaging)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Winui Packaging? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Quick Reference

| Task | Command | |------|---------| | Build for release | .\BuildAndRun.ps1 /p:Configuration=Release | | Package + sign | winapp package --cert devcert.pfx | | Generate + sign + package | winapp package --generate-cert --install-cert | | Generate dev certificate | winapp cert generate | | Trust certificate (admin) | winapp cert install ./devcert.pfx | | Sign existing file | winapp sign ./app.msix ./devcert.pfx | | Self-contained deployment | winapp package --cert devcert.pfx --self-contained |

End-to-End Workflow

Step 1: Build for Release

Use the BuildAndRun.ps1 script from the winui-dev-workflow skill to build your app in Release configuration without launching it:

.\BuildAndRun.ps1 /p:Configuration=Release -SkipRun
Step 2: Generate Certificate (one-time)
winapp cert generate --manifest .

Creates devcert.pfx (default password: password). The --manifest flag auto-matches the Publisher field in Package.appxmanifest.

Step 3: Trust Certificate (one-time, requires admin)
winapp cert install ./devcert.pfx

Adds cert to machine Trusted Root store. Persists across reboots.

Step 4: Package and Sign
winapp package  --cert ./devcert.pfx

This locates appxmanifest.xml, stages the layout, generates resources.pri, creates .msix, and signs it.

Step 5: Install or Distribute
# Local install
Add-AppxPackage ./MyApp.msix

# Or double-click the .msix file

Key Rules

  • Publisher must match between certificate and manifest Identity.Publisher — use winapp cert generate --manifest to auto-match
  • Prefer winapp package --cert over separate winapp sign — one step instead of two
  • cert install requires admin — run terminal as Administrator
  • Default PFX password is password — override with --password
  • --timestamp is critical for production — without it, signatures expire with the cert:

``powershell winapp package --cert prod.pfx --timestamp http://timestamp.digicert.com ``

  • --self-contained bundles Windows App SDK runtime — larger but no runtime dependency

CI/CD with GitHub Actions

name: Build and Package
on: [push]
jobs:
  build:
    runs-on: windows-latest
    steps:
      - uses: actions/checkout@v4
      - uses: microsoft/setup-WinAppCli@v0.1

      - name: Build
        run: dotnet build -c Release -p:Platform=x64

      - name: Package
        run: |
          winapp cert generate --if-exists skip --quiet
          winapp package ./bin/x64/Release/ --cert ./devcert.pfx --quiet

      - name: Upload artifact
        uses: actions/upload-artifact@v4
        with:
          name: msix-package
          path: "*.msix"

CI/CD tips:

  • Use --quiet for clean output
  • Use --if-exists skip with cert generate to avoid failures on re-runs
  • Store production PFX as a repository secret

Store Submission

  1. Partner Center account — register at partner.microsoft.com
  2. Age ratings — complete the questionnaire in Partner Center
  3. Screenshots — capture at 1366x768 minimum resolution
  4. Privacy policy — required for apps that access internet or user data
  5. Submit: upload the signed .msix / .msixbundle produced by winapp package via Microsoft Partner Center — Apps and games → your app → Packages. Microsoft Store submission is browser-based; there is no first-party CLI submit command yet.

Troubleshooting

| Error | Solution | |-------|----------| | "Publisher mismatch" | Run winapp cert generate --manifest to re-generate | | "Certificate not trusted" | Run winapp cert install ./devcert.pfx as admin | | "Access denied" | cert install needs admin elevation | | "Certificate file already exists" | Use --if-exists overwrite or --if-exists skip | | "appxmanifest.xml not found" | Run winapp init or pass --manifest | | "Package installation failed" | Trust cert first; remove stale: Get-AppxPackage \| Remove-AppxPackage | | Signature invalid after time | Re-sign with --timestamp |

References

| File | Read when... | |------|-------------| | references/sourcegen-patterns.md | Setting up AOT/trimming, JSON source generators, NativeAOT readiness, CsWin32 |

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.