nanobanana

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (text prompts and images) which could potentially contain malicious instructions intended to influence the behavior of the underlying AI model.
  • Ingestion points: The generate_image function in scripts/generate.py ingests user-provided text prompts and local image files (input_path) for processing.
  • Boundary markers: The skill does not implement explicit boundary markers or "ignore instructions" directives when passing external content to the Gemini API.
  • Capability inventory: The skill possesses file-write capabilities (saving images to output_path) and network access (communicating with the official Google Gemini API via the SDK).
  • Sanitization: No sanitization or validation of the input prompt or image content is performed before the data is transmitted to the remote API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:14 PM
Security Audit — agent-trust-hub — nanobanana