Back to skill

Security audit

Nano Banana 2 精准文字图片

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent image-generation helper that discloses its API use, local key storage, reference-image upload, and result downloads.

Before installing, understand that using this skill sends your prompts and any selected reference images to AI Hive, stores an API key locally if you run init, and downloads generated files to your Downloads folder. Use it with images and prompts you are comfortable sending to that provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill exposes operational capabilities including environment access, file read/write, network, and shell execution through documented commands, but does not declare permissions. This creates a trust and review gap: users or orchestrators may treat the skill as low-privilege while it can install packages, access local files, and make outbound requests, increasing the risk of unintended data exposure or command execution if the skill is invoked in a sensitive environment.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.