nanobanana
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation describes executing a Python script with user-provided prompts. The script uses
argparseto safely handle arguments, and use of the{prompt}placeholder in documentation is a common pattern for agent skills. While the agent must ensure proper escaping when invoking the shell, the script itself demonstrates safe parameter handling viaargparseand does not use dangerous functions likeos.systemwith raw user input. - [DATA_EXFILTRATION]: The skill manages API keys through environment variables (
GEMINI_API_KEY,GOOGLE_API_KEY), which is the recommended practice for credential security. It accesses local image files for editing purposes, with paths passed through a validation utility (validate_path) to mitigate directory traversal risks. - [PROMPT_INJECTION]: The skill acts as an interface for an image generation model and is subject to indirect prompt injection via the user-supplied generation instructions.
- Ingestion points: User input is ingested via the
promptcommand-line argument and optional image files processed byscripts/nanobanana.py. - Boundary markers: No specific delimiters or "ignore instructions" tags are used when passing the user prompt to the Gemini API client.
- Capability inventory: The script performs local file reads (
PIL.Image.open), local file writes (result_image.save), and network requests to the official Google Gemini API. - Sanitization: Input paths are processed by a
validate_pathtool, and session names are cleaned usingsanitize_filenamebefore being used in paths. The prompt content is passed to the model as intended for image generation.
Audit Metadata