スキル nano-banana-blockrun
📦

nano-banana-blockrun

コンテンツリビジョン r2 高リスク 🌐 ネットワークアクセス📁 ファイルシステムへのアクセス⚙️ 外部コマンド

BlockRunで有料AI画像を生成

画像生成では、多くの場合、別個のAPIキーと課金設定が必要です。このスキルはBlockRun x402 paymentsを使用し、対応モデルでプロンプトから画像を生成します。

対応: Claude Codex Code(CC)
⚠️ 38 不十分

自分のエージェントでインストール

このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。

エージェントリクエスト
Review the Skillstore skill "nano-banana-blockrun" from https://skillstore.io/skills/blockrunai-nano-banana-blockrun.md and its manifest at https://skillstore.io/api/skills/blockrunai-nano-banana-blockrun/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。

エージェントが読めるリソース

AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。

テストする

「nano-banana-blockrun」を使用しています。 山々に沈む夕日の画像を生成してください。

期待される結果:

このスキルはBlockRunを通じて画像を生成し、ホストされた画像URLまたは保存されたPNGパスのいずれかを返します。

「nano-banana-blockrun」を使用しています。 デザイン提案用に、モダンなキッチンの高品質な画像を作成してください。

期待される結果:

このスキルは対応モデルを選択し、有料生成のためにプロンプトを送信し、プロバイダーから返された修正済みプロンプトがあれば報告します。

「nano-banana-blockrun」を使用しています。 生成された画像を自分のプロジェクトアセットフォルダに保存してください。

期待される結果:

スクリプトは返されたPNG画像を指定された出力ディレクトリに書き込み、最終的なファイル場所を出力します。

セキュリティ監査

高リスク

Most URL, hidden-directory, Git ignore, and Markdown fence detections are benign documentation. Confirmed risks involve plaintext wallet-key handling and transmitting prompts and payment signatures to BlockRun. Additional risks include an unpinned executable dependency with key access and paid requests without approval or spending limits.

5
スキャンされたファイル
421
解析済み行数
1
レビュー項目
0
誤検知を無視

確認済みのセキュリティ上の懸念 (9)

高
Crypto seed/private key mention
# Your EVM wallet private key (with 0x prefix)
The template directs users to provide a raw EVM private key for a wallet holding USDC. Compromise of that plaintext credential can cause financial loss.
高
Environment file access
cp .env.example .env
The setup creates a plaintext .env file that the next instruction populates with a wallet private key. Local exposure of that file can compromise funds.
高
Environment file access
# Edit .env and add your private key
The instruction explicitly tells users to store a wallet private key in .env. This creates a high-impact local secret requiring strong protection.
高
Crypto seed/private key mention
# Edit .env and add your private key
The documented setup requires a raw wallet private key. Theft of this credential permits unauthorized signing and potential loss of wallet funds.
高
Environment file access
# Copy .env.example to .env and add your key
The comment directs users to add a wallet private key to a plaintext .env file. That credential can authorize payments if exposed.
高
Environment file access
cp .env.example .env
The command creates the .env file used for the wallet key. Although legitimate setup, it establishes sensitive plaintext storage.
高
Crypto seed/private key mention
3. Set your wallet private key:
The skill requires users to supply a raw wallet private key to enable paid requests. Credential compromise can lead to unauthorized transactions.
高
Unpinned Dependency Handles Wallet Credentials
The skill installs the latest blockrun-llm package, then runs it while a wallet private key is available. The audited files cannot verify the package's local-signing assurance.
The package command has no version constraint, and the documented client runs with the configured wallet key. No package implementation is present in the audited files.
確認済みの9件をすべて表示
高
Paid Requests Lack Approval and Spending Limits
The generation flow signs a USDC payment for each request, but the skill requires no per-request approval, request limit, or maximum charge.
The skill documents prices and automatic payment signing, while no approval or spending-control step appears in the workflow.
機能レビュー項目 (1)

これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。

低
Hardcoded URL
1. Your request goes to BlockRun API (https://blockrun.ai)
The documented workflow sends user prompts to the BlockRun API and later sends a payment signature. This is expected but real external data transmission.
監査者: codex 監査履歴を表示 →
このレポートを共有・引用

バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。

バージョン別レポートを開く
セキュリティ評価

レポートリンクをコピー

https://skillstore.io/skills/blockrunai-nano-banana-blockrun/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdownバッジ

[![Skillstore security assessment](https://skillstore.io/badges/skills/blockrunai-nano-banana-blockrun/security.svg)](https://skillstore.io/skills/blockrunai-nano-banana-blockrun?utm_source=security_passport_badge)

HTMLバッジ

<a href="https://skillstore.io/skills/blockrunai-nano-banana-blockrun?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/blockrunai-nano-banana-blockrun/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

埋め込みカード

<iframe src="https://skillstore.io/embed/skills/blockrunai-nano-banana-blockrun.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
学術引用 (APA · BibTeX · CFF)

APA形式の引用

BlockRunAI. (2026). nano-banana-blockrun security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/blockrunai-nano-banana-blockrun/audits/9

BibTeX形式の引用

@techreport{blockrunai-blockrunai-nano-banana-blockrun-2026, author = {BlockRunAI}, title = {nano-banana-blockrun security audit report (audit version 9)}, institution = {Skillstore}, year = {2026}, number = {9}, url = {https://skillstore.io/skills/blockrunai-nano-banana-blockrun/audits/9}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "nano-banana-blockrun security audit report (audit version 9)" version: "unspecified" type: report authors: - name: "BlockRunAI" date-released: "2026-07-23" url: "https://skillstore.io/skills/blockrunai-nano-banana-blockrun/audits/9" identifiers: - type: other value: "skillstore:blockrunai-nano-banana-blockrun:audit:9" description: "Skillstore immutable audit report identifier"

Skillstore スコア

このスコアの理由 証拠の信頼度: 中
55
アーキテクチャ
85
保守性
87
コンテンツ
71
コミュニティ
91
仕様準拠

作成できるもの

デザインコンセプトを作成

ムードボード、ランディングページ、クリエイティブな探索のための手早いビジュアルコンセプトを生成します。

プロジェクトアセットを作成

Claude CodeまたはCodex内で作業しながら、シンプルなイラスト素材を作成します。

x402ワークフローをテスト

実用的な画像タスクを使って、Base上のUSDCマイクロペイメントによる有料AIリクエストを検証します。

これらのプロンプトを試す

シンプルな画像を作成
ノート、コーヒーカップ、柔らかな朝の光がある静かな机の画像を生成してください。
より高品質なモデルを選択
コンパクトな電動キャンピングカーの詳細なコンセプト画像を生成してください。利用可能であればNano Banana Proを使用してください。
製品ビジュアルを作成
プライバシー重視のノートアプリ向けに、クリーンな製品ヒーロー画像を生成してください。落ち着いたオフィス環境を使用し、表示される文字は含めないでください。
生成の詳細を報告
未来的な交通ステーションの画像を生成してください。実行前に、モデル、推定コスト、出力フォルダ、ウォレットアドレスを示してください。

ベストプラクティス

  • 画像生成には、少額のUSDC残高を持つ専用ウォレットを使用してください。
  • 機密情報や個人情報をBlockRunに送信する前に、プロンプトを確認してください。
  • 繰り返し実行する前に、モデル、推定価格、出力ディレクトリを確認してください。

回避

  • 主要ウォレットの秘密鍵をプロジェクトの.envファイルに置かないでください。
  • ウォレット残高とコストを監視せずに、生成を繰り返し実行しないでください。
  • 機密情報、規制対象データ、顧客データを画像プロンプトで送信しないでください。

よくある質問

このスキルは何をしますか?
Claude、Codex、またはClaude Codeが、BlockRun対応画像モデルを通じて画像を生成するのを支援します。
APIキーは必要ですか?
APIキーは記載されていません。このワークフローは、Baseネットワーク上のUSDCによるx402 paymentsを使用します。
どの支払い方法を使用しますか?
生成画像リクエストごとに、Base上のUSDCマイクロペイメントを使用します。
生成された画像はどこに保存されますか?
Base64 PNGの結果は、選択した出力ディレクトリに保存されます。その他の画像結果はURLとして出力される場合があります。
ウォレットキーは自分のマシン外に送信されますか?
ドキュメントでは、署名はローカルで行われるとされています。それでもユーザーはキーを機密情報として扱い、制限付きのウォレットを使用するべきです。
自動インストールは推奨されますか?
このスキルはウォレットキーを扱い、パッケージをインストールし、ネットワーク呼び出しを行い、資金を消費するため、手動レビューが推奨されます。

開発者情報

作成者

BlockRunAI

ライセンス

MIT

Skillstore リビジョン

r2

バージョンに関する注意

作者はバージョンを宣言していません。

参照

a39a91716eadede5f4cdefd78178fed4e837a128

メンテナンスの新しさ

2026/7/25

利用状況

6 ダウンロード · 287 閲覧

ファイル構成

すべて表示