nano-banana-edit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, publicly-fetchable image URLs which are used as inputs for image-to-image editing. This represents a potential surface for image-based prompt injection where malicious instructions could be embedded within the image data.
  • Ingestion points: Untrusted external data enters the context via the image_urls array field defined in the model schema (SKILL.md).
  • Boundary markers: The skill lacks explicit boundary markers or "ignore embedded instructions" delimiters for the content provided via the image URLs.
  • Capability inventory: The skill utilizes the runcomfy CLI to perform operations and supports writing generated files to the local file system using the --output-dir argument.
  • Sanitization: No sanitization or integrity verification is performed on the content retrieved from the provided image URLs.
  • [COMMAND_EXECUTION]: The skill is designed to invoke the runcomfy CLI tool to interact with the RunComfy Model API. It documents how to pass JSON payloads and file system paths to the command line.
  • [EXTERNAL_DOWNLOADS]: The skill instructions require the installation of the @runcomfy/cli Node.js package and the agentspace-so/runcomfy-skills repository to function.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:36 AM
Security Audit — agent-trust-hub — nano-banana-edit