I think you are right, not validating an application that you install and going into your OS with access to more than the sandbox of the browser sounds like a good idea for adding even more malware on the echo system and malicious tracking software.
https://blog.lukaszolejnik.com/tracking-users-with-rogue-progressive-web-applications/