nano-banana-image

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for an image-generation skill, but the core execution model depends on an unverifiable `nano-banana` binary and passes it a live Gemini API key. That makes the install/execution trust and credential-forwarding footprint disproportionate unless the binary can be independently verified as an official or same-org open-source release.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Apr 8, 2026, 09:30 PM
Package URL
pkg:socket/skills-sh/Leechael%2Fnano-banana-image-skill%2Fnano-banana-image%2F@af42b314b6081bc43d0c8322a431c0746710340c