nano-banana

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the skill is functionally coherent with its stated purpose (image generation via Gemini models) but its install and execution approach (curl|bash installation and remote binary) is not proportionate or trustworthy by standard development practices. This introduces supply-chain risk and potential data flow concerns. Treat as SUSPICIOUS with elevated security risk due to unverifiable binary installation and external execution chain; mitigations should include using an officially verifiable package registry, pinning specific public checksums, or providing in-repo/built-from-source installation steps with transparent provenance. If credentials or sensitive data are ever forwarded to the external CLI, risk would escalate further.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fnano-banana%2F@a99908f58aa80fa0d2e4ea3af9cf545aee6981f0
Security Audit — socket — nano-banana