ClawAudit verdict
nano-banana-2
nano-banana-2-skill
Accesses credentials AND makes external network calls
Image generation skill supporting Atlas Cloud and Google AI Studio providers with explicit disclosure that local image files are uploaded to Atlas Cloud's temporary storage and explicit user confirmation required before upload.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but ClawAudit detects co-occurrence — it does not verify that one flows into another. Read the code to confirm a live chain.
Accesses credentials AND makes external network calls — potential credential theft
LLM02 · ASI03
Accesses credentials AND encodes data — may obfuscate stolen credentials
LLM02 · ASI03 · ASI04
Permission integrity
network_out
Findings (4)
Possible hardcoded credential
SKILL.md · prose · downgraded · API_KEY="your-key
Base64 encoding/decoding
SKILL.md · code · BASE64_ENCODE
Python urllib.request — network access
scripts/generate_image.py · prose · downgraded · urllib.request
Python os.environ.get — reads environment variable
scripts/generate_image.py · prose · downgraded · os.environ.get(
Permissions & capabilities
Requires 2 environment variables. (2 sensitive: ATLASCLOUD_API_KEY, GEMINI_API_KEY).
network_outcredential_accessdata_encoding Thanks — recorded.