pwa-expert
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill's instructions are purely technical and educational. No attempts to override safety guardrails, extract system prompts, or manipulate agent behavior were found.
- [DATA_EXFILTRATION]: There is no evidence of hardcoded credentials, sensitive file path access (e.g., .ssh, .env), or unauthorized network exfiltration logic.
- [REMOTE_CODE_EXECUTION]: The skill does not perform remote script downloads or execute code from untrusted external sources. The mentioned tools like 'next-pwa' and 'Workbox' are standard industry libraries.
- [COMMAND_EXECUTION]: Although the 'Bash' tool is permitted, the skill content does not include any suspicious or high-risk command patterns. All code snippets are standard JavaScript/TypeScript for web development.
- [SAFE]: The skill appears to be a legitimate developer utility focusing on PWA best practices and implementation patterns.
Audit Metadata