nano-banana-prompting

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection (LOW): The skill workflow involves ingesting user-provided 'existing prompts' and 'visual references' to guide the prompt-crafting process. This creates a surface where malicious instructions embedded in user data could influence the agent's behavior. * Ingestion points: Step 1 in SKILL.md explicitly gathers user prompts and images. * Boundary markers: The skill does not define explicit delimiters or instructions to ignore commands within the user's reference material. * Capability inventory: The skill's capabilities are restricted to gathering information via AskUserQuestion and passing the final prompt to the nano-banana skill. It lacks dangerous capabilities like shell access or file system modification. * Sanitization: No input sanitization or validation steps are described for the gathered materials.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 06:40 PM