Back to skill

Security audit

Nano Banana 2 电商主图

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI image-generation helper for ecommerce product images with proportionate API, upload, credential, and download behavior.

Before installing, be aware that reference images you choose are uploaded to AI Hive or its returned object-storage upload URL, generated outputs are downloaded locally, and an API key may be stored in your home directory if you run init. Review platform rules yourself before publishing ecommerce images.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding
The skill invokes shell commands, reads and writes files, uses environment-derived configuration, and makes network requests, yet it does not declare any permissions or capability boundaries. This creates a transparency and policy-enforcement gap: a host may expose more power than users expect, and reviewers cannot easily verify whether the network/file operations are appropriately constrained.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.