nano-banana-prompting
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data, including 'Existing prompts' and 'Visual references', to generate new prompts that are then passed to the
nano-bananaimage generation skill. This workflow creates a surface for indirect prompt injection where malicious instructions in the user's input could influence the final generation. - Ingestion points: User-provided 'Existing prompts' and 'Visual references' are gathered in Step 1, and further details are collected via the
AskUserQuestiontool in Step 2. - Boundary markers: The instructions do not specify the use of delimiters or clear separation markers (e.g., '---' or specific XML tags) when interpolating user-provided content into the generated prompt, making it easier for embedded instructions to be followed by the downstream model.
- Capability inventory: The skill invokes the
nano-bananaskill in Step 6 to perform image generation based on the crafted prompt. - Sanitization: There are no procedures defined for sanitizing, filtering, or validating the content of user-supplied materials before they are incorporated into the final prompt construction.
Audit Metadata