nano-banana-2

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates as a prompt engineering framework that transforms user-provided descriptions into structured inputs for image generation, creating a surface where malicious user input could potentially influence the resulting prompt or downstream tool behavior.\n
  • Ingestion points: User-provided descriptions and requests for image generation or editing triggered by keywords like 'Nano Banana' or 'Gemini image generation' as defined in the SKILL.md frontmatter.\n
  • Boundary markers: The instructions do not define specific delimiters or instructions for the agent to differentiate between the agent's instructions and potentially malicious data within the user's input during prompt construction.\n
  • Capability inventory: The documentation in SKILL.md and references/specs.md indicates that the skill relies on the 'vs' tool to perform network API calls to Gemini services and references the 'seedance' skill for interacting with JSON configuration files.\n
  • Sanitization: The skill lacks explicit instructions for the agent to sanitize, escape, or validate user-provided content before it is interpolated into the final prompt frameworks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:00 PM
Security Audit — agent-trust-hub — nano-banana-2