evolink-nano-banana-2

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This SKILL manifest appears coherent with its stated purpose: it requires an Evolink API key, sends user prompts and uploaded images to Evolink's documented endpoints, and recommends using a third-party MCP package to manage generation and file hosting. There is no explicit malicious code or obfuscation in the manifest itself. The primary risks are supply-chain and credential-forwarding: recommending npx installation of @evolinkai/evolink-media and instructing the user/agent to provide EVOLINK_API_KEY to MCP tooling means a third-party package will receive and use that key and handle user data. That transitive trust and the network-forwarding of user-supplied images/prompts are the main security concerns. I classify this as not overtly malicious but carrying moderate supply-chain/credential risk; operators should audit the referenced npm package and limit the API key scope (least privilege), and avoid uploading sensitive images unless the provider's policies are reviewed.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 01:43 AM
Package URL
pkg:socket/skills-sh/EvoLinkAI%2FNano-banana-2-skill-for-openclaw%2Fevolink-nano-banana-2%2F@2d02d126a38227c8a2901b560ff5f5a14fc6a3be