Back to skill

Security audit

Nano Banana Pro

Security checks for vulnerabilities and agentic risk

Overview

This image-generation skill is mostly coherent, but it handles a Gemini API key in ways that can expose the secret and does not clearly warn before sending prompts or images to Google.

Review before installing. Prefer setting GEMINI_API_KEY in a protected environment instead of pasting keys into chat or using --api-key, avoid confidential prompts or private images unless Google API upload is acceptable, and consider pinning dependencies or using a lockfile before routine use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/generate_image.py:3
Finding

Unpinned Dependencies Permit Unreviewed Supply-Chain Changes

Content
View full analysis
=3.10" # dependencies = [ # "google-genai>=1.0.0", # "pillow>=10.0.0", # ] # /// ``` ### Technical Analysis The script declares dependencies using open-ended minimum-version constraints. When the documented `uv run` workflow resolves these dependencies, it may install any future release matching the constraints. Consequently, the code executed by the Skill can change without a corresponding change to, or security review of, the Skill package. No malicious dependency is currently identified in the audited files. The risk arises from mutable supply-chain resolution: compromise of an upstream package or publication of a malicious future version could introduce arbitrary code into the execution environment. ### Attack Path 1. An attacker compromises the release process or maintainer account of an allowed dependency, or otherwise causes a malicious satisfying version to be published. 2. A user invokes the script through the documented `uv run` workflow. 3. Dependency resolution selects and installs the malicious or compromised release because no exact version or reviewed lockfile prevents it. 4. Package-controlled code executes during installation, import, or normal API use. 5. The payload runs with the same operating-system privileges and environment access as the Agent process. ### Impact Assessment Successful exploitation could provide arbitrary code execution under the Agent user's account. Depending on local permissions, the payload could access the Gemini API key, user prompts, input images, generated output, and other files readable or writable by that account. It could also make network requests or alter user-owned files. This issue does not itself grant administrative privileges; its scope is bounded by ...[truncated 54 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_image.py:47
Finding

Gemini API Key Can Be Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs use of an environment variable (GEMINI_API_KEY) and command execution, but the metadata declares no permissions or trust boundary implications. This can mislead users and hosting systems about the skill's capability to access sensitive configuration and invoke external tooling, reducing transparency and informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill sends user prompts and potentially local input images to Google's external API, but the description and usage guidance do not clearly warn users about this data transfer. Users may unknowingly expose sensitive prompts, file contents, or proprietary images to a third party, creating privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script sends the user's prompt and, when provided, the contents of a local input image to Google's external API, but it gives no explicit privacy notice or confirmation at the point of transmission. In an agent/skill context, users may reasonably assume local processing, so sensitive prompts or images could be disclosed to a third party without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.