nano-banana-pro
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of user-supplied prompts and local image files, which are then passed to an external vision-language model.
- Ingestion points: The
--promptand--input-imagecommand-line arguments inscripts/generate_image.pyingest data directly into the model's processing context. - Boundary markers: No delimiters or instructions are provided to the model to ignore potentially malicious content embedded within the prompt or the pixel data of input images.
- Capability inventory: The
scripts/generate_image.pyscript has the capability to read local files (PIL.Image.open), write to the file system (PIL.Image.save), and perform network operations via thegoogle-genailibrary. - Sanitization: The script does not perform validation or sanitization on the input prompt or the file paths provided, allowing for potential manipulation of agent behavior if it processes adversarial content.
Audit Metadata