nano-banana

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core image-generation purpose is coherent, but the trust model is weaker than it should be. The skill requires transitive installation of another skill, uses an install path inconsistent with the publisher's own documented belt CLI channels, grants broad Bash access, and forwards user auth/data through third-party CLI infrastructure. This looks more like a risky integration pattern than confirmed malware.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
May 13, 2026, 01:14 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fnano-banana%2F@95dc100d12f42c8d6e5f76e8be45504ce0e74af0