nano-banana

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core capability fits the stated purpose, and the intended data flow to Gemini is proportionate, but the install instructions are internally inconsistent with the claimed Google/Gemini tooling. Recommending `@anthropic-ai/gemini-cli` instead of the official Google package creates a material supply-chain risk for the primary executable this skill depends on.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Mar 27, 2026, 01:46 AM
Package URL
pkg:socket/skills-sh/jh941213%2Fmy-claude-code-asset%2Fnano-banana%2F@25447a97d5bff6470fd2e812b60f5c89d9cbf9bf