nanobanana-infographic
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided infographic briefs (typically in JSON format) to construct prompts for downstream image models, representing an indirect prompt injection surface.\n
- Ingestion points:
scripts/build_variant_pack.pyingests data from brief templates such astemplates/brief.json.\n - Boundary markers: The skill does not currently implement explicit boundary delimiters or 'ignore instructions' warnings when interpolating user data into the final prompt text.\n
- Capability inventory: The skill possesses network capability to communicate with the Gemini API (
scripts/probe_gemini_image_api.py) and file system access to write prompt and image files to the disk.\n - Sanitization: Input processing is limited to basic string normalization (e.g., stripping whitespace) and lacks specific sanitization for prompt injection patterns.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates network communication with Google's official Developer API (
generativelanguage.googleapis.com) to generate image content and list models. These operations target a well-known service provider and are necessary for the skill's primary functionality.\n- [SAFE]: The skill uses local Python scripts for all core logic and does not depend on unverified external packages or remote script execution (e.g., curl-to-bash). API credentials are safely handled through the environment variableGEMINI_API_KEYrather than being hardcoded.
Audit Metadata