nano-banana

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing external data.
  • Ingestion points: User-provided prompts, input images, and remote video URLs via the --video-to-image parameter.
  • Boundary markers: None identified in the skill documentation to delimit untrusted content.
  • Capability inventory: Includes file-writing capabilities through the --output flag and network interactions via API calls.
  • Sanitization: No explicit validation or content filtering mechanisms are defined in the instructions.
  • [EXTERNAL_DOWNLOADS]: The skill references well-known services and APIs for its core functionality.
  • Services: Utilizes the Google Gemini API for image generation, Google Search for grounding, and YouTube for video-to-image analysis.
  • Context: These interactions are documented and consistent with the intended use of the tool, utilizing established and reputable platforms.
  • [DATA_EXFILTRATION]: Analysis of network operations indicates communication is limited to official API endpoints and established services. No access to sensitive local files (such as credentials or SSH keys) or unauthorized data transmission patterns were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:45 PM
Security Audit — agent-trust-hub — nano-banana