Nano Banana 2 Image Generation Master
Warn
Audited by Snyk on Mar 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly accepts arbitrary external URLs as "image_input" and an optional "google_search" grounding parameter in SKILL.md/master_prompt_reference.md and the scripts (scripts/generate_kie.py) pass those fields to the remote API and download remote images, meaning untrusted public web content can be ingested and materially influence generation behavior.
Audit Metadata