nano-banana-pro
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes official and well-known libraries
google-genaiandpillowfor API interaction and image manipulation. - [COMMAND_EXECUTION]: It executes a bundled Python script
generate_image.pyusing theuvpackage manager to perform its tasks. - [DATA_EXFILTRATION]: The skill transmits user-specified prompt text and local images to Google's well-known Gemini API; this is intended behavior and uses trusted infrastructure.
- [PROMPT_INJECTION]: The tool is subject to indirect prompt injection as it processes external inputs (Ingestion points:
--promptand-iarguments in SKILL.md; Boundary markers: None; Capability inventory:generate_image.pyperforms network API calls and file system read/write; Sanitization: None).
Audit Metadata