nanobanana-infographic

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided infographic briefs (typically in JSON format) to construct prompts for downstream image models, representing an indirect prompt injection surface.\n
  • Ingestion points: scripts/build_variant_pack.py ingests data from brief templates such as templates/brief.json.\n
  • Boundary markers: The skill does not currently implement explicit boundary delimiters or 'ignore instructions' warnings when interpolating user data into the final prompt text.\n
  • Capability inventory: The skill possesses network capability to communicate with the Gemini API (scripts/probe_gemini_image_api.py) and file system access to write prompt and image files to the disk.\n
  • Sanitization: Input processing is limited to basic string normalization (e.g., stripping whitespace) and lacks specific sanitization for prompt injection patterns.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates network communication with Google's official Developer API (generativelanguage.googleapis.com) to generate image content and list models. These operations target a well-known service provider and are necessary for the skill's primary functionality.\n- [SAFE]: The skill uses local Python scripts for all core logic and does not depend on unverified external packages or remote script execution (e.g., curl-to-bash). API credentials are safely handled through the environment variable GEMINI_API_KEY rather than being hardcoded.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — nanobanana-infographic