nano-banana-2
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill uses
pnpm dlxto download and run the@pilio/clipackage. This is the official tool provided by the vendor, pilioai, to facilitate API interactions. - [COMMAND_EXECUTION]: Shell commands are invoked to perform image generation and task management. These commands use arguments derived from user prompts and local image paths.
- [EXTERNAL_DOWNLOADS]: The
@pilio/clipackage is fetched from the standard NPM registry at runtime, ensuring that the latest official version of the vendor's tool is used.
Audit Metadata