bananahub

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s image-generation capabilities generally match its stated purpose, but its footprint includes notable trust and data-flow risks: API keys may be sent to arbitrary compatible endpoints, remote templates can be installed from repo targets, and telemetry/network destinations are not fully disclosed here. This looks more like a high-risk multi-provider integration than confirmed malware.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 8, 2026, 11:28 AM
Package URL
pkg:socket/skills-sh/bananahub-ai%2Fbananahub-skill%2Fbananahub%2F@16d8312e4e2ef246b0aa3ffa01cab8724f098ec1