nano-banana
Warn
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions include a setup step to download and install a CLI extension from 'https://github.com/gemini-cli-extensions/nanobanana', which is an unverified third-party GitHub organization.
- [REMOTE_CODE_EXECUTION]: The command 'gemini extensions install' fetches code from a remote URL and integrates it into the execution environment, posing a risk of executing arbitrary code if the source repository is compromised or malicious.
- [COMMAND_EXECUTION]: The skill requires the agent to use the '--yolo' flag for all tool invocations. The instructions explicitly state this flag is used to 'automatically approve all tool actions' and skip confirmation prompts, which removes human-in-the-loop oversight for shell command execution.
- [PROMPT_INJECTION]: The skill uses high-priority directives such as 'REQUIRED for all image generation requests' and 'ALWAYS use this skill' in the description and instructions to override the agent's standard behavior and tool selection logic.
Audit Metadata