fal-text-to-image

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided prompts and images, which represents a theoretical surface for instructions embedded in external data.
  • Ingestion points: The PROMPT argument and INPUT_IMAGE path/URL processed by the fal-text-to-image, fal-image-remix, and fal-image-edit scripts.
  • Capability inventory: The scripts perform network requests to the fal.ai API and write generated image files to a local outputs/ directory.
  • Boundary markers: The skill does not implement specific delimiters or instructions to ignore commands that might be embedded in user-supplied strings or image metadata.
  • Sanitization: Prompt strings are passed directly to the remote API without escaping or validation.
  • [DATA_EXFILTRATION]: The skill communicates with external servers to upload image data and download generation results.
  • Evidence: The scripts use the fal-client library to upload local files and the requests library to fetch generated images from *.fal.ai storage domains.
  • Note: These network operations are the intended primary purpose of the skill and target a well-known AI service.
  • [COMMAND_EXECUTION]: The skill includes executable Python scripts intended to be run by the agent.
  • Evidence: The README.md and SKILL.md files provide instructions for executing the provided scripts using uv run python.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 09:21 AM
Security Audit — agent-trust-hub — fal-text-to-image