nano-banana-2

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the belt-sh/cli tool and the inferencesh Python package, which are necessary for the skill's core functionality of interacting with the inference.sh API.
  • [COMMAND_EXECUTION]: The instructions utilize the belt CLI to run image generation apps. The skill's configuration limits the agent's shell access specifically to this command.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface where it processes user-provided prompts and image URLs.
  • Ingestion points: The prompt and images input parameters in the belt app run command and the Python SDK methods.
  • Boundary markers: Not present.
  • Capability inventory: Execution of the belt command and network access to the inference service.
  • Sanitization: No explicit sanitization of input text or image links is described in the provided documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:19 PM
Security Audit — agent-trust-hub — nano-banana-2