nanobanana

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core image-generation purpose matches the skill, and the official Gemini endpoint/model references are coherent. The main risk is the custom gateway design: it allows prompts, images, and API credentials to be sent to arbitrary non-Google endpoints, with auto auth potentially forwarding both bearer and API-key credentials. That is a meaningful data-flow and credential-forwarding concern, though not confirmed malware.

Confidence: 89%Severity: 63%
Audit Metadata
Analyzed At
Apr 23, 2026, 06:22 AM
Package URL
pkg:socket/skills-sh/gargantuax%2Fopenskills%2Fnanobanana%2F@00f81d296b8ddad9751b45e8231dbbd565b83ba9