nanobanana
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data (text prompts and images) which could potentially contain malicious instructions intended to influence the behavior of the underlying AI model.
- Ingestion points: The
generate_imagefunction inscripts/generate.pyingests user-provided text prompts and local image files (input_path) for processing. - Boundary markers: The skill does not implement explicit boundary markers or "ignore instructions" directives when passing external content to the Gemini API.
- Capability inventory: The skill possesses file-write capabilities (saving images to
output_path) and network access (communicating with the official Google Gemini API via the SDK). - Sanitization: No sanitization or validation of the input prompt or image content is performed before the data is transmitted to the remote API.
Audit Metadata