nano-banana

Fail

Audited by Socket on Mar 21, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The core capability is coherent for an image-generation skill, but it depends on a remote CLI installed via curl|sh, forwards auth and content through inference.sh instead of direct Google endpoints, and encourages transitive skill installation. This looks more like a platform wrapper than a direct Gemini integration; risk is medium from install trust and intermediary data flow, not confirmed malware.

Confidence: 84%Severity: 54%
Audit Metadata
Analyzed At
Mar 21, 2026, 01:40 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Fnano-banana%2F@630b455a3363c9bf3896c53f5f0992eb8e776da7