nano-banana

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references external installation procedures for the belt CLI tool and links to documentation and image assets hosted on the inference.sh domain and GitHub. These references are legitimate for the skill's purpose.
  • [COMMAND_EXECUTION]: The skill relies on the belt CLI tool to perform authentication and execute image generation models. The tool access is restricted to the belt command within the Bash environment.
  • [PROMPT_INJECTION]: The skill ingests user-provided text prompts and image URLs which serves as a potential surface for indirect prompt injection. 1. Ingestion points: Command arguments in Bash examples (SKILL.md). 2. Boundary markers: The skill uses structured JSON payloads for input parameters. 3. Capability inventory: Executing image generation via the belt CLI. 4. Sanitization: No explicit sanitization is shown, but the risk is mitigated by the specific scope of the tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 04:09 PM
Security Audit — agent-trust-hub — nano-banana