Back to skill

Security audit

三剪客 · nano-banana

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real a7w image-generation wrapper, but it also ships a broader generic account client that can use your API key to inspect and call other platform plugins.

Install only if you are comfortable giving this client an a7w API key that may access more than the nano_banana image plugin. Use a scoped or low-balance key if the platform supports it, avoid sensitive prompts or private image URLs, use HTTPS/authenticated callbacks, and do not use --host/A7W_HOST unless you intentionally trust that destination.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is a narrow image-generation skill, but the embedded client behavior appears to support generic plugin enumeration, arbitrary schema inspection, arbitrary marketplace API calls, schema export, API key persistence, and broader task/credits queries. This mismatch is dangerous because it hides a materially broader operational surface than users would reasonably expect, enabling overbroad network access and data handling under the cover of a benign image tool.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
description: "图片生成与编辑应用,支持文生图、图生图和多规格模型选择。支持 创建图片任务、查询图片任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
description: "图片生成与编辑应用,支持文生图、图生图和多规格模型选择。支持 创建图片任务、查询图片任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language instructions, usage guidance, and safety notes are all presented only in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a justified locale constraint is documented, which is not present here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

一把 api.a7w.cn 的 API Key。完整的注册、充值、取 Key 步骤见 references/getting-started.md, 或直接去 算力集市 · 注册领 API Key。

bash
python3 scripts/client.py login --key sk-你的key

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 95)May include surrounding context.

一把 api.a7w.cn 的 API Key。完整的注册、充值、取 Key 步骤见 references/getting-started.md, 或直接去 算力集市 · 注册领 API Key。

bash
python3 scripts/client.py login --key sk-你的key

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 104)May include surrounding context.

一把 api.a7w.cn 的 API Key。完整的注册、充值、取 Key 步骤见 references/getting-started.md, 或直接去 算力集市 · 注册领 API Key。

bash
python3 scripts/client.py login --key sk-你的key

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents this as an image-generation/editing skill, but the documented client commands expose broader account and platform operations such as app enumeration, identity checks, and usage inspection. This expands the effective capability and trust boundary of the skill beyond its stated purpose, increasing the chance that users provide an API key to a tool that can access more of their account context than expected.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises executable client functionality with network, shell, file read/write, and environment access but does not declare any tool scope or permissions boundaries. In an agent ecosystem, this can cause users or hosts to underestimate what the skill can do, increasing the risk of unintended command execution, local persistence, or external data transmission.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The skill explicitly directs users to a third-party external service and centers operation around transmitting data and credentials to api.a7w.cn. External transmission is expected for this kind of integration, but it remains security-relevant because prompts, image URLs, callback endpoints, and authentication material leave the local trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: nano-banana-image
slug: nano-banana-image
displayName: 三剪客 · nano-banana
description: "图片生成与编辑应用,支持文生图、图生图和多规格模型选择。支持 创建图片任务、查询图片任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「nano-banana」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs users to provide an API key and a callback URL but does not warn that these values will be transmitted to a third-party service and may expose account access or receive sensitive job data. In this context, the callback URL also creates a server-to-server data flow that can leak prompts, image references, results, or metadata if misconfigured.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The summary repeats the need to use the third-party api.a7w.cn platform, reinforcing that skill use depends on sending user-controlled content and credentials off-platform. Even if legitimate, this creates a data exposure surface that should be disclosed and scoped clearly.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
displayName: 三剪客 · nano-banana
description: "图片生成与编辑应用,支持文生图、图生图和多规格模型选择。支持 创建图片任务、查询图片任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「nano-banana」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT
tags:
  - 三剪客

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The example call includes both a remote reference image URL and a callback URL, showing that user data and generated results may flow through multiple external endpoints. In an image-generation skill, this context makes the transmission more sensitive because prompts and image references may contain proprietary or personal content, and callback endpoints can unintentionally expose outputs or metadata.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

python3 scripts/client.py call nano_banana submit --json '{"prompt": "A clean product photo of a yellow banana-shaped speaker on a white table.", "image_urls": ["https://example.com/reference.png"], "aspect_ratio": "1:1", "callback_url": "https://example.com/api/ai/callback"}'

text

> **没有 Key?** 见 `references/getting-started.md`——注册、充值、取 Key 的完整步骤。也可以直接去 [算力集市](https://api.a7w.cn/) 注册。

## 接口一览

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly instructs users to provide external image URLs for editing, which causes user-supplied images to be transmitted to a third-party API service. Because the skill text provides no privacy notice, consent guidance, retention details, or warnings about sensitive image content, users may unknowingly upload personal or confidential images to an external processor.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is presented as an image-generation/editing client, but the code is a generic marketplace client that can enumerate apps, inspect schemas, and call arbitrary plugin APIs. That broader-than-declared capability increases the risk of over-privileged use, accidental data access, and misuse by an agent that believes it is constrained to image tasks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file includes its module docstring, CLI descriptions, help text, and runtime messages entirely in Chinese, which effectively forces a specific language for all users. The file does not offer any language selection, opt-in, or explanation that the skill is intended only for a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring advertises whoami as validating the key and showing account and balance, and points as querying balance. In code, cmd_whoami only lists accessible apps and key prefix because no account endpoint exists, while cmd_points merely sums recent task usage from /api/v1/tasks and explicitly notes that no balance API is available.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Marketplace-wide enumeration and schema dumping are unnecessary for a narrowly scoped image-task skill and materially expand reconnaissance capability. In an agent setting, this can expose unrelated plugin metadata, encourage unauthorized exploration, and increase the blast radius if the skill or its key is misused.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The documentation presents the client as tightly scoped and safe in terms of key handling, but elsewhere documents platform-wide commands like apps and schema for arbitrary plugins. While not a direct contradiction about destination host, it creates intent-level inconsistency between a skill-specific tool and a general account client.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill metadata and instructions are entirely in Chinese, which can amount to a language policy issue when no user opt-in or locale justification is provided. The file does not indicate that the skill is intentionally limited to Chinese-speaking users or offer an alternative language path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents all user-facing instructions exclusively in Chinese, which can amount to a language policy issue when no user opt-in or alternative locale is offered. There is no indication that this skill is intentionally limited to Chinese-speaking users or a China-specific compliance context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level usage text says whoami checks account and balance and points checks balance. The actual command implementations and docstrings state that the gateway does not expose account or balance endpoints, so whoami validates the key via app listing and points estimates usage from recent tasks instead.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.