fal
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documents secure authentication practices by explicitly warning against embedding
FAL_KEYin browser bundles and recommending server-side proxies. - [SAFE]: The skill provides robust security guidance for webhooks, including full code examples for ED25519 signature verification against the official fal.ai JWKS endpoint (
https://rest.fal.ai/.well-known/jwks.json). - [EXTERNAL_DOWNLOADS]: The skill references official and well-known packages including
@fal-ai/client(NPM) andfal-client(PyPI). These are standard libraries for the service described. - [COMMAND_EXECUTION]: The provided script
scripts/verify.shis a utility for static analysis of the skill's own documentation to ensure compliance with best practices (e.g., checking for deprecated libraries). It does not perform network operations or access sensitive system files. - [CREDENTIALS_UNSAFE]: The skill references
FAL_KEYas an environment variable and uses placeholder patterns likekey_id:key_secretfor documentation. No hardcoded credentials or secrets were found. - [PROMPT_INJECTION]: The skill contains standard instructional content for AI agents. No bypass, override, or system prompt extraction patterns were detected.
Audit Metadata