Back to skill

Security audit

Nano Banana Pro 1.0.1

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent image-generation tool, but it asks agents to handle a Gemini API key in chat or command-line arguments and sends prompts/images to Google without a clear privacy warning.

Review before installing. Use this only with non-sensitive prompts and images you are willing to send to Google's API. Configure GEMINI_API_KEY outside chat and avoid passing keys on the command line. For safer operation, pin or lock dependencies before running the script in a trusted environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/generate_image.py:2
Finding

Runtime Resolution of Unpinned Third-Party Dependencies

Content
View full analysis
=3.10" # dependencies = [ # "google-genai>=1.0.0", # "pillow>=10.0.0", # ] # /// ``` The documented invocation causes `uv` to resolve these dependencies when the script is run: ```bash uv run ~/.codex/skills/nano-banana-pro/scripts/generate_image.py --prompt "your image description" --filename "output-name.png" [--resolution 1K|2K|4K] [--api-key KEY] ``` ### Technical Analysis The inline dependency metadata uses open-ended `>=` constraints without a committed lockfile, exact versions, or package hashes. Consequently, execution is not reproducible: a future package version satisfying these constraints can be selected without having been reviewed as part of this skill. Python packages may execute code during installation, import, or normal library use. The script imports and uses both dependencies after runtime resolution. Therefore, a compromised upstream release, compromised package-distribution account, or unexpectedly unsafe future release could introduce code that executes with the privileges of the user invoking the skill. No evidence was found that the current dependency names are typosquatted or presently malicious. The finding concerns the unsafe and mutable dependency-resolution model. ### Attack Path 1. An attacker compromises the publication channel or maintainer account for a declared dependency, or otherwise causes a malicious version satisfying the open-ended constraint to be published. 2. A user invokes the script through the documented `uv run` command in an environment where the affected version has not already been safely locked and cached. 3. `uv` resolves and installs the malicious or compromised version because it satisfies `google-genai>=1.0.0` or `pil ...[truncated 837 chars]
Remediation
View remediation
", # "pillow==", # ] ``` 2. Generate and commit a lockfile containing the complete transitive dependency graph. 3. Run `uv` in locked or frozen mode so execution fails rather than silently changing resolved versions. 4. Use package hashes where supported to verify downloaded artifacts. 5. Review dependency updates before modifying the lockfile, including release notes, provenance, maintainership changes, and vulnerability advisories. 6. Prefer an internal package mirror or allowlisted package registry for controlled environments. 7. Run the image-generation process in a restricted environment with only the filesystem and network access required for the task. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_image.py:53
Finding

Gemini API Key Can Be Exposed Through Command-Line Arguments

Content
View full analysis
`. 3. The command or its arguments are retained in conversation records, execution logs, shell history, process met ...[truncated 1129 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (5)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
- Prompt "A serene Japanese garden" → `2025-11-23-14-23-05-japanese-garden.png`
- Prompt "sunset over mountains" → `2025-11-23-15-30-12-sunset-mountains.png`
- Prompt "create an image of a robot" → `2025-11-23-16-45-33-robot.png`
- Unclear context → `2025-11-23-17-12-48-x9k2.png`

## Image Editing

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_image.py (reported line 23)May include surrounding context.

python
def get_api_key(provided_key: str | None) -> str | None:
    """Get API key from argument first, then environment."""
    if provided_key:
        return provided_key
    return os.environ.get("GEMINI_API_KEY")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs use of environment-derived secrets (GEMINI_API_KEY) and execution of a script, but the metadata declares no explicit tool scope or permissions. That mismatch weakens policy enforcement and makes it harder for a host agent to reason about or constrain the skill's access to sensitive resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill sends user prompts and optional input images to Google's external Nano Banana Pro API, but the instructions do not clearly warn the user that their data leaves the local environment. This can cause unintended disclosure of sensitive text, images, filenames, or embedded personal information to a third-party service.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
Examples:
- Prompt "A serene Japanese garden" → `2025-11-23-14-23-05-japanese-garden.png`
- Prompt "sunset over mountains" → `2025-11-23-15-30-12-sunset-mountains.png`
- Prompt "create an image of a robot" → `2025-11-23-16-45-33-robot.png`
- Unclear context → `2025-11-23-17-12-48-x9k2.png`

## Image Editing

Static analysis

No suspicious patterns detected.