Security & trust

WinMate scripts run installers with administrator rights. This page describes what a script does, how packages are checked, where the limits are, and how to verify a script before running it.

What a WinMate script does

  • It runs winget, scoop or choco for the packages listed at the top of the script, and nothing else. That list is visible in the preview before the download.
  • It requests administrator rights once. Apps whose installers refuse elevation run under the normal user account through a temporary scheduled task that is removed afterwards.
  • It downloads nothing from WinMate. Installers come from the vendors, as recorded in the package manifests.
  • It writes a log and a run record to %LOCALAPPDATA%\WinMate, plus an undo script that removes only the apps the run installed.
  • There is no telemetry. The selection is stored in the browser only (privacy).

Verifying a script

Current version
2.3.0
Engine SHA-256
d3a662d54f9543910685884c9659132106302c97b64dcff686c121634a136322
Built from commit
435c9e3041f7

Every generated script consists of a short configuration block with the selected apps and the engine, which is identical in all scripts. To confirm that the engine is unchanged:

  1. Download winmate.ps1 from the latest GitHub release. Releases are built by public GitHub Actions and carry a build provenance attestation: gh attestation verify winmate.ps1 --repo baba537/WinMate
  2. Run .\winmate.ps1 -Verify .\WinMate-Install.cmd. It prints the apps the script installs and reports OK only if the engine matches the published hash.
  3. Or compare the engine block manually against src/ps/engine.ps1. The site is built reproducibly from the repository, so the result can be rebuilt and compared; build-info.json lists the hashes.

How packages are checked

  • winget: manifests in microsoft/winget-pkgs are validated and scanned by Microsoft before publication. winget compares the SHA-256 hash of every installer against its manifest and refuses to run a file that does not match. Store apps are delivered by the Microsoft Store.
  • Chocolatey: community packages are moderated and virus-scanned; downloaded installers must carry checksums.
  • Scoop: manifests contain hashes that Scoop checks after the download; buckets change through reviewed pull requests.
  • WinMate: a scheduled job checks every package ID against the official indexes once a week (last check: 2026-09-14) and records the current versions. Scripts use exact IDs (--exact) and a fixed source, and can pin the recorded versions.

Threat model

ThreatMitigationRemaining risk
The website or hosting is compromised and serves a modified scriptOpen source, reproducible build in public CI, script preview, engine hash checked by -Verify against an attested release, strict Content-Security-PolicyScripts that are run without being read or verified
A package source or manifest is compromisedReview, scanning and hash checks by winget, Chocolatey and Scoop; optional version pinningWinMate cannot detect a malicious package that the upstream repository accepted
A wrong or malicious package ID enters the catalogPull request review, CI validation against the official indexes, IDs visible on every app page and in the scriptA reviewer overlooks a similar-looking ID
Typosquatting and ambiguous namesExact package IDs (--exact) and a fixed source (--source winget) instead of name searchesLow
Abuse of the administrator sessionOne elevation, used only for the listed packages; no services, no persistent tasks; temporary files are deletedInstallers themselves run with full rights, which is inherent to installing software
A broken installationRun record, undo script for newly installed apps, one retry, detailed logsAn undo cannot revert changes an installer makes outside its own uninstaller

Known limits

  • No Authenticode signature. Scripts are generated in the browser for one specific selection and therefore cannot be code-signed. Release files carry GitHub build provenance instead, and the engine hash is published.
  • No independent security audit. The code is small and readable; reviews and reports are welcome.
  • Single maintainer, AI-assisted development. Everything is public and can be checked.
  • Not a deployment or management tool. WinMate generates install scripts. There is no central management, no offline mirror and no compliance reporting.

Reporting a vulnerability

Please report security issues privately through GitHub security advisories rather than in public issues. Details are in SECURITY.md. Wrong package IDs and other bugs belong in the issue tracker.