nano-banana-pro

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of user-supplied prompts and local image files, which are then passed to an external vision-language model.
  • Ingestion points: The --prompt and --input-image command-line arguments in scripts/generate_image.py ingest data directly into the model's processing context.
  • Boundary markers: No delimiters or instructions are provided to the model to ignore potentially malicious content embedded within the prompt or the pixel data of input images.
  • Capability inventory: The scripts/generate_image.py script has the capability to read local files (PIL.Image.open), write to the file system (PIL.Image.save), and perform network operations via the google-genai library.
  • Sanitization: The script does not perform validation or sanitization on the input prompt or the file paths provided, allowing for potential manipulation of agent behavior if it processes adversarial content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — nano-banana-pro