Back to skill

Security audit

Work Productivity Nano Banana Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

The skill is not malicious, but it should be reviewed because its automatic activation rules are much broader than its stated Nano Banana Pro workflow purpose.

Install only if you are comfortable with this skill being considered for broad productivity, editing, image, and bug-fix prompts. A safer version should narrow activation to explicit Nano Banana Pro or full skill-name requests and avoid implicit invocation for generic terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
89% confidence
Finding
The trigger phrases are extremely broad, overlapping with common terms like 'nano', 'banana', 'pro', 'generate', and 'edit', which can cause the skill to activate in unrelated contexts. In an agent ecosystem, this increases the risk of unintended invocation, context hijacking, or the skill influencing workflows the user did not explicitly request.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords and example invocations are broad, generic terms such as 'nano', 'pro', 'generate', 'edit', and 'bug fix', which are likely to match many ordinary user requests unrelated to this specific skill. This can cause unintended skill activation, routing user requests into the wrong workflow, and potentially exposing users to incorrect guidance or unexpected prompt/context injection from an unrelated skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keyword list includes extremely generic terms like "nano," "banana," "pro," "generate," "edit," and "images," which can cause this skill to activate for many unrelated user requests. Overbroad activation increases the chance of unintended routing, causing irrelevant instructions to be injected into conversations and potentially interfering with safer or more appropriate skills.

Vague Triggers

High
Confidence
89% confidence
Finding
The manifest description says to use the skill when a user asks for broad concepts like work-productivity, practical workflow, artifact, checklist, analysis, or implementation support, which are common across many unrelated tasks. This ambiguous activation guidance can make the skill match far outside its intended niche, leading to prompt-surface expansion and misrouting of user requests.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger sentences are phrased so broadly that they reinforce permissive activation behavior rather than demonstrating precise intended use. While not directly exploitable on their own, they train routing toward false positives and increase the likelihood that unrelated user prompts will invoke this skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keyword list is overly broad and includes generic terms like 'nano', 'banana', 'pro', 'generate', 'edit', and 'images', which can match many unrelated user requests. This can cause unintended skill activation, making the agent apply this workflow outside its intended scope and potentially override more appropriate skills or user intent.

Vague Triggers

High
Confidence
93% confidence
Finding
The description defines activation conditions using very broad criteria like 'when a user asks for work-productivity, nano-banana-pro, nano, banana, pro, or needs a practical workflow, artifact, checklist, analysis, or implementation support'. This ambiguous scope is dangerous because it can capture a large number of unrelated productivity or implementation requests, leading to prompt-routing errors and unintended behavior.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are malformed, truncated, and too vague to establish a safe invocation boundary. Poorly formed examples can train maintainers or routing systems to accept partial, ambiguous matches, increasing the chance of accidental activation for unrelated requests.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt is phrased as a broad, natural-language trigger and includes generic terms like 'help me' and common workflow/productivity concepts, which can cause unintended or implicit invocation outside narrowly scoped user intent. Because implicit invocation is enabled, this increases the chance the skill is selected in unrelated contexts, potentially exposing users to unneeded automation, prompt interference, or expanded attack surface from adversarial skill behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger examples are broad and include generic phrases like asking for a 'practical workflow', which can match ordinary user requests unrelated to this skill's intended scope. This can cause unintended activation, leading the agent to inject irrelevant instructions or artifacts into unrelated tasks and reducing reliability or safety of downstream behavior.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The usage signals and trigger sentences do not clearly bound when the skill should run, mixing specific product references with very general language. In an agent environment, ambiguous activation criteria can over-match many unrelated prompts, causing prompt-routing errors, context pollution, and accidental execution of instructions not meant for the user's actual task.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.