nanobanana

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The upload_file tool enables reading files from the local filesystem via the path parameter and uploading them to the Google Gemini Files API. This functionality lacks path restrictions, creating a risk that sensitive configuration or credential files could be exfiltrated if the agent is directed to target them.
  • [COMMAND_EXECUTION]: The generate_image and upload_file tools interact with the local filesystem by accepting file paths for reading (input_image_path_1, path) and writing (output_path). This grants the agent broad filesystem access which could be abused for unauthorized data access or file modification.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes user-supplied strings (prompt, instruction) without sanitization. 1. Ingestion points: prompt and instruction parameters in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Local file access and network upload to the Gemini API. 4. Sanitization: Absent. An attacker could embed instructions in a prompt to trick the agent into performing unintended file operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 05:05 AM
Security Audit — agent-trust-hub — nanobanana