nano-banana-pro
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of text prompts and image files which are passed to a multimodal AI model without explicit boundary markers or sanitization logic.
- Ingestion points: The
args.promptandargs.imagesarguments ingenerate_image.pyaccept external data. - Boundary markers: Absent; the script directly appends user input to the model's content list.
- Capability inventory: The skill possesses
Writeaccess to save images andBashaccess to execute the generator script. - Sanitization: None detected; raw input is passed to the Google GenAI client.
- [EXTERNAL_DOWNLOADS]: The skill depends on the
google-genaiPython package. - Evidence: The
generate_image.pyscript specifiesgoogle-genaiin its inline dependency metadata. - Context: The package is a well-known library from a trusted organization for interacting with official AI APIs.
- [METADATA_POISONING]: The skill description and usage instructions reference a model version (
gemini-3-pro-image-preview) that is currently not part of the public Google Gemini model lineup. - Evidence: Found in
SKILL.mddescription andgenerate_image.pymodel parameter. - Context: While likely a placeholder or speculative name, it qualifies as deceptive metadata regarding the skill's actual backend capabilities.
Audit Metadata