fal-ai-media

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and executes the fal-ai-mcp-server package using the npx command as part of the MCP server configuration.
  • [COMMAND_EXECUTION]: Provides setup instructions for configuring the fal-ai MCP server within the ~/.claude.json file, involving shell commands.
  • [REMOTE_CODE_EXECUTION]: Includes a Python code example demonstrating how to integrate with the ElevenLabs text-to-speech API using the requests library.
  • [PROMPT_INJECTION]: The skill processes user-supplied text to generate prompts for various AI models; while this creates an indirect prompt injection surface, the risk is inherent to the skill's purpose and its capabilities are limited to generating media outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 04:01 AM
Security Audit — agent-trust-hub — fal-ai-media