Back to skill

Security audit

Nano Banana Pro 电商主图

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent AI image-generation helper that uses an external AI Hive API and local API-key configuration, with no evidence of hidden exfiltration or destructive behavior.

Install only if you are comfortable using AI Hive: the skill can upload selected reference images to that service, spend API credits through your API key, open a browser for setup, store the key locally, and download generated files to your Downloads folder.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding
The skill declares no permissions, yet its documented commands clearly require shell execution, network access, environment-variable use, and likely file read/write. This creates a transparency and least-privilege problem: users and hosting agents may authorize or invoke the skill without understanding that it can install packages, contact external services, and process local files.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The skill is presented as a narrowly scoped ecommerce main-image generator, but the underlying tool appears to support much broader actions including account queries, generic chat, media uploads, browser-based API-key setup, and other OpenAPI operations. That mismatch is dangerous because it can cause over-trust and over-authorization, letting a seemingly simple image skill become a general-purpose external-service client with access to user data and credentials.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.