nano-banana-pro

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the uv package manager to install and run its script, depending on google-genai and pillow. These are official and well-known libraries from trusted sources (Google and the Python community).
  • [COMMAND_EXECUTION]: The skill uses uv run to execute its local Python script. This is the intended and documented method for running the tool within the platform's environment.
  • [DATA_EXFILTRATION]: The script communicates with Google's Gemini API to process images and prompts. This is a well-known service and the primary purpose of the skill. Sensitive data (API keys) are handled via environment variables, which is a standard and secure practice.
  • [INDIRECT_PROMPT_INJECTION]: As an AI-powered image generation tool, the skill is naturally susceptible to indirect prompt injection if the agent provides prompts or images derived from untrusted sources.
  • Ingestion points: The --prompt and --input-image arguments in generate_image.py accept external content.
  • Boundary markers: None present; the script passes the prompt directly to the model.
  • Capability inventory: The script has file-read (input images), file-write (output image), and network access (Google API) capabilities.
  • Sanitization: None; the content is passed as-is to the generative model. This is an inherent risk of LLM-integrated tools but is managed by the model's internal safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — nano-banana-pro