nanobanana-image-generation
Audited by Socket on Mar 12, 2026
1 alert found:
Obfuscated FileThe skill demonstrates coherent purpose-capability alignment for Gemini-based image generation/editing with structured workflow and environment-based configuration. The primary security considerations are: (1) reliance on potentially untrusted third-party endpoints as a base_url substitute, (2) handling of API keys and secret files with adequate local protection, and (3) data flows to external APIs and back to local storage. Overall, the footprint is proportionate to its stated purpose, but the use of non-official proxy endpoints elevates security risk modestly. Treat as SUSPICIOUS for the base_url flexibility (due to data-path exposure risk) but BENIGN in intent given standard API-key usage and normal image-generation workflows.