nano-banana
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core capability fits the stated purpose, and the intended data flow to Gemini is proportionate, but the install instructions are internally inconsistent with the claimed Google/Gemini tooling. Recommending `@anthropic-ai/gemini-cli` instead of the official Google package creates a material supply-chain risk for the primary executable this skill depends on.
Confidence: 90%Severity: 72%
Audit Metadata