nano-banana

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent, but it depends on third-party MCP packages that receive the Gemini API key and mediate all image requests. That makes the main risk supply-chain trust and credential forwarding, not confirmed malware. The misleading claim about local-only processing further weakens data-flow integrity.

Confidence: 83%Severity: 66%
Audit Metadata
Analyzed At
Apr 18, 2026, 03:44 AM
Package URL
pkg:socket/skills-sh/ckorhonen%2Fclaude-skills%2Fnano-banana%2F@74ab7397a3bf7def5a08d46e0ac618ad813aef3c