nano-banana
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS. The skill's capabilities broadly match its stated purpose, but its trust model is weak: it installs and executes a personal GitHub repo with local dependency resolution, then asks the user to store and supply a Gemini API key to that code. No obvious exfiltration or proxy routing is documented, so this is not confirmed malware, but the install path and credential forwarding make it a medium-risk skill.
Confidence: 78%Severity: 62%
Audit Metadata