skills/kensaurus/skills/enhance-pwa/Gen Agent Trust Hub

enhance-pwa

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to install PWA libraries and run performance audits. Examples include npm install @ducanh2912/next-pwa and running npx lighthouse to verify the PWA score.
  • [EXTERNAL_DOWNLOADS]: The skill references several external Node.js packages and plugins required for PWA functionality, such as vite-plugin-pwa, next-pwa, and workbox. These are standard, well-known dependencies within the web development ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: Phase 1 involves using firecrawl:firecrawl_search to research framework-specific PWA tooling. This pattern introduces a surface for indirect prompt injection as the agent ingests untrusted content from the web. The skill possesses the capability to modify project configuration files (Vite, Next.js) and execute commands based on this research.
  • Ingestion points: Web content fetched via firecrawl:firecrawl_search in Phase 1 and library documentation resolved via context7:resolve-library-id.
  • Boundary markers: None explicitly defined for the search result ingestion.
  • Capability inventory: File system writes (creating manifests, editing config files), package installation (npm install), and command execution (npx lighthouse).
  • Sanitization: Not explicitly mentioned; the skill relies on the agent's reasoning to filter relevant technical documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 05:12 AM
Security Audit — agent-trust-hub — enhance-pwa