nano-banana
Warn
Audited by Socket on Apr 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose is coherent, but it depends on third-party MCP packages that receive the Gemini API key and mediate all image requests. That makes the main risk supply-chain trust and credential forwarding, not confirmed malware. The misleading claim about local-only processing further weakens data-flow integrity.
Confidence: 83%Severity: 66%
Audit Metadata