nano-banana-edit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, publicly-fetchable image URLs which are used as inputs for image-to-image editing. This represents a potential surface for image-based prompt injection where malicious instructions could be embedded within the image data.
- Ingestion points: Untrusted external data enters the context via the
image_urlsarray field defined in the model schema (SKILL.md). - Boundary markers: The skill lacks explicit boundary markers or "ignore embedded instructions" delimiters for the content provided via the image URLs.
- Capability inventory: The skill utilizes the
runcomfyCLI to perform operations and supports writing generated files to the local file system using the--output-dirargument. - Sanitization: No sanitization or integrity verification is performed on the content retrieved from the provided image URLs.
- [COMMAND_EXECUTION]: The skill is designed to invoke the
runcomfyCLI tool to interact with the RunComfy Model API. It documents how to pass JSON payloads and file system paths to the command line. - [EXTERNAL_DOWNLOADS]: The skill instructions require the installation of the
@runcomfy/cliNode.js package and theagentspace-so/runcomfy-skillsrepository to function.
Audit Metadata