Model or dataset
AgriciDaniel/banana-claude avatar
AgriciDaniel/banana-claude

One approval, one attempt, and a changed plan needs a new one

AI image generation skill for Claude Code - Creative Director powered by Gemini

1,067 stars241 forksPythonMIT

At a glance

What is it?
Banana Claude is a Claude Code plugin that turns a plain-language request into a Gemini image workflow, and its distinguishing feature is not image quality but cost control: the plugin installs disabled because generation is a paid service, every paid tool shows a plan with a nominal estimate before anything is sent, one short-lived approval authorises exactly one provider attempt, and a changed plan needs a new approval. The upgrade path from the previous version is a security exercise rather than a copy operation.
Who is it for?
Adopt banana-claude if you generate images as part of a review process rather than one at a time, because the plan gate, the estimate, the one-approval-one-attempt rule and the three-prompt portfolio comparison are the parts you would otherwise build.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 5 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

It plans offline and shows the bill before spending

The opening paragraph is the pitch and it is a strange pitch for an image tool, because it describes paperwork. Banana Claude turns a plain-language creative request into a planned and reviewable Gemini image workflow, and before any paid request it shows the prompt, the model, the data settings, the output destination, and a nominal estimate. None of those five things is the image. All five of them are the difference between a tool you trust with a credit card and one you try once. The framing continues into the workflow description, where the plan is built offline first, you review the exact plan, and only then do you approve the paid request when it matches your intent. Nothing about that is unusual as a principle. What is unusual is finding it in an image generation plugin at all, in a field where the normal experience is a text box, a generate button, and a surprise on the invoice. Installation is four commands in the agent itself, after you have Claude Code 2.1.199 or newer, Python 3.11 or newer with python3 on PATH, and a Gemini API key for a billing-enabled project:

bash
/plugin marketplace add AgriciDaniel/banana-claude
/plugin install banana-claude@banana-claude-marketplace
/plugin enable banana-claude@banana-claude-marketplace
/reload-plugins

Then you ask for the image in a sentence, for example an urban 16:9 GitHub hero with clean left-side copy space.

One approval buys one attempt, and a changed plan buys none

The workflow has six named steps and the fourth is the load-bearing one. You ask for an outcome in normal language. The tool builds a visual brief and chooses a route. You inspect the prompt, references, privacy settings and estimate. One short-lived approval authorises one provider attempt. The image and a privacy-conscious metadata sidecar are saved. Then you review the actual pixels and fix, regenerate or ship. The approval rule is stated twice, in slightly different words, and the second statement is the one that matters: a changed plan needs a new approval. That closes the obvious loophole, where an agent adjusts your prompt after you approved it and spends money on something you never saw. It also means the approval is worthless as a budget, since every regeneration is another approval, which is a deliberate trade between spend control and convenience. Most tools in this space give you one of those two things. This one is explicit that it is choosing the first.

Install disabled, and four places a key must not appear

The control section lists six properties, and two of them are about installation and secrets. The plugin installs disabled, because image generation is a paid service, which means a fresh install cannot spend your money until you deliberately turn it on. API keys stay out of commands, request URLs, metadata and public continuous integration, which is a specific and testable list rather than a general promise, and it is the kind of list worth checking against your own logs, because a key in a command line ends up in shell history. Cost records stay private and omit raw prompts by default, which is a privacy choice with a real cost, since a cost record with no prompt is harder to audit against what you asked for. And generated output is never treated as automatically correct or production ready, which the README backs with an explicit list of things it cannot guarantee: consistency, spelling, geometry, policy acceptance, rights clearance, and a final invoice. That last one is unusual honesty, since a tool that bills you should be the last to promise the bill.

Six verbs and three model routes, over a dated reference file

The capability list is organised as verbs rather than features, which is the right shape for a tool that routes to different models depending on what you asked for. Generate covers campaign visuals, covers, product scenes, diagrams, concepts and social assets. Edit makes one clear change while protecting identity, geometry and brand details. Continue iterates using stored sessions on either the Flash or Pro tier, or attaches the last result as a fresh reference. Compare tests up to three prompts across three model routes in one bounded portfolio, which is the feature that most directly pays for the plugin's existence, because the question you actually have is which prompt and which model. Review checks copy, crop, composition, consistency, artefacts, rights and provenance. Typeset does something the model cannot. Underneath, the tool routes across Google's current Nano Banana 2 Lite, Nano Banana 2 and Nano Banana Pro models, and the model details live in a reference file inside the skill's references directory rather than in the README.

Typesetting locally is an admission, and a good one

The Typeset entry is the most honest line in the capability list, and it is worth reading twice: it adds approved copy, fonts, logos and trusted raster art locally when exact text matters. That is the tool saying that the image model will not reliably spell your words, and that a marketing image with the wrong letter in it is worse than no image. The fix is the traditional one, composite the type locally where you control the font and the position, and treat the model's contribution as the artwork underneath. The same reasoning shows up in Edit, which is scoped to one clear change while protecting identity, geometry and brand details, which is a constraint on the operation rather than a promise about the result. If you are evaluating this tool, Typeset is the feature that tells you the author has actually shipped images for someone else, because the people who have not are still asking the model to render a logo.

Compare mode is three prompts over three routes, bounded

The Compare feature deserves a closer look because it is where the design decisions become visible. It lets you test up to three prompts across three model routes in one bounded portfolio, and the word bounded is doing real work. There is no unlimited grid, no search over prompt space, no automated scoring of which result is better. There is a fixed small matrix, which means a fixed small bill, which means a comparison you can afford to run on a real project rather than a comparison you theorise about. It also fits the rest of the design, where the tool refuses to pretend it can tell you which image is good, and instead gives you a review checklist covering copy, crop, composition, consistency, artefacts, rights and provenance. The bounded portfolio plus the review step is a coherent pair: generate a small number of candidates cheaply, then apply human judgement to a list of named things. That is a different shape from a product that scores your image for you.

The upgrade from the old version is a security exercise

The upgrade section is the most surprising part of the README, and it is the part to read before installing anything. If you have an older public install, the instruction is explicit: do not simply overwrite it. An older install may have left an unpinned third-party MCP entry behind, or a raw Google key in your Claude settings, or an obsolete skill directory. Version 3 responds with a redacted scan, a review-first cleanup, and explicit state migrations, and the guide is linked for the upgrade path. The instruction to rotate any key that an older setup stored on disk or exposed in shell history is the one to act on, because a key that was in a settings file once should be considered exposed regardless of what the new version does. There is a small version oddity worth noting while you are in there, since the release list shows 1.4.1 and then 3.0.0 while the upgrade guide refers to 2.1.0 installs, so work out which version you actually have before following a guide written for a different one.

A plugin with a typed Python package behind it

The repository is a plugin distribution with a Python project attached, and the configuration says what standards the code is held to. The project targets Python 3.11 with a line length of 88 and a lint selection covering the error, pyflakes and import rules, plus mypy configured in strict mode for the same Python version. The import configuration is the interesting part, because it defines a custom section order with a bootstrap section placed between the standard library and third party, and the comment explains why: a test support module inserts the bundled script directory before the tests import the executable modules by their plugin runtime names. In other words, the tool's executables are imported as modules under the names the plugin runtime gives them, which is why a path has to be established before the import happens, and why the import linter needs a section that exists only for this project. Alongside that sit the plugin manifest, an MCP configuration file, skills, agents, tools, tests, an install script, a security document, a code of conduct and a citation file, which is the shape of a project that expects to be cited.

Editorial conclusion

Adopt banana-claude if you generate images as part of a review process rather than one at a time, because the plan gate, the estimate, the one-approval-one-attempt rule and the three-prompt portfolio comparison are the parts you would otherwise build. Do not adopt it for occasional one-off images, where a direct API call with the official SDK is a shorter path, and do not enable version 3 on top of an older install without reading the upgrade guide, because an older install may have left an unpinned third-party MCP entry or a raw key in your settings file. Verify four things: that you are on Claude Code 2.1.199 or newer with Python 3.11 or newer, that your Google AI project has billing enabled, which the README states as a requirement rather than an optional extra, that the model reference file under the skill's references directory is current for the models you plan to route to, and that you read SECURITY.md before production use, which the README asks for explicitly. The licence is MIT, version 3.0.0 shipped on 2026-08-30, and the last push was 2026-09-18.

Frequently asked questions

What are the requirements for banana-claude?

Claude Code 2.1.199 or newer, Python 3.11 or newer with python3 on PATH, and a Gemini API key for a billing-enabled Google AI project. It is installed as a plugin through a marketplace, and the plugin installs disabled because image generation is a paid service.

How does banana-claude control spending?

Every paid tool shows its plan and requires a decision before execution, one short-lived approval permits one provider attempt, and a changed plan needs a new approval. The plan shown beforehand includes the prompt, model, data settings, output destination and a nominal estimate, and Compare mode is bounded to up to three prompts across three model routes.

Which Gemini models does banana-claude use?

It routes across Google's current Nano Banana 2 Lite, Nano Banana 2 and Nano Banana Pro models. The current capabilities, pricing and a deprecated compatibility route are documented in a dated reference file inside the skill's references directory rather than in the README.

How do I upgrade from an older banana-claude install?

Do not overwrite it. An older install may have left an unpinned third-party MCP entry, a raw Google key in Claude settings, or an obsolete skill directory. Version 3 adds a redacted scan, review-first cleanup and explicit state migrations, and the README asks you to rotate any key an older setup stored on disk or exposed in shell history.

What licence is banana-claude released under?

MIT, with the LICENSE file at the repository root. The most recent release is version 3.0.0 from 2026-08-30, described as the full creative system, and the last push to main was 2026-09-18.

Official sources

  1. AgriciDaniel/banana-claude on GitHub
  2. Issues
  3. License: MIT
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/agricidaniel-banana-claude.svg)](https://hysenlabs.com/projects/agricidaniel-banana-claude)