nextjs-pwa
Audited by Socket on Feb 15, 2026
1 alert found:
Security[Skill Scanner] Download or install from free hosting/deployment platform detected No evidence of malicious behavior in the provided skill/documentation. The content is a coherent PWA implementation guide for Next.js and a third-party library (Serwist). Primary risks are accidental: broad service worker caching patterns could cause sensitive responses to be cached or stale, and suppressing dev warnings may mask issues. No credential harvesting, obfuscated payloads, or external exfiltration mechanisms were found. LLM verification: This skill document is a benign implementation guide for Next.js PWAs and does not contain direct malicious code. The highest supply-chain risk comes from instructing unpinned installations of a third-party package (Serwist) and linking to external hosting; consumers should audit and pin package versions and review the actual serwist package source before installing. There is no evidence in this document of obfuscated payloads or direct data-exfiltration code.