nano-banana
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is entirely composed of instructional markdown and configuration files. It does not contain any executable scripts, binaries, or automated code triggers.
- [NO_CODE]: No code was shipped with the skill, which minimizes the risk of local command execution or persistence mechanisms.
- [SAFE]: No hardcoded credentials or sensitive data exfiltration patterns were identified. The skill correctly references external tool files for handling API connections and authentication.
- [SAFE]: The skill includes defensive instructions that mandate refusing the generation of real identifiable individuals and copyrighted intellectual property, aligning with safety and brand-security best practices.
- [PROMPT_INJECTION]: The skill ingests untrusted user input to formulate image prompts, creating a surface for indirect prompt injection.
- Ingestion points: User requests for images in SKILL.md and brand-profile.md.
- Boundary markers: Absent in the provided natural-language prompt templates.
- Capability inventory: Image generation and upload via tools/integrations/nano-banana.md.
- Sanitization: The skill instructs the agent to verify rendered text and labels for accuracy before publishing.
Audit Metadata