fal-ai-media
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill's purpose is coherent, but its actual trust boundary is not. It presents fal.ai media generation while directing users to an unpinned community MCP package that receives the FAL_KEY, instead of fal.ai's documented official MCP endpoint. Data flows are mostly expected for this use case, but install provenance and credential forwarding make the skill medium-high risk rather than benign.
Confidence: 86%Severity: 78%
Audit Metadata