nano-banana-pro
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is image generation, but the documented data flow routes prompts, images, and API keys through third-party intermediary providers while implying Google Gemini usage. The core risk is credential and content forwarding to non-official endpoints, plus inconsistent script provenance for the fallback path.
Confidence: 86%Severity: 78%
Audit Metadata