nano-banana

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

No direct malware or code-execution backdoor is present in the provided content. The main security concern is trust and data exposure: the skill routes all prompt data to a third-party domain (api.eng0.ai) which is presented as a Gemini/Google-related service but not an official Google endpoint. Users should treat prompts as sensitive data, verify eng0.ai's trustworthiness and authentication model before use, and expect that generated images may include invisible watermarking. Overall the skill appears functionally legitimate for image generation but carries moderate supply-chain/trust risk due to the external gateway and lack of authentication details.

Confidence: 80%Severity: 55%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:47 PM
Package URL
pkg:socket/skills-sh/eng0ai%2Feng0-template-skills%2Fnano-banana%2F@279611a059eefea98bfef9f494cb25832d663130