nanobanana

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation describes executing a Python script with user-provided prompts. The script uses argparse to safely handle arguments, and use of the {prompt} placeholder in documentation is a common pattern for agent skills. While the agent must ensure proper escaping when invoking the shell, the script itself demonstrates safe parameter handling via argparse and does not use dangerous functions like os.system with raw user input.
  • [DATA_EXFILTRATION]: The skill manages API keys through environment variables (GEMINI_API_KEY, GOOGLE_API_KEY), which is the recommended practice for credential security. It accesses local image files for editing purposes, with paths passed through a validation utility (validate_path) to mitigate directory traversal risks.
  • [PROMPT_INJECTION]: The skill acts as an interface for an image generation model and is subject to indirect prompt injection via the user-supplied generation instructions.
  • Ingestion points: User input is ingested via the prompt command-line argument and optional image files processed by scripts/nanobanana.py.
  • Boundary markers: No specific delimiters or "ignore instructions" tags are used when passing the user prompt to the Gemini API client.
  • Capability inventory: The script performs local file reads (PIL.Image.open), local file writes (result_image.save), and network requests to the official Google Gemini API.
  • Sanitization: Input paths are processed by a validate_path tool, and session names are cleaned using sanitize_filename before being used in paths. The prompt content is passed to the model as intended for image generation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — nanobanana