Back to skill

Security audit

nano-banana

Security checks across malware telemetry and agentic risk

Overview

This skill is a prompt-writing guide for AI social-media images, with disclosed brand-context use and no hidden execution or credential behavior.

Before installing, understand that this skill guides an agent to use brand styling and possibly reference images to draft AI image prompts for social posts. Review generated images, spelling, data, and disclosure requirements before publishing, especially if another integration is used to upload or attach the image to a post.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The phrase "for the Korean market" introduces a locale-specific output constraint in natural language. The file does not indicate that this is user-selected, optional, or justified as a region-specific workflow, which can conflict with the policy requiring language/locale choice or clear documentation.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.