Back to skill

Security audit

Nanobanana Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Gemini image-generation helper, with privacy and dependency hygiene caveats users should understand before sending prompts or images.

Install only if you are comfortable sending your prompts and any selected input images to Google's Gemini API. Prefer setting GEMINI_API_KEY in the environment rather than passing it on the command line, avoid confidential or regulated images unless external processing is approved, and consider pinning dependencies or using a lockfile for repeatable installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/generate_image.py:3
Finding

Unbounded Dependency Versions Allow Unreviewed Supply-Chain Code

Content
View full analysis
=3.10" # dependencies = [ # "google-genai>=1.0.0", # "pillow>=10.0.0", # ] # /// ``` ### Technical Analysis The inline dependency metadata specifies only minimum versions for `google-genai` and `pillow`. When the documented `uv run` command resolves these dependencies without an enforced lockfile, it may install any future release satisfying the constraints. Consequently, the code executed by this Skill can change without any modification to the audited repository. A compromised package release, malicious maintainer update, or dependency-account takeover could introduce attacker-controlled installation or runtime code. This finding concerns unsafe version mutability. No evidence was found that the currently named packages are malicious, typosquatted, or sourced from an unauthorized registry. ### Attack Path 1. An attacker compromises the publication process or maintainer account for an allowed dependency. 2. The attacker publishes a malicious version satisfying `google-genai>=1.0.0` or `pillow>=10.0.0`. 3. A user invokes the documented `uv run scripts/generate_image.py` command in an environment without a previously enforced lock. 4. `uv` resolves and installs the malicious release. 5. Attacker-controlled code executes during package installation, import, or subsequent API use with the privileges of the user running the Skill. ### Impact Assessment Successful exploitation could provide arbitrary code execution with the invoking user's privileges. Depending on that user's environment, the attacker could read accessible files and environment variables, including `GEMINI_API_KEY`, alter project data, make network requests, or compromise other resources available to the account. This issue does not independentl ...[truncated 83 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/generate_image.py:33
Finding

Gemini API Key Can Be Exposed Through Command-Line Arguments

Content
View full analysis
str | None: """Get API key from argument first, then environment.""" if provided_key: return provided_key return os.environ.get("GEMINI_API_KEY") ``` ```python parser.add_argument( "--api-key", "-k", help="Gemini API key (overrides GEMINI_API_KEY env var)" ) ``` The module usage text also advertises this credential-passing mechanism: ```python Usage: uv run generate_image.py --prompt "your image description" --filename "output.png" [--resolution 1K|2K|4K] [--api-key KEY] ``` ### Technical Analysis Passing an API key with `--api-key` places the secret in the command-line argument vector. Depending on the operating system and execution environment, command arguments may be observable through process inspection, shell history, job-control records, audit systems, telemetry, debugging output, or CI/CD logs. The script does not directly print the API key, and the documented Skill workflow primarily recommends `GEMINI_API_KEY`. Nevertheless, retaining and advertising the command-line option creates an avoidable credential-disclosure path. ### Attack Path 1. A user invokes the script with `--api-key REAL_SECRET`. 2. The shell records the command in history, or process-monitoring and job-telemetry systems capture its argument vector. 3. A local user or operator with access to those records retrieves the exposed key. 4. The attacker uses the key directly against the Gemini API until the credential is revoked or its quota and policy controls prevent further use. This path requires access to local process information, command history, logs, or telemetry containing the invocation. ### Impact Assessment An exposed key could allow unauthorized Gemini API requests un ...[truncated 308 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_image.py (reported line 34)May include surrounding context.

python
def get_api_key(provided_key: str | None) -> str | None:
    """Get API key from argument first, then environment."""
    if provided_key:
        return provided_key
    return os.environ.get("GEMINI_API_KEY")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README presents the skill as 'Zero Config' and focuses on local usage details, but it does not disclose that prompts and uploaded input images are transmitted to Google's Gemini API for processing. This can mislead users into sending sensitive text or images to a third-party service without informed consent, creating privacy, compliance, and data-handling risks.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill requires access to the GEMINI_API_KEY environment variable but does not declare an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes the skill's access expectations less transparent to the agent runtime and user, increasing the chance of unintended secret exposure or overly broad execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to send prompts and potentially up to 14 input images to the Gemini Image API, but it does not clearly warn that this content is transmitted to a third-party service. In contexts involving private, proprietary, or sensitive images, this omission can cause inadvertent data disclosure because users may assume processing is local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends user prompts and optional local input images to Google's Gemini API, but the top-level documentation does not clearly warn users that their text and image content will be transmitted to a third-party remote service. In a skill context that may be invoked by agents on behalf of users, this omission increases the risk of accidental disclosure of sensitive prompts or local image data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.