Back to skill

Security audit

Nano Banana Pro 角色一致性图片

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI image-generation helper that uploads only user-selected reference images and stores an AI Hive API key when the user runs setup.

Before installing, be comfortable sending selected reference images and prompts to AI Hive, storing an AI Hive API key locally, and installing the requests dependency. Use only images you have rights to use, especially for real people or commercial likenesses.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill invokes a local Python script with capabilities that include network access, shell execution, environment-variable use, and file read/write, yet no explicit permissions are declared. This creates a transparency and consent gap: an agent or user may run the skill without understanding that it can open browser pages, write credentials to disk, upload local images, and contact external services.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.