You may include the full path to the KiXtart executable, indeed it is recommended.

If you are not sure what is going on, use the "-d" switch to create a debug version. This will output some useful information, including the execution path at both the encrypting and decrypting phase. When you are happy that all is running as expected, create a production version without the "-d" flag.

Note, you will of course not see any output if you use the console-less version.

You may set an environment variable before calling the encrypted script, and this will be available when the unencrypted script executes.