banana

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill communicates with the official Google Generative Language API at generativelanguage.googleapis.com to perform image tasks. This is the core functionality and uses an established, well-known service provider.
  • [DYNAMIC_EXECUTION]: Scripts use the ctypes library to access platform-specific native functions for atomic renames (renameat2, renameatx_np) and linking (linkat). These are utilized to ensure that image assets and cost ledgers are updated in a transactionally safe manner, mitigating risks of data corruption or race conditions.
  • [DATA_EXPOSURE]: The skill manages its own state and legacy configuration within the agent environment, including controlled access to ~/.claude/settings.json for maintenance. This functionality is focused on the skill's own lifecycle management and includes dry-run and backup features for user safety.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles potentially untrusted data from reference images and search results. It implements robust mitigation by instructing the agent to treat all such data strictly as visual or factual evidence and never as instructions, effectively closing the indirect injection attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:19 PM
Security Audit — agent-trust-hub — banana