fal-ai

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and TypeScript examples for the @fal-ai/serverless-client library. This is a standard and legitimate dependency for interacting with the fal.ai platform.
  • [SAFE]: Authentication practices recommended in the documentation follow security standards by using environment variables (process.env.FAL_KEY) for secret management. Placeholder strings like 'your-api-key' are used appropriately in examples.
  • [SAFE]: Network operations described in the skill are restricted to official fal.ai endpoints for media generation tasks, which is the stated purpose of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing user-supplied prompts. However, the documentation includes examples of using built-in safety features, such as enable_safety_checker: true and safety_tolerance, to mitigate potential issues during runtime generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:04 PM
Security Audit — agent-trust-hub — fal-ai