Back to skill

Security audit

Nano Banana Pro 直播带货图片

Security checks across malware telemetry and agentic risk

Overview

This is a coherent AI Hive image-generation skill that stores an API key and uploads user-selected media, with no evidence of automatic exfiltration, destructive behavior, or hidden active broad commands.

Install only if you are comfortable using AI Hive as the remote processor for prompts and selected media, and treat the configured API key as a billing credential. Do not point --image or upload at private files that are not meant to be sent to the service.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill manifest exposes or implies capabilities such as shell, network, file access, and environment use without declaring permissions, which weakens reviewability and informed consent. Even if the documented examples are image-generation related, undeclared execution-capable surfaces can be abused for unintended actions or data access if the backing scripts are more powerful than the description suggests.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
This is a strong description-behavior mismatch: a skill presented as a narrow livestream image generator reportedly supports broad account queries, model enumeration, chat, video generation, arbitrary media upload, and interactive browser/API-key setup. Such hidden general-purpose capabilities materially increase the attack surface and can mislead users and reviewers into granting trust or inputs they would not provide to a broader automation tool.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file implements a general-purpose AI client supporting chat, image, video, model listing, uploads, and task polling, while the declared skill is narrowly scoped to Nano Banana Pro livestream image generation. This scope mismatch is dangerous because it gives downstream users or agents access to unrelated capabilities that may bypass policy, review expectations, or least-privilege assumptions for this skill.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
Exposing user-info retrieval, including account and wallet details, is unrelated to livestream image generation and expands the data-access surface of the skill. Even if authenticated access is required, this can leak billing or account metadata through an image-focused tool where users would not reasonably expect account inspection features.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
Video generation support materially exceeds the manifest's image-only livestream asset purpose and introduces additional media-handling and remote-processing behavior not expected from this skill. In a skill ecosystem, that mismatch can enable users or agents to invoke broader capabilities than approved, undermining trust boundaries and capability-based review.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.