fal-ai-media

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for configuring the fal-ai-mcp-server via npx, which is a standard procedure for installing MCP tools. It also references official documentation and API endpoints from well-known services like fal.ai and ElevenLabs.
  • [CREDENTIALS_UNSAFE]: The skill correctly instructs users to use environment variables (FAL_KEY, ELEVENLABS_API_KEY) for secret management. It uses safe placeholders like YOUR_FAL_KEY_HERE rather than hardcoding actual credentials.
  • [COMMAND_EXECUTION]: The skill includes code snippets for Python (requests) and MCP tool invocations. These are standard implementation examples for the stated purpose of media generation and do not contain malicious commands or unauthorized file access.
  • [DATA_EXFILTRATION]: Network operations described (calling fal.ai and ElevenLabs APIs) are transparent, targeted at the intended service providers, and do not involve sensitive local file access or unauthorized data transmission.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — fal-ai-media