Agent skill

Daytona Windows Certificate Test

by Devin-AXIS in Devin-AXIS/iPolloWork

Reproduces iPolloWork enterprise TLS behavior in a Daytona Windows sandbox by installing a fake corporate CA and proving the app and its runtimes use the OS trust store.

Custom licenceAuto-check passedTesting & QA

Install Daytona Windows Certificate Test

skills CLI
$ npx skills add Devin-AXIS/iPolloWork --skill daytona-windows-cert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Devin-AXIS/iPolloWork daytona-windows-cert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Devin-AXIS/iPolloWork.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/daytona-windows-cert .claude/skills/daytona-windows-cert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
daytona-windows-cert
GitHub stars
6.8k
Used in
1 other repo
Token cost
~3.2k tokens
SKILL.md length
914 words
Files
2 (incl. scripts)
Skills in repo
30
Repo updated
First seen
Licence
Custom licence

At a glance

Reproduces iPolloWork enterprise TLS behavior in a Daytona Windows sandbox by installing a fake corporate CA and proving the app and its runtimes use the OS trust store.

  • Works in 5 steps: Create the Windows sandbox → exec vs VNC (the session-0 trap) → Get the app build in → …
  • Reproducing a 'TLS fetch failed' error when iPolloWork reaches a self-hosted control plane on Windows
  • SKILL.md covers When to use, Prereqs, 1. Create the Windows sandbox and 2. exec vs VNC (the session-0…, plus 5 more sections
  • Runs JavaScript scripts from its folder; calls gh, brew and python3

What it does

The skill reproduces the iPolloWork enterprise TLS scenario on Windows: it installs a fake corporate certificate authority into the machine store, serves healthy and broken HTTPS control planes, installs a Windows build, and shows that the desktop app and the runtimes it spawns follow the operating system trust path. It is the Windows companion to a Daytona Electron test skill, points to another skill when frame-by-frame proof, screenshots or PR evidence are needed, and reuses the repository's own support scripts and doc instead of copying their logic.

Prerequisites are a Daytona CLI at least as new as the API (the verified one was v0.194), the gh CLI authenticated to the iPolloWork repository with rights to create and delete temporary public prereleases, and a Windows build or installer with no secrets or customer material in the temporary release asset. The sandbox comes from Daytona's prebuilt windows snapshot, offered in small, medium and large classes, and the verified path used windows-medium. Sandboxes can auto-stop and need a restart, and because daytona ssh is interactive-only and fails in scripts, setup commands go through daytona exec. A ca-probe.js script is bundled.

When your agent uses it

  • Reproducing a 'TLS fetch failed' error when iPolloWork reaches a self-hosted control plane on Windows
  • Validating an enterprise CA, corporate certificate or GPO-deployed certificate path on Windows
  • Proving a Windows build uses the OS trust store and passes NODE_EXTRA_CA_CERTS to spawned runtimes
  • Setting up a Daytona Windows sandbox for a certificate test

Example prompts

  • “Test the enterprise certificate fix on Windows in a Daytona sandbox.”
  • “Users on Windows see TLS fetch failed against our self-hosted control plane. Reproduce it with a fake corporate CA.”
  • “Create a windows-medium sandbox and check that the spawned runtimes receive NODE_EXTRA_CA_CERTS.”

Requirements

  • Daytona CLI at least as new as the API
  • GitHub CLI (gh) authenticated to the iPolloWork repository
  • A Windows iPolloWork build or installer

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Create the Windows sandbox
  2. exec vs VNC (the session-0 trap)
  3. Get the app build in
  4. Stand up the enterprise-TLS repro
  5. Verify the fix

What it can do on your machine

Read from SKILL.md and the folder at commit 53908e0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • gh
    • brew
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Daytona Windows Certificate Test loads about 3.2k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 914 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 914 words (~3,171 tokens).

“Run the verified Windows repro for iPolloWork enterprise TLS behavior: install a fake corporate CA into the Windows machine store, serve healthy and broken HTTPS control planes, install a Windows build, and prove the desktop app and spawned runtimes use…”

— opening of SKILL.md by Devin-AXIS, Custom licence
name
daytona-windows-cert

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file (scripts) in .opencode/skills/daytona-windows-cert of Devin-AXIS/iPolloWork.

  • SKILL.md
  • scripts/ca-probe.js

Open the folder on GitHubat commit 53908e0

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Devin-AXIS/iPolloWork, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Daytona Windows Certificate Test next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Daytona Windows Certificate Test compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Daytona Windows Certificate Test this skillDevin-AXIS/iPolloWork6.8k1 repos~3.2kAutomated safety check: PassCustom licence
Add Full Slicefullstackhero/dotnet-starter-kit6.8k—~783Automated safety check: PassMIT
Local CImodule-federation/core2.7k—~914Automated safety check: PassMIT
Dqd Labctrsploit/ctrsploit154—~1.6kAutomated safety check: PassNone
Must Gather Investigationscylladb/scylla-operator401—~2.4kAutomated safety check: PassApache-2.0
Promotion Branches E2E Testhardisgroupcom/sfdx-hardis402—~11kAutomated safety check: NotesAGPL-3.0

Similar skills

  • Add Full Slice

    fullstackhero/dotnet-starter-kit

    Build a capability end-to-end — backend vertical slice (Contracts→handler→validator→endpoint) AND the React page wired to it.

    6.8k GitHub stars~783 tokensUpdated today
    Testing & QAAuto-check passed
  • Local CI

    module-federation/core

    Run this repository's local CI parity commands and pnpm run ci:local jobs.

    2.7k GitHub stars~914 tokensUpdated today
    Testing & QAAuto-check passed
  • Dqd Lab

    ctrsploit/ctrsploit

    Manage ctrsploit dqd lab environments from github.com/ctrsploit/dqd.

    154 GitHub stars~1.6k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Must Gather Investigation

    scylladb/scylla-operator

    Investigate failed e2e tests from Ginkgo JSON reports and must-gather artifacts, systematically analyzing logs, events, and resource states to identify root causes.

    401 GitHub stars~2.4k tokensUpdated today
    Testing & QAAuto-check passed
  • Promotion Branches E2E Test

    hardisgroupcom/sfdx-hardis

    Runs a full end-to-end test of sfdx-hardis promotion branches and backpromote against real Salesforce orgs and a throwaway repository, then writes a report.

    402 GitHub stars~11k tokensUpdated today
    Testing & QAAuto-check: notes
  • Crabbox Setup

    AI-Builder-Club/skills

    Scaffold an isolated CLOUD dev box per agent (via crabbox + Daytona) for any codebase — the parallel-safe counterpart to dev-local-setup.

    1.3k GitHub stars~1.9k tokensUpdated 23 days ago
    Testing & QAAuto-check: notes

More from Devin-AXIS/iPolloWork

All 30 skills in this repo
  • A code-change gate for the iPolloWork repository: search and reuse first, keep one source of truth, justify every new file or dependency, and audit the change.

    6.8k GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Build iPolloWork Templates

    Devin-AXIS/iPolloWork

    Builds a reusable iPolloWork template for Design, Slides or PPT, or HyperFrames Video through conversation, keeping a manifest, reusable variables and a validated package current.

    6.8k GitHub stars~925 tokensUpdated yesterday
    Auto-check passed
  • OpenCode Plugin Creator

    Devin-AXIS/iPolloWork

    Scaffolds an OpenCode plugin for iPolloWork with the right async factory shape, zod-based tool definitions and hook registration, and explains where to place and register it.

    6.8k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Agent-First Screenshots

    Devin-AXIS/iPolloWork

    Has an agent drive the real app through CDP and capture clean, defect-free product screenshots, gated by DOM, pixel and vision checks in a loop.

    6.8k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Daytona Chrome CDP

    Devin-AXIS/iPolloWork

    Launches a standalone Chrome or Chromium in a Daytona sandbox and drives it over CDP for web sign-in, OAuth and other flows that should bypass the Electron app.

    6.8k GitHub stars~582 tokensUpdated yesterday
    Auto-check passed
  • Daytona Cloud Server Setup

    Devin-AXIS/iPolloWork

    Starts the hosted server side of iPolloWork in a Daytona sandbox, running Den Web, Den API, the worker proxy and MySQL for end-to-end cloud testing.

    6.8k GitHub stars~687 tokensUpdated yesterday
    Auto-check passed

Questions about Daytona Windows Certificate Test

What does Daytona Windows Certificate Test do?

Reproduces iPolloWork enterprise TLS behavior in a Daytona Windows sandbox by installing a fake corporate CA and proving the app and its runtimes use the OS trust store. The skill reproduces the iPolloWork enterprise TLS scenario on Windows: it installs a fake corporate certificate authority into the machine store, serves healthy and broken HTTPS control planes, installs a Windows build, and shows that the desktop app and the runtimes it spawns follow the operating system trust path. It is the Windows companion to a Daytona Electron test skill, points to another skill when frame-by-frame proof, screenshots or PR evidence are needed, and reuses the repository's own support scripts and doc instead of copying their logic.

When should I use Daytona Windows Certificate Test?

Daytona Windows Certificate Test fits situations like: reproducing a 'TLS fetch failed' error when iPolloWork reaches a self-hosted control plane on Windows; validating an enterprise CA, corporate certificate or GPO-deployed certificate path on Windows; proving a Windows build uses the OS trust store and passes NODE_EXTRA_CA_CERTS to spawned runtimes; setting up a Daytona Windows sandbox for a certificate test.

How do I install Daytona Windows Certificate Test in Claude Code?

Run `npx skills add Devin-AXIS/iPolloWork --skill daytona-windows-cert -a claude-code`. Or copy the skill folder (.opencode/skills/daytona-windows-cert in Devin-AXIS/iPolloWork) into .claude/skills/daytona-windows-cert in your project. Claude Code loads it when a task matches its description.

How do I install Daytona Windows Certificate Test in Codex?

Run `npx skills add Devin-AXIS/iPolloWork --skill daytona-windows-cert -a codex`. Or copy the skill folder (.opencode/skills/daytona-windows-cert in Devin-AXIS/iPolloWork) into .agents/skills/daytona-windows-cert in your project. Codex loads it when a task matches its description.

Can I use Daytona Windows Certificate Test in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Devin-AXIS/iPolloWork --skill daytona-windows-cert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/daytona-windows-cert, .gemini/skills/daytona-windows-cert, .github/skills/daytona-windows-cert and .opencode/skills/daytona-windows-cert in your project.

What does Daytona Windows Certificate Test need to run?

Going by SKILL.md and its folder, Daytona Windows Certificate Test needs JavaScript for the scripts in its folder and the command-line tools its instructions call (gh, brew and python3). Our summary lists: Daytona CLI at least as new as the API; GitHub CLI (gh) authenticated to the iPolloWork repository; A Windows iPolloWork build or installer.

Does Daytona Windows Certificate Test access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Daytona Windows Certificate Test safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Daytona Windows Certificate Test use?

Daytona Windows Certificate Test has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Daytona Windows Certificate Test use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Daytona Windows Certificate Test?

Skills that share tags, products or a category with Daytona Windows Certificate Test: Add Full Slice (fullstackhero/dotnet-starter-kit, 6.8k stars), Local CI (module-federation/core, 2.7k stars), Dqd Lab (ctrsploit/ctrsploit, 154 stars) and Must Gather Investigation (scylladb/scylla-operator, 401 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Daytona Windows Certificate Test?

Devin-AXIS (a GitHub user) maintains it in Devin-AXIS/iPolloWork, which has 6,791 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 8, 2026.

Source: Devin-AXIS/iPolloWork on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.