daytona-windows-cert
test on Windows, enterprise CA, corporate certificate, GPO cert, TLS fetch failed, Windows sandbox, daytona windows, self-hosted cert. Use when validating iPolloWork Windows enterprise TLS/OS-trust fixes in a Daytona Windows sandbox.
Asset-Profil
Coding- und Entwickler-Agents
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Szenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent-Fit
Claude Code + CLI + Codex
Geeignet für Codex, Claude Code, Cursor, CLI oder benutzerdefinierte Agents.
Installieren
Bereit
npx skills add Devin-AXIS/iPolloWork --skill daytona-windows-cert
Wartung
Aktuell
Heute gepusht
Risiko
Prüfung nötig
Dependency or permission surface needs review
GitHub-Qualität
4.5K
83/100 Qualität · 70/100 Vertrauen
Abdeckungs-Tags
Review-Notizen
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent-Adoptionskarte
Vertrauen, Audit und Installationsbereitschaft auf einen Blick
Diese Werte kombinieren öffentliche Repository-Metadaten, OpenAgentSkill-Reviewsignale, Wartungsaktualität und Installationsbereitschaft. Sie helfen bei der Vorauswahl, ersetzen aber keine menschliche Prüfung.
Qualität
StarkSolid option that is likely worth shortlisting for production workflows.
Vertrauen
Nur SandboxNützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.
Audit
Prüfung nötigMaschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.
OpenAgentSkill Trust Score v5
Menschliche Prüfung vor Installation
Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.
Stars
4.5K GitHub-Stars
Repository-Aktivität
4.5K Stars und 879 Forks
Wartung
Heute gepusht
Lizenz
NOASSERTION
Installieren
npx skills add Devin-AXIS/iPolloWork --skill daytona-windows-cert
Installationssicherheit
Standard-Paket- oder Laufzeit-Installationspfad
Berechtigungsfläche
secrets or environment access, shell or command execution
Agent-Ergebnisse
Noch keine Agent-Ergebnisdaten
Dokumentation
Starker README/SKILL.md-Kontext
Risikoübersicht
Vor Produktion prüfen
- Repository license is NOASSERTION; licensing for the skill and its assets is unclear.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
Installationsbereitschaft
Installationspfad verfügbar
- Installationspfad ist verfügbar
- Repository-Belege sind verfügbar
- Lizenz ist angegeben
- Noch keine Agent-Proven-Ergebnisbelege
Agent-lesbare Metadaten
Maschinenlesbare Entscheidungsdaten für diesen Skill.
Nutze diesen Block oder das eingebettete JSON, um zu entscheiden, ob ein Agent diesen Skill installieren, eine Alternative wählen oder zuerst menschliche Prüfung anfordern soll.
Geeignete Aufgaben
- Local desktop-Workflows
- Claude-Code-Teams
- Teams, die GitHub-Adoptionssignale schätzen
- Navigate local resources
Geeignete Agents
Installationsentscheidung
- Befehl
- npx skills add Devin-AXIS/iPolloWork --skill daytona-windows-cert
- Richtlinie
- Blockieren
- Menschliche Prüfung
- Ja
Vertrauen und Risiko
- Vertrauen
- 62/100
- Audit
- 80/100
- Risikoebene
- Prüfung nötig
Ergebnis-Loop
- Endpoint
- /api/agent/outcome
- Event-ID
- resolve
- Ergebnisse
- 5
Installationsbefehl
npx skills add Devin-AXIS/iPolloWork --skill daytona-windows-certNicht verwenden, wenn
- Teams, die ein vom Anbieter unterstütztes SLA benötigen
- production agents without a repository review
- Repository license is NOASSERTION; licensing for the skill and its assets is unclear.
- No OpenAgentSkill engagement data yet
- Hinweise auf Hochrisiko-Berechtigungen: Shell or command execution, Secrets or environment access
Alternative
Code Review
168.6K Stars
npx skills add mattpocock/skills --skill code-review
Alternative
Grill With Docs
164.7K Stars
npx skills add mattpocock/skills --skill grill-with-docs
Alternative
To Spec
164.7K Stars
npx skills add mattpocock/skills --skill to-spec
Alternative
To Tickets
176.7K Stars
npx skills add mattpocock/skills --skill to-tickets
Agent-Sicherheit v2
40/100 · Automatische Installation vermeiden
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
Hoch
Shell- oder Befehlsausführung
Die Skill-Metadaten verweisen auf Terminal-, CLI-, Shell-, Subprozess- oder Befehlsausführungs-Workflows.
Mittel
Netzwerkzugriff
Die Skill ruft wahrscheinlich Remote-Seiten, APIs, Repositories oder externe Dienste ab.
Mittel
Dateisystemzugriff
Die Skill kann Projektdateien, Dokumente, generierte Artefakte oder den lokalen Arbeitsbereich lesen oder schreiben.
Hoch
Secrets or environment access
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
- Hinweise auf Hochrisiko-Berechtigungen: Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
Installationsziele
Diesen Skill im Agent-Workflow installieren
Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install devin-axis-daytona-windows-certAgent-Auflösungsplan
Lass einen Agent die Eignung vor der Installation prüfen.
Die Resolve API liefert die beste Skill, Alternativen, Sicherheitsrichtlinien, Auditnotizen, Installationsziel und einen direkt nutzbaren Prompt.
JSON öffnen
/api/agent/resolve?task=Use%20daytona-windows-cert%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve-Text
/api/agent/resolve?task=Use%20daytona-windows-cert%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Installationsübergabe
/api/skills/devin-axis-daytona-windows-cert/install
Agent sollte prüfen
- Task fit and alternatives from Resolve API.
- Audit score, trust score, and safety policy warnings.
- Install target compatibility for Codex, Claude Code, Cursor, or CLI.
Prompt kopieren
Task: Use daytona-windows-cert in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20daytona-windows-cert%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/devin-axis-daytona-windows-cert/install
Install command: npx skills add Devin-AXIS/iPolloWork --skill daytona-windows-cert
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent-Übergabe
Gib dem Agent den Installationspfad, nicht noch ein Verzeichnis.
Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.
Installationsübergabe
/api/skills/devin-axis-daytona-windows-cert/install
LLM-Textformat
/api/skills/devin-axis-daytona-windows-cert/install?format=text
Alternativen finden
/api/skills/search?q=daytona-windows-cert&limit=3
Agent-Prompt
Use daytona-windows-cert for this task. Review https://www.openagentskill.com/api/skills/devin-axis-daytona-windows-cert/install, then install with: npx skills add Devin-AXIS/iPolloWork --skill daytona-windows-certRegistry-Metadaten
Agent-lesbares Profil für die automatische Skill-Auswahl.
Die Registry API stellt Entscheidungs-, Vertrauens-, Audit-, Use-Case- und Installationssignale ohne UI-Scraping bereit.
Manifest
/api/registry/manifest/devin-axis-daytona-windows-cert
LLM-Text
/api/registry/manifest/devin-axis-daytona-windows-cert?format=text
Installationsalias
/api/registry/install/devin-axis-daytona-windows-cert
Empfehlen
/api/registry/recommend?task=Use%20daytona-windows-cert%20in%20an%20agent%20workflow&limit=3
Agent-Fit
Local desktop
Use-Case-Tags
Plattformen
Claude Code
Audit-Bericht
Prüfung nötig · 80/100
Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.
Agent-Entscheidungspanel
Primäre Wahl für Local desktop
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Rolle im Stack
Primäre Wahl
Primäre Eignung
Local desktop
Vertrauenslabel
Produktionsbereit
Installationspfad
Befehl bereit
Verwenden wenn
- Local desktop-Workflows
- Claude-Code-Teams
- Teams, die GitHub-Adoptionssignale schätzen
Evidenz
- 4,484 GitHub-Stars
- recent repository activity
- install command or GitHub repo available
- Qualitätsprofil 83/100
zuerst prüfen
- Repository license is NOASSERTION; licensing for the skill and its assets is unclear.
- No OpenAgentSkill engagement data yet
Implementierungspfad
- 1Installieren Sie es in einem Sandbox-Agent und führen Sie eine Local desktop-Aufgabe vollständig aus.
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
Vertrauensprofil
Nur Sandbox
Nützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.
GitHub-Akzeptanz
Bestanden4.5K GitHub-Stars
Star-/Fork-Aktivität
Bestanden4.5K Stars und 879 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar
Aktuelle Wartung
BestandenHeute gepusht
Lizenzklarheit
BestandenNOASSERTION
Positive Signale
- KI-Prüfung genehmigt
- Installationspfad ist verfügbar
- Repository-Belege sind verfügbar
- Kürzlich gewartetes Repository
- Aussagekräftiges GitHub-Adoptionssignal
- Der Installationsbefehl weist kein offensichtliches Hochrisikomuster auf
- Ergebniszyklus ist bereit, benötigt aber den ersten echten Agent-Lauf
Vor Installation prüfen
- Repository license is NOASSERTION; licensing for the skill and its assets is unclear.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
- Noch keine echten Agent-Ergebnisberichte
- Vor unbeaufsichtigter Installation ist menschliche Prüfung erforderlich
Empfohlene Aktion
Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.
Qualitätsprofil
Stark Kandidat für Agent-Workflows
Solid option that is likely worth shortlisting for production workflows.
Workflow-Eignung
Diese Skill in diesen Szenarien nutzen
Operate local tools
Local desktop
I need my agent to operate local files and desktop apps in a repeatable workflow.
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Workflow-Eignung
Zum vollständigen Workflow hinzufügen
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Turn skills into distribution
Content growth agent
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternativen-Shortlist
Vor Installation vergleichen
Similar skills that may fit this task.
Code Review
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
Grill With Docs
A relentless interview that pressure-tests a plan against the codebase, sharpens domain language, and updates CONTEXT.md and ADRs when decisions become durable.
To Spec
Turn the current conversation and codebase context into a structured implementation spec, then publish it to the configured project issue tracker.
To Tickets
Break a plan, spec, or conversation into independently actionable tracer-bullet tickets with explicit blocking relationships.
Übersicht
--- name: daytona-windows-cert description: "test on Windows, enterprise CA, corporate certificate, GPO cert, TLS fetch failed, Windows sandbox, daytona windows, self-hosted cert. Use when validating iPolloWork Windows enterprise TLS/OS-trust fixes in a Daytona Windows sandbox." ---
# Skill: Daytona Windows Enterprise Certificate Test
Run the verified Windows repro for iPolloWork enterprise TLS behavior: install a fake corporate CA into the Windows machine store, serve healthy and broken HTTPS control planes, install a Windows build, and prove the desktop app and spawned runtimes use the operating system trust path.
Use this as the Windows companion to `daytona-electron-test`. Use `fraimz` when the result needs frame-by-frame proof, screenshots, or PR evidence. Reuse the repo support assets instead of copying their logic: `scripts/support/setup-ipollowork-tls-repro.ps1`, `scripts/support/ipollowork-doctor.ps1`, and `docs/support/enterprise-network-doctor.md`.
## When to use
- User says "test on Windows", "Windows sandbox", or "daytona windows". - User is validating an enterprise CA, corporate certificate, GPO cert, or self-hosted cert path on Windows. - User reports `TLS fetch failed`, `fetch failed`, or a certificate-specific failure when connecting iPolloWork to a self-hosted control plane. - User needs to prove the Windows app uses OS trust and spawned runtimes receive the OS trust bundle via `NODE_EXTRA_CA_CERTS`.
## Prereqs
- Daytona CLI must be at least the API version. The verified CLI was v0.194:
```bash brew upgrade daytonaio/cli/daytona brew link --overwrite daytona daytona version ```
- `gh` must be authenticated to `Devin-AXIS/iPolloWork` and able to create/delete temporary public prereleases. - Have a Windows iPolloWork build or installer ready. Keep secrets and customer materials out of the temporary release asset.
## 1. Create the Windows sandbox
Windows sandboxes are VM-only and are created from Daytona's prebuilt `windows` snapshot. Available classes are `windows-small` (1 vCPU / 4 GB), `windows-medium` (2 vCPU / 8 GB), and `windows-large` (4 vCPU / 16 GB). The verified path used `windows-medium`:
```bash daytona create --snapshot windows-medium ```
The command prints a sandbox ID and a web terminal URL. Save the ID once:
```bash SANDBOX_ID="<SANDBOX_ID>" ```
Windows sandboxes may auto-stop. Restart the sandbox before continuing:
```bash daytona sandbox start <ID> ```
Use the saved shell variable for later commands:
```bash daytona sandbox start "$SANDBOX_ID" ```
## 2. exec vs VNC (the session-0 trap)
**Important:** `daytona ssh <ID>` is interactive-only and fails from scripts on the host-key prompt. Use this shape for setup commands instead:
```bash daytona exec <ID> -- <cmd> ```
For example:
```bash daytona exec "$SANDBOX_ID" -- whoami ```
`daytona exec` runs as `nt authority\system` in Windows session 0. That is useful for admin setup, but it **cannot see the interactive VNC user's app UI**, and `$env:APPDATA` resolves to the SYSTEM profile, not `C:\Users\Administrator`. Do not inspect app UI state, userData, or installed app settings through SYSTEM profile paths.
Human GUI access is: Daytona Dashboard -> sandbox -> ⋮ menu -> **VNC** -> Connect. Use `exec` for setup and logs; use VNC to drive the installed iPolloWork app and observe the user-visible result.
## 3. Get the app build in
For large Windows builds, zip the build, attach it to a temporary **public prerelease**, and download it inside the VM with the Windows-bundled `curl.exe` and `tar`. The `curl.exe` 8.x and `tar` binaries ship in the Windows image.
From the repo root on the host, stage a zip that expands under `C:\ow`. Include the app build plus the support scripts from this repo so the VM reuses the checked-in harness:
```bash TAG="ipollowork-win-cert-repro-$(date +%Y%m%d%H%M%S)" ZIP="/tmp/${TAG}.zip" # Put your Windows app build under /tmp/ipollowork-win-cert-upload/ipollowork/app # and include scripts/support/setup-ipollowork-tls-repro.ps1 plus # scripts/support/ipollowork-doctor.ps1 under ipollowork/scripts/support/. # Include .opencode/skills/daytona-windows-cert/scripts/ca-probe.js as # ipollowork/ca-probe.js. ditto -c -k --keepParent /tmp/ipollowork-win-cert-upload/ipollowork "$ZIP" gh release create "$TAG" "$ZIP" --repo Devin-AXIS/iPolloWork --prerelease ```
The release command shape from the verified session was:
```bash gh release create <tag> <zip> --repo Devin-AXIS/iPolloWork --prerelease ```
Download and extract inside Windows:
```bash DOWNLOAD_URL="https://github.com/Devin-AXIS/iPolloWork/releases/download/${TAG}/$(basename "$ZIP")" daytona exec "$SANDBOX_ID" -- cmd /c 'mkdir C:\ow 2>NUL' daytona exec "$SANDBOX_ID" -- cmd /c "curl.exe -L -o C:\ow\app.zip $DOWNLOAD_URL" daytona exec "$SANDBOX_ID" -- cmd /c 'tar -xf C:\ow\app.zip -C C:\ow' ```
The Windows download/extract shape from the verified session was:
```bash daytona exec "$SANDBOX_ID" -- cmd /c 'curl.exe -L -o C:\ow\app.zip <release-download-url>' daytona exec "$SANDBOX_ID" -- cmd /c 'tar -xf C:\ow\app.zip -C C:\ow' ```
If the zip only contains the app, fetch the support scripts from the same branch instead of rewriting them:
```bash daytona exec "$SANDBOX_ID" -- cmd /c 'mkdir C:\ow\ipollowork\scripts\support 2>NUL' daytona exec "$SANDBOX_ID" -- cmd /c 'curl.exe -L -o C:\ow\ipollowork\scripts\support\setup-ipollowork-tls-repro.ps1 https://raw.githubusercontent.com/Devin-AXIS/iPolloWork/dev/scripts/support/setup-ipollowork-tls-repro.ps1' daytona exec "$SANDBOX_ID" -- cmd /c 'curl.exe -L -o C:\ow\ipollowork\scripts\support\ipollowork-doctor.ps1 https://raw.githubusercontent.com/Devin-AXIS/iPolloWork/dev/scripts/support/ipollowork-doctor.ps1' ```
## 4. Stand up the enterprise-TLS repro
`scripts/support/setup-ipollowork-tls-repro.ps1` creates a fake corporate root and intermediate, trusts the root in `Cert:\LocalMachine\Root`, maps `poc.ipollowork.test` to localhost, and serves:
- `https://poc.ipollowork.test:8443` — healthy chain. - `https://poc.ipollowork.test:9443` — broken chain with the intermediate removed.
Do not run the listeners only inside a one-off `daytona exec`; the PowerShell listeners die when that exec session closes. Persist them with a scheduled task that runs as SYSTEM and keeps the session alive:
```bash ENCODED=$(python3 - <<'PY' import base64 script = r''' $ErrorActionPreference = "Stop" $repo = "C:\ow\ipollowork" $cmdPath = "C:\ow\start-ipollowork-tls-repro.cmd" $cmd = @" @echo off cd /d "$repo" powershell -NoProfile -ExecutionPolicy Bypass -File scripts\support\setup-ipollowork-tls-repro.ps1 powershell -NoProfile -ExecutionPolicy Bypass -Command "while (`$true) { Start-Sleep -Seconds 3600 }" "@ Set-Content -LiteralPath $cmdPath -Value $cmd -Encoding ASCII schtasks /create /f /sc onstart /ru SYSTEM /tn iPolloWorkTlsRepro /tr $cmdPath schtasks /run /tn iPolloWorkTlsRepro ''' print(base64.b64encode(script.encode("utf-16le")).decode()) PY ) daytona exec "$SANDBOX_ID" -- powershell -NoProfile -ExecutionPolicy Bypass -EncodedCommand "$ENCODED" ```
Verify the healthy listener is up:
```bash daytona exec "$SANDBOX_ID" -- cmd /c 'netstat -ano | findstr :8443' ```
Optional diagnostic output from the checked-in doctor script:
```bash daytona exec "$SANDBOX_ID" -- powershell -NoProfile -ExecutionPolicy Bypass -File 'C:\ow\ipollowork\scripts\support\ipollowork-doctor.ps1' -WebUrl https://poc.ipollowork.test:8443 -ApiUrl https://poc.ipollowork.test:9443 -ExpectedIssuerMatch "iPolloWork TLS Repro" ```
## 5. Verify the fix
### Probe Electron's view of the Windows machine store
Copy `.opencode/skills/daytona-windows-cert/scripts/ca-probe.js` into the VM as `C:\ow\ca-probe.js`. Its contents are intentionally small and reusable:
```bash daytona exec "$SANDBOX_ID" -- cmd /c 'copy C:\ow\ipollowork\ca-probe.js C:\ow\ca-probe.js' ```
```js const { X509Certificate } = require("node:crypto"); const tls = require("node:tls");
const needle = (process.env.IPOLLOWORK_TLS_REPRO_CA_MATCH || "iPolloWork TLS Repro").toLowerCase();
function countMatchingSubjects(certificates) { let count = 0; for (const pem of certificates) { try { const certificate = new X509Certificate(pem); if (certificate.subject.toLowerCase().includes(needle)) count += 1; } catch { // Ignore entries that are not parseable X.509 certificates. } } return count; }
const system = tls.getCACertificates("system"); const bundled = tls.getCACertificates("default");
const result = { systemCount: system.length, reproInSystem: countMatchingSubjects(system), defaultCount: bundled.length, reproInDefault: countMatchingSubjects(bundled), };
console.log(JSON.stringify(result, null, 2));
if (result.reproInSystem === 0) { process.exitCode = 1; } ```
Run Electron in node mode. Adjust the executable path for your unpacked build or installed app:
```bash daytona exec "$SANDBOX_ID" -- cmd /c 'set ELECTRON_RUN_AS_NODE=1 && "C:\ow\ipollowork\app\iPolloWork.exe" C:\ow\ca-probe.js' ```
The verified result was:
```json {"systemCount":42,"reproInSystem":6,"defaultCount":150,"reproInDefault":0} ```
This is the crucial #2562 verification for the GPO/enterprise-CA case: the Windows system store (`LocalMachine\Root`) contains the repro corporate CA, while the bundled Mozilla roots do not.
### Verify the installed app via VNC
Drive the installed iPolloWork Windows app through VNC, not `daytona exec`.
1. Open Daytona Dashboard -> sandbox -> ⋮ menu -> **VNC** -> Connect. 2. Launch or install iPolloWork as the interactive user. 3. Point the self-hosted/control-plane URL at `https://poc.ipollowork.test:8443`. The request should succeed. 4. Repeat against `https://poc.ipollowork.test:9443`. The request should fail with a named certificate/chain error, not a vague `fetch failed` banner.
Use `daytona-electron-test` for normal Electron driving patterns and `fraimz` for captured proof if this is PR evidence.
### Verify the app's generated CA bundle path
The real Windows userData folder is:
```text C:\Users\<User>\AppData\Roaming\com.differentai.ipollowork ```
It is **not** `C:\Users\<User>\AppData\Roaming\iPolloWork`. Because `exec` runs as SYSTEM, inspect the interactive user path explicitly:
```bash daytona exec "$SANDBOX_ID" -- cmd /c 'dir "C:\Users\Administrator\AppData\Roaming\com.differentai.ipollowork\system-ca-bundle.pem"' daytona exec "$SANDBOX_ID" -- cmd /c 'findstr /c:"iPolloWork TLS Repro" "C:\Users\Administrator\AppData\Roaming\com.differentai.ipollowork\system-ca-bundle.pem"' ```
Known gotcha: `system-ca-bundle.pem` is written once at first launch and then memoized. If a CA is added **after** first launch, restart the app before expecting it to appear. On real fleets the GPO CA is present at boot, so this usually does not bite customers.
## Shell/quoting gotchas
- zsh strips backslashes in unquoted Windows paths. Quote the whole `cmd /c` payload:
```bash daytona exec "$SANDBOX_ID" -- cmd /c 'dir "C:\Users\Administrator\AppData\Roaming\com.differentai.ipollowork"' ```
- Pipes and `|` inside `daytona exec ... -- powershell -Command '...'` can be eaten by the intermediate `cmd` layer. Use `powershell -EncodedCommand` with a base64 UTF-16LE payload for anything with pipes or nested quotes:
```bash ENCODED=$(python3 - <<'PY' import base64 command = r'Get-ChildItem Cert:\LocalMachine\Root | Where-Object Subject -like "*iPolloWork TLS Repro*"' print(base64.b64encode(command.encode("utf-16le")).decode()) PY ) daytona exec "$SANDBOX_ID" -- powershell -NoProfile -ExecutionPolicy Bypass -EncodedCommand "$ENCODED" ```
- `%ERRORLEVEL%` expands at parse time in `cmd` one-liners. Prefer PowerShell and `$LASTEXITCODE` when you need to propagate exit codes:
```bash daytona exec "$SANDBOX_ID" -- powershell -NoProfile -ExecutionPolicy Bypass -Command 'curl.exe --version; exit $LASTEXITCODE' ```
- `cmd /c` plus `timeout` fails with "input redirection is not s
Technische Details
- Version
- 1.0.0
- Lizenz
- NOASSERTION
- Letzte Aktualisierung
- 22. Aug. 2026
- Veröffentlicht
- 22. Aug. 2026
Entscheidungsübersicht
Primäre Wahl
4,484 GitHub-Stars
Audit
Installationsprüfung
Installations- und Adoptionsprüfung
- Sicherheit
- 72/100
- Wartung
- 100/100
- Installieren
- 92/100
Von Agent belegte Evidenz
Von Agent belegte Evidenz
Ergebnisberichte nach Resolve, Prüfung, Installation und einem begrenzten Lauf.
- Erfolgsrate
- —
- Letzter Fehler
- —
- Ergebnisse
- 0
- Ausgabequalität
- —
- Fehlgeschlagen
- 0
- Nicht relevant
- 0
- Installationen
- 0
- Durch Risiko blockiert
- 0
- Einrichtung erforderlich
- 0
- Produktion
- 0
Noch keine Agent-Ergebnisdaten. Der erste Lauf kann Erfolg, Einrichtungsbedarf, Risikoblockaden, Fehler oder Irrelevanz über /api/agent/outcome melden.
Installieren
Zum Agent-Workflow hinzufügen
Kostenlos und Open Source. Bericht vor der Installation in Produktions-Agents prüfen.
Wachstums-Loop
Share-Kit
Szenariobasierter Entwurf für daytona-windows-cert, bereit für einen manuellen X-Post.
daytona-windows-cert: test on Windows, enterprise CA, corporate certificate, GPO cert, TLS fetch failed, Windows sa... 4.5K stars https://www.openagentskill.com/skills/devin-axis-daytona-windows-cert?ref=x
Optionale Antwort mit Installationsbefehl
Listing + install path for daytona-windows-cert: https://www.openagentskill.com/skills/devin-axis-daytona-windows-cert?ref=x Install: npx skills add Devin-AXIS/iPolloWork --skill daytona-windows-cert
Quelle des Eintrags
Registry-indexiert
Dieser Eintrag wurde aus öffentlichen Quellen indexiert und ist erst nach Genehmigung eines Maintainer-Anspruchs offiziell.
- Ersteller
- Devin-AXIS
- Quelle
- Devin-AXIS/iPolloWork
- Indexiert von
- OpenAgentSkill Community-Index
Die Zuordnung verlinkt auf das öffentliche Repository oder Creator-Profil. Creator können den Eintrag beanspruchen, um Eigentümersignale zu aktualisieren.
Diesen Skill beanspruchenEigentümeranspruch
Diesen Skill-Eintrag beanspruchen
Dieser Registry-indexiert-Eintrag wird Devin-AXIS zugeschrieben, ist aber noch nicht offiziell markiert. Beanspruche ihn, um ein verifiziertes Eigentümersignal hinzuzufügen und künftige Launch-, Installations- und Audit-Updates vertrauenswürdiger zu machen.
Creator-Backlink-Kit
Evidenz-Badges in deine README einfügen
Zeige den kanonischen Eintrag, aktuelle Vertrauens- und Audit-Signale sowie echte Agent-Proven-Evidenz dort, wo Entwickler das Repository bewerten.
[](https://www.openagentskill.com/skills/devin-axis-daytona-windows-cert)
[](https://www.openagentskill.com/skills/devin-axis-daytona-windows-cert)
[](https://www.openagentskill.com/skills/devin-axis-daytona-windows-cert/audit)
[](https://www.openagentskill.com/skills/devin-axis-daytona-windows-cert)Autor
Devin-AXIS
@devin-axis
Tags
Plattform-Fit
Gesundheitssignale
- GitHub-Stars
- 4.5K
- Qualitätswert
- 48/100
- Letzter GitHub-Push
- 22. Aug. 2026
- Framework-Hinweise
- Unbekannt
- OpenAgentSkill-Aufrufe
- 0
- Installationskopien
- 0
- Externe Klicks
- 0
Community-Signal
Teile mit, ob dieser Skill für deinen Agent-Workflow nützlich ist. Zusammengefasstes Feedback verbessert das Ranking im Laufe der Zeit.
Vertrauen & Sicherheit
Nur Sandbox
- GitHub-Akzeptanz4.5K GitHub-StarsBestanden
- Star-/Fork-Aktivität4.5K Stars und 879 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbarBestanden
- Aktuelle WartungHeute gepushtBestanden
- LizenzklarheitNOASSERTIONBestanden
- README/SKILL.md-VollständigkeitMetadaten enthalten ausreichend Nutzungs- und Workflow-KontextBestanden
- Abhängigkeits-/Laufzeitrisikocommand execution surface, credential or environment accessPrüfen
Ähnliche Skills
Code Review
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
168.6K StarsGrill With Docs
A relentless interview that pressure-tests a plan against the codebase, sharpens domain language, and updates CONTEXT.md and ADRs when decisions become durable.
164.7K StarsTo Spec
Turn the current conversation and codebase context into a structured implementation spec, then publish it to the configured project issue tracker.
164.7K StarsTo Tickets
Break a plan, spec, or conversation into independently actionable tracer-bullet tickets with explicit blocking relationships.
176.7K Stars