Skills nano-banana-blockrun
๐Ÿ“ฆ

nano-banana-blockrun

Content revision r2 High Risk ๐ŸŒ Network access๐Ÿ“ Filesystem accessโš™๏ธ External commands

Generate Images with Nano Banana and USDC

Image generation often requires separate API subscriptions and keys. This skill uses BlockRun to request supported models and pay per image with USDC on Base.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "nano-banana-blockrun" from https://skillstore.io/skills/blockrunai-nano-banana-blockrun.md and its manifest at https://skillstore.io/api/skills/blockrunai-nano-banana-blockrun/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "nano-banana-blockrun". Generate one image of a glass greenhouse at sunrise using Nano Banana.

Expected outcome:

Selected Nano Banana at 1024x1024. Estimated charge is approximately $0.05 USDC. The paid request is awaiting approval.

Using "nano-banana-blockrun". Create a detailed city poster and compare the standard and Pro models first.

Expected outcome:

  • Nano Banana: approximately $0.05 for 1024x1024 output.
  • Nano Banana Pro: approximately $0.10 for output up to 4K.
  • No request was sent. Select one option to approve its estimated charge.

Using "nano-banana-blockrun". Generate an approved Nano Banana image of a red bicycle beside a lake.

Expected outcome:

The image request completed. The SDK returned a hosted image URL for the generated result.

Security Audit

High Risk
v9 โ€ข 7/23/2026 Open versioned report

Most URL, hidden-directory, Git ignore, and Markdown fence detections are benign documentation. Confirmed risks involve plaintext wallet-key handling and transmitting prompts and payment signatures to BlockRun. Additional risks include an unpinned executable dependency with key access and paid requests without approval or spending limits.

5
Files scanned
421
Lines analyzed
1
Review items
0
False positives ignored

Confirmed security concerns (9)

High
Crypto seed/private key mention
# Your EVM wallet private key (with 0x prefix)
The template directs users to provide a raw EVM private key for a wallet holding USDC. Compromise of that plaintext credential can cause financial loss.
High
Environment file access
cp .env.example .env
The setup creates a plaintext .env file that the next instruction populates with a wallet private key. Local exposure of that file can compromise funds.
High
Environment file access
# Edit .env and add your private key
The instruction explicitly tells users to store a wallet private key in .env. This creates a high-impact local secret requiring strong protection.
High
Crypto seed/private key mention
# Edit .env and add your private key
The documented setup requires a raw wallet private key. Theft of this credential permits unauthorized signing and potential loss of wallet funds.
High
Environment file access
# Copy .env.example to .env and add your key
The comment directs users to add a wallet private key to a plaintext .env file. That credential can authorize payments if exposed.
High
Environment file access
cp .env.example .env
The command creates the .env file used for the wallet key. Although legitimate setup, it establishes sensitive plaintext storage.
High
Crypto seed/private key mention
3. Set your wallet private key:
The skill requires users to supply a raw wallet private key to enable paid requests. Credential compromise can lead to unauthorized transactions.
High
Unpinned Dependency Handles Wallet Credentials
The skill installs the latest blockrun-llm package, then runs it while a wallet private key is available. The audited files cannot verify the package's local-signing assurance.
The package command has no version constraint, and the documented client runs with the configured wallet key. No package implementation is present in the audited files.
Show all 9 confirmed findings
High
Paid Requests Lack Approval and Spending Limits
The generation flow signs a USDC payment for each request, but the skill requires no per-request approval, request limit, or maximum charge.
The skill documents prices and automatic payment signing, while no approval or spending-control step appears in the workflow.
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Hardcoded URL
1. Your request goes to BlockRun API (https://blockrun.ai)
The documented workflow sends user prompts to the BlockRun API and later sends a payment signature. This is expected but real external data transmission.
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/blockrunai-nano-banana-blockrun/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/blockrunai-nano-banana-blockrun/security.svg)](https://skillstore.io/skills/blockrunai-nano-banana-blockrun?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/blockrunai-nano-banana-blockrun?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/blockrunai-nano-banana-blockrun/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/blockrunai-nano-banana-blockrun.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

BlockRunAI. (2026). nano-banana-blockrun security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/blockrunai-nano-banana-blockrun/audits/9

BibTeX citation

@techreport{blockrunai-blockrunai-nano-banana-blockrun-2026, author = {BlockRunAI}, title = {nano-banana-blockrun security audit report (audit version 9)}, institution = {Skillstore}, year = {2026}, number = {9}, url = {https://skillstore.io/skills/blockrunai-nano-banana-blockrun/audits/9}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "nano-banana-blockrun security audit report (audit version 9)" version: "unspecified" type: report authors: - name: "BlockRunAI" date-released: "2026-07-23" url: "https://skillstore.io/skills/blockrunai-nano-banana-blockrun/audits/9" identifiers: - type: other value: "skillstore:blockrunai-nano-banana-blockrun:audit:9" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
71
Community
91
Spec Compliance

What You Can Build

Create Design Concepts

Generate a single concept image after reviewing the selected model and estimated charge.

Prototype Visual Assets

Request temporary artwork for an application prototype without configuring a conventional image API key.

Prepare Campaign Drafts

Develop approved image prompts and generate a controlled set of campaign drafts within a defined budget.

Try These Prompts

Generate One Image
Generate one 1024x1024 image of [subject] in [style]. Before execution, state the selected model and estimated USDC charge.
Create a Product Concept
Create a product concept image for [product] with [background], [lighting], and [brand colors]. Use Nano Banana and request approval before payment.
Compare Model Options
Compare Nano Banana and Nano Banana Pro for [scene]. Explain price and resolution differences, then generate only the approved option.
Plan a Budgeted Image Set
Plan three campaign images with a total budget of [amount] USDC. Present prompts, model choices, and costs before making any paid requests.

Best Practices

  • Use a dedicated low-balance wallet and never expose a primary wallet key.
  • Confirm the model, estimated charge, and request count before each generation.
  • Pin and review the blockrun-llm package version before installing it.

Avoid

  • Do not store a funded primary wallet key in a project environment file.
  • Do not allow retries or batch generation without a strict spending limit.
  • Do not assume the referenced generation script exists in this package.

Frequently Asked Questions

Which models are documented?
The skill lists Nano Banana, Nano Banana Pro, and DALL-E 3.
What payment method is required?
Requests use USDC on the Base network through the x402 payment flow.
Does this skill require an API key?
No conventional service API key is documented. The SDK requires access to a wallet private key for payment signing.
How much does an image cost?
Documented prices range from about $0.04 to $0.12 per image. Actual charges can change.
Does the private key leave the machine?
The documentation claims local signing, but the audited package does not include the SDK implementation needed to verify that claim.
Can I use the documented generation script?
No scripts/generate.py file appears in the audited package. Use the documented SDK only after reviewing and pinning its dependency.

Developer Details

Author

BlockRunAI

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

a39a91716eadede5f4cdefd78178fed4e837a128

Maintenance freshness

7/24/2026

Usage

6 downloads ยท 287 views

File structure

๐Ÿ“„ .env.example

๐Ÿ“„ .gitignore

๐Ÿ“„ example_image.png

๐Ÿ“„ LICENSE

๐Ÿ“„ README.md

๐Ÿ“„ SKILL.md

View all