Back to skill

Security audit

Nano Banana 2 直播带货图片

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI image-generation helper for livestream assets that uses a fixed AI Hive API and proportionate local configuration.

Install this only if you are comfortable sending selected reference images and prompts to AI Hive, storing an AI Hive API key locally, and downloading generated images to your Downloads folder. Review prompts and uploaded images for private or sensitive content before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
76% confidence
Finding
The skill invokes shell commands, reads and writes local files, uses environment variables, and performs network requests, yet it declares no permissions or capability boundaries. This creates a trust and review gap: users may assume a simple image-prompt skill while it can persist secrets, contact external services, and manipulate local state.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The documented purpose is a narrow livestream-image workflow, but the behavior described by the finding includes API-key onboarding, browser opening, independent media upload, arbitrary task querying, and generic image generation/editing. That mismatch is dangerous because it can mislead users about the skill's true access and data flows, increasing the chance they provide secrets or sensitive images under false assumptions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.