nano-banana-prompting

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data, including 'Existing prompts' and 'Visual references', to generate new prompts that are then passed to the nano-banana image generation skill. This workflow creates a surface for indirect prompt injection where malicious instructions in the user's input could influence the final generation.
  • Ingestion points: User-provided 'Existing prompts' and 'Visual references' are gathered in Step 1, and further details are collected via the AskUserQuestion tool in Step 2.
  • Boundary markers: The instructions do not specify the use of delimiters or clear separation markers (e.g., '---' or specific XML tags) when interpolating user-provided content into the generated prompt, making it easier for embedded instructions to be followed by the downstream model.
  • Capability inventory: The skill invokes the nano-banana skill in Step 6 to perform image generation based on the crafted prompt.
  • Sanitization: There are no procedures defined for sanitizing, filtering, or validating the content of user-supplied materials before they are incorporated into the final prompt construction.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — nano-banana-prompting