nano-banana
Pass
Audited by Gen Agent Trust Hub on Mar 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation includes a 'Quick Start' command that uses curl | sh to install the infsh CLI from the vendor's website.
- [COMMAND_EXECUTION]: The skill is configured to use the infsh CLI tool. The allowed-tools frontmatter correctly restricts the agent's execution environment to only allow commands prefixed with infsh, which prevents the execution of the installation script or other unauthorized commands.
Audit Metadata