nano-banana-2
Fail
Audited by Socket on Feb 26, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The material documents a legitimate convenience wrapper (inference.sh CLI) to access Google Gemini image generation. I found no explicit malicious code or backdoor in the provided text. The primary risks are supply-chain and privacy: a download-and-execute install pattern and routing all prompts/images through a third-party service (inference.sh / dist.inference.sh) that becomes a central trust and exfiltration point. Users should verify installers, review credential handling, and avoid uploading sensitive data. Overall the snippet is not clearly malicious but warrants caution due to distribution and data-handling risks.
Confidence: 98%Severity: 90%
Audit Metadata