nano-banana

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and core capability align with image generation, and the Gemini CLI extension mechanism appears officially supported. Risk comes from mandatory installation of third-party extension code from a separate GitHub org and the blanket requirement to run with --yolo, which grants unnecessary autonomous approval. No clear exfiltration or overtly malicious behavior is evident, but install trust and autonomy are broader than ideal.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Mar 27, 2026, 06:09 AM
Package URL
pkg:socket/skills-sh/Derek-X-Wang%2Fskills%2Fnano-banana%2F@226582c38f2b7389eb776508b7436d850df6a43c