Skills nano-banana-edit
๐Ÿ“ฆ

nano-banana-edit

Content revision r2 High Risk โš™๏ธ External commands๐ŸŒ Network access๐Ÿ“ Filesystem access

Edit Images with Nano Banana 2

Image edits often change subjects, framing, or branding unintentionally. This skill structures Nano Banana 2 requests for focused edits, consistent batches, and controlled outputs through RunComfy.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "nano-banana-edit" from https://skillstore.io/skills/agentspace-so-nano-banana-edit.md and its manifest at https://skillstore.io/api/skills/agentspace-so-nano-banana-edit/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "nano-banana-edit". Keep the portrait subject unchanged and replace only the office background with a bright studio wall.

Expected outcome:

One edited portrait with the original subject and pose, a bright studio wall, and the requested file format.

Using "nano-banana-edit". Apply the same neutral background, square framing, and resolution to three product images.

Expected outcome:

  • Three edited product images with matching backgrounds.
  • Consistent square framing and resolution across the batch.
  • Downloaded files stored in the selected output directory.

Using "nano-banana-edit". Remove only the leftmost object from a still life while preserving the table and lighting.

Expected outcome:

An edited still life without the leftmost object, while the remaining objects, table, and lighting stay consistent.

Security Audit

High Risk
v6 โ€ข 7/23/2026 Open versioned report

Most flags are false positives caused by Markdown backticks, placeholder URLs, and a documented token path. The skill still recommends unpinned package execution and sends prompts and image references to RunComfy. Its shell examples do not adequately protect generated user text from shell quoting failures.

1
Files scanned
186
Lines analyzed
3
Review items
0
False positives ignored

Confirmed security concerns (2)

High
Unsafe Shell Boundary for Generated Prompt JSON
The examples place JSON inside a single-quoted shell argument, while the skill states that user prompts enter this argument. CLI-side non-expansion cannot stop shell parsing before the CLI starts.
The documented Bash form has a real quoting boundary, and line 182 confirms user prompt data reaches that argument. Exploitation depends on how the agent constructs and launches the command.
Medium
Third-Party Prompt and Image Disclosure
RunComfy receives the edit prompt and fetches user-provided image URLs. Sensitive images, signed URLs, and prompt content therefore leave the local environment.
The skill explicitly documents public input URLs, API submission, server-side fetching, and outbound service domains.
Capability review items (3)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Ruby/shell backtick execution
```bash
The fenced block contains an unpinned npx command that can download and execute npm code while installing a community skill globally.
Medium
Ruby/shell backtick execution
1. **RunComfy CLI** โ€” `npm i -g @runcomfy/cli`
The prerequisite directs users to install an unpinned npm package globally. Package installation can execute lifecycle code with the user's privileges.
Low
Hardcoded URL
The skill invokes `runcomfy run google/nano-banana-2/edit` with a JSON body matching the schema. The
The paragraph explicitly states that the CLI posts requests to the RunComfy API, polls results, and downloads generated files. This is expected functionality but real outbound network activity.
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/agentspace-so-nano-banana-edit/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/agentspace-so-nano-banana-edit/security.svg)](https://skillstore.io/skills/agentspace-so-nano-banana-edit?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/agentspace-so-nano-banana-edit?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/agentspace-so-nano-banana-edit/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/agentspace-so-nano-banana-edit.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

agentspace-so. (2026). nano-banana-edit security audit report (audit version 6) [Author version unspecified]. Skillstore. https://skillstore.io/skills/agentspace-so-nano-banana-edit/audits/6

BibTeX citation

@techreport{agentspace-so-agentspace-so-nano-banana-edit-2026, author = {agentspace-so}, title = {nano-banana-edit security audit report (audit version 6)}, institution = {Skillstore}, year = {2026}, number = {6}, url = {https://skillstore.io/skills/agentspace-so-nano-banana-edit/audits/6}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "nano-banana-edit security audit report (audit version 6)" version: "unspecified" type: report authors: - name: "agentspace-so" date-released: "2026-07-23" url: "https://skillstore.io/skills/agentspace-so-nano-banana-edit/audits/6" identifiers: - type: other value: "skillstore:agentspace-so-nano-banana-edit:audit:6" description: "Skillstore immutable audit report identifier"

Compare variants

3 installable variants

Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.

Why this variant is first

Higher Skillstore usage
runcomfy-com Recommended

runcomfy-com-nano-banana-edit

Skillstore Score 50
Evidence Confidence High
Skillstore usage 9
Updated

2026-08-21

doany-ai-nano-banana-edit

Skillstore Score 50
Evidence Confidence High
Skillstore usage 7
Updated

2026-08-21

agentspace-so-nano-banana-edit

Skillstore Score 38
Evidence Confidence High
Skillstore usage 6
Updated

2026-08-21

Skillstore Score

Why this score Evidence Confidence: High
55
Architecture
85
Maintainability
87
Content
68
Community
91
Spec Compliance

What You Can Build

Standardize product galleries

Apply one background and framing treatment across multiple product images while preserving each product.

Create campaign variants

Generate controlled background, clothing, or label variations for visual review and testing.

Automate image revisions

Run repeatable image edits with fixed dimensions, formats, seeds, and output locations.

Try These Prompts

Replace a background
Edit {image_url}. Keep the subject, pose, and clothing unchanged. Replace only the background with {background_description}. Save the result to {output_directory}.
Change one object
Edit {image_url}. Preserve {protected_details}. Change only {target_region} to {requested_change}. Keep all other pixels as consistent as possible.
Process a consistent batch
Edit all images from {image_urls}. Preserve {protected_features}. Apply {change} consistently. Lock the aspect ratio to {aspect_ratio} and resolution to {resolution}.
Generate controlled variants
Edit {image_urls} with {change}. Preserve {protected_features}. Use seed {seed}, {aspect_ratio}, {resolution}, and {format}. Produce {count} variants with web search {web_search_setting}.

Best Practices

  • State preservation requirements before describing the requested change.
  • Use precise spatial terms and split complex edits into separate passes.
  • Lock aspect ratio, resolution, prompt structure, and seed when comparing batch variants.

Avoid

  • Do not combine many unrelated changes in one instruction.
  • Do not omit the features that must remain unchanged.
  • Do not send confidential images or URLs without reviewing RunComfy data handling terms.

Frequently Asked Questions

Does this skill edit local files directly?
No. Inputs must use publicly fetchable HTTPS URLs, and the CLI downloads generated outputs to the selected directory.
How many images can one request process?
One request accepts one to twenty input images and can produce one to four output images.
Which output formats are supported?
The documented endpoint supports PNG, JPEG, and WebP output.
Can it preserve a person's identity?
It is designed for identity preservation, but results can drift. State every protected feature before the requested change.
Where are prompts and images processed?
RunComfy receives the prompt, and its model server fetches the supplied image URLs for processing.
Is a RunComfy account required?
Yes. Interactive use requires RunComfy login, while automated environments can provide a RunComfy token.

Developer Details

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

181fdefcafd96b041926e61c4b2e306ca7e7820e

Maintenance freshness

7/24/2026

Usage

3 downloads ยท 76 views

File structure

๐Ÿ“„ SKILL.md