banana

Warn

Audited by Socket on Apr 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s image-generation behavior is broadly aligned with its stated purpose, but it introduces medium trust risk by routing a Google API key through a third-party MCP package installed via mutable npx/npm paths. No clear malware or exfiltration is shown, yet install provenance and credential forwarding are not tight enough to treat as fully benign.

Confidence: 81%Severity: 62%
AnomalyLOW
scripts/setup_mcp.py

Best matching/most complete assessment is the supply-chain + credential-handling risk identification: this code itself does not show direct malware (no exfiltration or payload execution), but it (1) persistently stores a user’s Google AI API key in plaintext in `~/.claude/settings.json` and (2) configures Claude Code to run an unpinned npm package via `npx -y @ycse/nanobanana-mcp`—a significant indirect supply-chain execution vector. Additionally, `--check` prints masked key fragments, which can still leak partial secrets to terminal/log history. Review the legitimacy of the MCP package and protect/limit access to the settings file (and ideally avoid plaintext key storage).

Confidence: 72%Severity: 69%
Audit Metadata
Analyzed At
Apr 14, 2026, 07:29 AM
Package URL
pkg:socket/skills-sh/AgriciDaniel%2Fbanana-claude%2Fbanana%2F@d1b5d4e48de87f3d5d7ea5ef599deb8ef263fa1d