enhance-pwa
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to install PWA libraries and run performance audits. Examples include
npm install @ducanh2912/next-pwaand runningnpx lighthouseto verify the PWA score. - [EXTERNAL_DOWNLOADS]: The skill references several external Node.js packages and plugins required for PWA functionality, such as
vite-plugin-pwa,next-pwa, andworkbox. These are standard, well-known dependencies within the web development ecosystem. - [INDIRECT_PROMPT_INJECTION]: Phase 1 involves using
firecrawl:firecrawl_searchto research framework-specific PWA tooling. This pattern introduces a surface for indirect prompt injection as the agent ingests untrusted content from the web. The skill possesses the capability to modify project configuration files (Vite, Next.js) and execute commands based on this research. - Ingestion points: Web content fetched via
firecrawl:firecrawl_searchin Phase 1 and library documentation resolved viacontext7:resolve-library-id. - Boundary markers: None explicitly defined for the search result ingestion.
- Capability inventory: File system writes (creating manifests, editing config files), package installation (
npm install), and command execution (npx lighthouse). - Sanitization: Not explicitly mentioned; the skill relies on the agent's reasoning to filter relevant technical documentation.
Audit Metadata