fal-ai-media
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides configuration instructions to install and run the
fal-ai-mcp-servervianpx. This utilizes an external package from a well-known media generation service. - [DATA_EXPOSURE_AND_EXFILTRATION]: Included Python code snippets perform network operations by sending data to the ElevenLabs API (
api.elevenlabs.io) for speech synthesis. This represents a standard integration with a well-known third-party service and handles API keys via environment variables as per best practices. - [INDIRECT_PROMPT_INJECTION]: The skill defines a data ingestion surface by accepting user-supplied prompts that are passed directly to AI models for media generation.
- Ingestion points:
promptfields withingenerate()tool calls. - Boundary markers: None specified to delimit user content from instructions.
- Capability inventory: The skill has the ability to upload files and perform network requests to external APIs.
- Sanitization: No explicit validation or escaping of user-provided prompt strings is defined in the instructions.
Audit Metadata