genmedia

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core fal.ai functionality is coherent, but the skill centralizes all API use through an external CLI, installs that CLI via official-yet-risky remote execution, forwards the API key into the CLI, and can install additional skills. This looks more like elevated supply-chain and trust-expansion risk than confirmed malicious behavior.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 15, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/fal-ai-community%2Fskills%2Fgenmedia%2F@47de19e96b4722d320400a7adb7cfd9f287d116d