Back to skill

Security audit

Nano Banana 2 商品精修

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed product-photo retouch skill that uses AI Hive for user-selected images and does not show hidden or unrelated behavior.

Before installing, confirm you are comfortable sending selected product images to AI Hive and storing an AI Hive API key locally. Review generated outputs against the original product so labels, logos, colors, quantities, defects, and other SKU facts are not accidentally changed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill advertises and demonstrates code-capable behavior including shell execution, file read/write, environment access, and network usage, but does not declare permissions. This undermines transparency and review controls, making it easier for a seemingly narrow image-retouch skill to access local files, saved credentials, or external services without users and policy engines understanding its real capabilities.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The documented purpose is tightly scoped to truthful, consistent product-photo retouching, but the described behavior exposes a general image editing/generation pipeline with arbitrary prompts, parameter passthrough, upload/task primitives, and local API-key setup. Because there is no technical enforcement of the 'do not change SKU facts' rule, the skill can be repurposed to generate misleading product imagery, alter labels or features, or perform broader operations than users expect.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.