nano-banana-pro
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes the
uvpackage manager to install and run its script, depending ongoogle-genaiandpillow. These are official and well-known libraries from trusted sources (Google and the Python community). - [COMMAND_EXECUTION]: The skill uses
uv runto execute its local Python script. This is the intended and documented method for running the tool within the platform's environment. - [DATA_EXFILTRATION]: The script communicates with Google's Gemini API to process images and prompts. This is a well-known service and the primary purpose of the skill. Sensitive data (API keys) are handled via environment variables, which is a standard and secure practice.
- [INDIRECT_PROMPT_INJECTION]: As an AI-powered image generation tool, the skill is naturally susceptible to indirect prompt injection if the agent provides prompts or images derived from untrusted sources.
- Ingestion points: The
--promptand--input-imagearguments ingenerate_image.pyaccept external content. - Boundary markers: None present; the script passes the prompt directly to the model.
- Capability inventory: The script has file-read (input images), file-write (output image), and network access (Google API) capabilities.
- Sanitization: None; the content is passed as-is to the generative model. This is an inherent risk of LLM-integrated tools but is managed by the model's internal safety filters.
Audit Metadata