nano-banana

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is entirely composed of instructional markdown and configuration files. It does not contain any executable scripts, binaries, or automated code triggers.
  • [NO_CODE]: No code was shipped with the skill, which minimizes the risk of local command execution or persistence mechanisms.
  • [SAFE]: No hardcoded credentials or sensitive data exfiltration patterns were identified. The skill correctly references external tool files for handling API connections and authentication.
  • [SAFE]: The skill includes defensive instructions that mandate refusing the generation of real identifiable individuals and copyrighted intellectual property, aligning with safety and brand-security best practices.
  • [PROMPT_INJECTION]: The skill ingests untrusted user input to formulate image prompts, creating a surface for indirect prompt injection.
  • Ingestion points: User requests for images in SKILL.md and brand-profile.md.
  • Boundary markers: Absent in the provided natural-language prompt templates.
  • Capability inventory: Image generation and upload via tools/integrations/nano-banana.md.
  • Sanitization: The skill instructs the agent to verify rendered text and labels for accuracy before publishing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 02:27 PM
Security Audit — agent-trust-hub — nano-banana