sf-diagram-nanobananapro
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill's prerequisite check script fetches and executes the
uvtool installer from its official domain (astral.sh), which is a well-known service for Python development tools. - [COMMAND_EXECUTION]: The Python script for image generation uses the macOS
opencommand to display the final visual output in the user's default image viewer. - [CREDENTIALS_UNSAFE]: The skill includes explicit security notes and guidance for users to store their
GEMINI_API_KEYin environment variables (~/.zshrc) rather than hardcoding it, ensuring sensitive credentials are not exposed in the codebase.
Audit Metadata