nano-banana-2

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The artifact is documentation for a remote image-generation skill that requires installing a third-party CLI and authenticating to remote services. I found no direct embedded malicious code or obfuscated payloads in the document itself. However, several supply-chain and privacy risks are present and should be mitigated: (1) avoid curl|sh installer patterns — prefer explicit download and checksum/signature verification before execution; (2) require and document least-privilege, scoped tokens and secure local storage for `infsh login`; (3) audit transitive npm packages before `npx skills add` and minimize transitive installs; (4) treat uploads of images and prompts as potential data-exfiltration vectors and avoid sending sensitive material; (5) restrict allowed tools/permissions to least privilege and be cautious enabling web grounding which can introduce prompt-injection risks. Operationally this package should be treated as useful but medium supply-chain risk until installation and transitive dependencies are audited.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 10:13 AM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fnano-banana-2%2F@f2494fc20f1c2985d07c1b329c9533ff80a2c86a