Back to skill

Security audit

商品换背景与商业场景图|Nano Banana Pro

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed product-image background replacement tool that uploads user-selected images to AI Hive and saves generated results locally.

Install only if you are comfortable sending the selected product and background images, prompts, and task metadata to AI Hive. Use the preview command before submitting, avoid uploading unlicensed or sensitive images, and store the API key only on machines you trust.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill invokes local Python scripts, installs dependencies, reads product reference files, may write outputs, uses shell execution, and explicitly sends authentication and task requests to a remote API, yet no permissions are declared. This creates a transparency and consent problem: a user or platform may underestimate the skill's ability to access files, run commands, and communicate over the network, which increases the risk of unintended data exposure or unsafe execution in an agent environment.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.