fal-ai-media
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose is coherent, but its install and trust model are not: it routes a sensitive `FAL_KEY` through an npm-fetched MCP server that the provided evidence does not verify as an official fal.ai package, while fal.ai docs appear to describe a different same-org MCP path. Because an unverifiable executable receives credentials, this warrants high security risk even without proof of malicious intent.
Confidence: 88%Severity: 86%
Audit Metadata