nano-banana

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated purpose, but its trust model is weak: it installs and executes a personal GitHub repo with local dependency resolution, then asks the user to store and supply a Gemini API key to that code. No obvious exfiltration or proxy routing is documented, so this is not confirmed malware, but the install path and credential forwarding make it a medium-risk skill.

Confidence: 78%Severity: 62%
Audit Metadata
Analyzed At
Mar 18, 2026, 12:48 AM
Package URL
pkg:socket/skills-sh/kingbootoshi%2Fnano-banana-2-skill%2Fnano-banana%2F@d11ce0c8c2db92853b426cecccb930e08e4c5c12