genmedia-ref
Warn
Audited by Socket on Apr 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's stated purpose is plausible for fal.ai, but its actual dependency is an unverified `genmedia` CLI that does not match fal.ai's documented official `fal` CLI. Because the skill forwards `FAL_KEY` and file data into this unverifiable tool, it triggers high supply-chain and credential-forwarding risk despite otherwise coherent functionality.
Confidence: 91%Severity: 86%
Audit Metadata