fal-text-to-image
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided prompts and images, which represents a theoretical surface for instructions embedded in external data.
- Ingestion points: The
PROMPTargument andINPUT_IMAGEpath/URL processed by thefal-text-to-image,fal-image-remix, andfal-image-editscripts. - Capability inventory: The scripts perform network requests to the fal.ai API and write generated image files to a local
outputs/directory. - Boundary markers: The skill does not implement specific delimiters or instructions to ignore commands that might be embedded in user-supplied strings or image metadata.
- Sanitization: Prompt strings are passed directly to the remote API without escaping or validation.
- [DATA_EXFILTRATION]: The skill communicates with external servers to upload image data and download generation results.
- Evidence: The scripts use the
fal-clientlibrary to upload local files and therequestslibrary to fetch generated images from*.fal.aistorage domains. - Note: These network operations are the intended primary purpose of the skill and target a well-known AI service.
- [COMMAND_EXECUTION]: The skill includes executable Python scripts intended to be run by the agent.
- Evidence: The
README.mdandSKILL.mdfiles provide instructions for executing the provided scripts usinguv run python.
Audit Metadata