winapp-manifest

A tool for creating and editing Windows app manifest files, XML files that declare an app's identity, capabilities, entry point, and icons.

In plain words
What is it for?
Use it to create or update a Package.appxmanifest file, choose packaged or sparse packaging, declare capabilities, and generate app icon assets.
Why use it?
It helps Windows apps describe how they are packaged, launched, and what system access they require.

Skill for Claude CodeCodex

Part of the winapp plugin — 10 skills, 1 agent shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/microsoft/winappcli/winapp-manifest
Any agent
npx skills add microsoft/winappCli --skill winapp-manifest
Clone the repo
git clone --depth 1 https://github.com/microsoft/winappCli

Made for: Claude Code, Codex.

Or install winapp, the plugin that ships this one along with the rest of its 10 skills, 1 agent.

Per session 90 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,898 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00090 $0.01898
Opus 5 $0.00045 $0.00949
Sonnet 5 $0.00018 $0.00380
Haiku 4.5 $0.00009 $0.00190

Measured 3d ago against content hash cf0e4d41d8e5, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

winapp-manifest scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/winapp/skills/winapp-manifest/SKILL.md · 165 lines

How it starts

The opening of the file, as written. The whole thing — 165 lines — stays where its author put it; the contents beside it link to each section on GitHub.

When to use

Use this skill when:

  • Creating Package.appxmanifest for a project that doesn't have one yet
  • Generating app icon assets from a single source image
  • Understanding manifest structure for package identity and capabilities

Prerequisites

  • winapp CLI installed
  • Optional: a source image (PNG or SVG, at least 400x400 pixels) for custom app icons

Key concepts

Package.appxmanifest is the key prerequisite for most winapp commands — it's more important than winapp.yaml. It declares:

  • Package identity — name, publisher, version
  • App entry point — which executable to launch
  • Capabilities — what the app can access (internet, file system, etc.)
  • Visual assets — icons for Start menu, taskbar, installers
  • Extensions — share target, startup tasks, file associations, etc.

Two manifest templates:

  • packaged (default) — for full MSIX distribution
  • sparse — for desktop apps that need package identity without full MSIX containment (uses AllowExternalContent)

winapp init also generates a manifest as part of full project setup. Use winapp manifest generate when you only need the manifest without SDK setup or winapp.yaml.

Usage

Generate a new manifest

# Defaults — uses current folder name, current user as publisher
winapp manifest generate

# Into a specific directory
winapp manifest generate ./my-project

# Customize identity
winapp manifest generate --package-name "MyApp" --publisher-name "CN=Contoso" --version "2.0.0.0"

# Set entry point and description
winapp manifest generate --executable myapp.exe --description "My awesome app"

# Generate a sparse manifest (for desktop apps needing identity without full MSIX)
winapp manifest generate --template sparse

# Overwrite existing manifest
winapp manifest generate --if-exists overwrite

Output:

  • Package.appxmanifest — the manifest file
  • Assets/ — default app icons in required sizes (Square44x44Logo, Square150x150Logo, Wide310x150Logo, etc.)

Read the full file on GitHub · 165 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 165 lines · 90 tokens per session scan A cf0e4d41d8e5

Subscribe to this mod's changes

winapp-manifest is a skill published in the GitHub repository microsoft/winappCli (1,205 stars, last pushed 5d ago), licensed MIT. It adds 90 tokens to every session and 1,898 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

chat-perf

Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.

microsoft/vscode · 51 tokens

heap-snapshot-analysis

Analyze V8 heap snapshots to investigate memory leaks and retention issues. Use when given .heapsnapshot files, asked to compare before/after snapshots, asked to find what retains objects, or investigating why objects survive GC. Provides snapshot parsing, comparison, retainer-path helpers, and scratchpad scripts.

microsoft/vscode · 65 tokens

integrated-browser

Use this when working on the VS Code integrated browser ("browserView") to understand its architecture and mental model. Covers the embedded Chromium browser, its editor tab, navigation, overlay/layout, sessions, and agent browser tools under src/vs/platform/browserView and src/vs/workbench/contrib/browserView.

microsoft/vscode · 68 tokens

agent-host-e2e-tests

Use when writing, recording, updating, or troubleshooting the agent host end-to-end tests under src/vs/platform/agentHost/test/node/e2e (black-box tests that drive the whole agent host over the AHP protocol, using a CapiReplayProxy record/replay system for Claude/Copilot/Codex). Covers adding a cross-provider test…

microsoft/vscode · 104 tokens

agent-host-logs

Analyze Agent Host debug log exports. Use when given an ah-logs or ahp-logs zip/folder, an Export Agent Host Debug Logs bundle, events.jsonl, AHP JSONL transport logs, Agent Host.log, remote-agenthost.log, or copilot-logs.

microsoft/vscode · 62 tokens

launch

Launch Code OSS (VS Code from sources) into an isolated throwaway profile with unique debug ports so you can drive it with @playwright/cli AND attach a Node debugger via dap-cli in the same session. Use when working on VS Code itself and you want to interact with the running workbench, automate chat or UI flows, test…

microsoft/vscode · 96 tokens