Back to skill

Security audit

Nano Banana Image

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent CellCog image-generation helper, but users should remember that prompts and images may be sent to a third-party service.

Install only if you are comfortable using CellCog as a third-party image service. Do not submit secrets, regulated data, proprietary images, or private likenesses unless you have approval and understand CellCog's privacy and retention terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to send prompts and potentially image-related content to a third-party service (CellCog/Nano Banana) but does not clearly disclose that user data will leave the local agent environment. This can lead to unintentional exposure of sensitive prompts, proprietary images, or personal data, especially because the skill encourages broad image-generation and editing workflows that may include uploaded reference material.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.