ClawAudit verdict
poyo-nano-banana
The skill uses PoYo AI Nano Banana, which could be used for malicious purposes if not properly restricted.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Possible hardcoded credential
scripts/submit_nano_banana.sh ยท prose ยท downgraded ยท api_key="${POYO_API_KEY:-${1:-}}
References webhook/callback URL
SKILL.md ยท prose ยท downgraded ยท callback_url
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: POYO_API_KEY). Requires 1 system binary. (1 elevated: curl).
Is this flag fair?
Thanks โ recorded.