create-product-images-nanobanana

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a workflow to ingest data from external product URLs and user-provided briefs to populate media generation prompts. Ingestion points include the intake brief and automated web fetching of product details. While the prompt templates do not feature explicit sanitization or boundary markers against instructions embedded in external content, the risk is restricted to the skill's primary capabilities, which involve generating media artifacts and writing local manifest files.
  • [COMMAND_EXECUTION]: References are made to an external assembly script and the dynamic construction of ffmpeg filter expressions for audio mixing. However, the skill package does not include these scripts, and the described usage is consistent with standard media processing workflows.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the retrieval of brand assets, such as logos and product images, from remote URLs for use as references in video generation models. These operations are limited to media assets and do not involve the execution of remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 04:39 PM
Security Audit — agent-trust-hub — create-product-images-nanobanana