Back to skill

Security audit

Nano Banana 2 图片换背景

Security checks across malware telemetry and agentic risk

Overview

This skill coherently edits user-specified images through AI Hive and discloses its main network, file, and API key behavior.

Before installing, understand that selected reference images and prompts are sent to AI Hive, an AI Hive API key may be stored locally, and generated files are saved to your Downloads folder by default. Use it for intended product/background replacement tasks and avoid providing private images unless you are comfortable uploading them to the configured service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill advertises and invokes shell commands, network access, file reads/writes, and likely environment-variable use, but does not declare permissions or clearly constrain those capabilities in metadata. This creates a trust and review gap: an orchestrator or user may invoke the skill without understanding that it can access local files and send data to a remote API, increasing the risk of unintended data exposure or misuse if inputs are manipulated.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The description uses very broad trigger phrases spanning many common image-editing and e-commerce scenarios, which can cause over-invocation for unrelated user requests. That increases the chance the skill is selected in contexts where users did not intend to authorize local file handling or remote upload of images, expanding exposure to privacy and data-handling risks.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.