fal-ai-media

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides configuration instructions to install and run the fal-ai-mcp-server via npx. This utilizes an external package from a well-known media generation service.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: Included Python code snippets perform network operations by sending data to the ElevenLabs API (api.elevenlabs.io) for speech synthesis. This represents a standard integration with a well-known third-party service and handles API keys via environment variables as per best practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a data ingestion surface by accepting user-supplied prompts that are passed directly to AI models for media generation.
  • Ingestion points: prompt fields within generate() tool calls.
  • Boundary markers: None specified to delimit user content from instructions.
  • Capability inventory: The skill has the ability to upload files and perform network requests to external APIs.
  • Sanitization: No explicit validation or escaping of user-provided prompt strings is defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — fal-ai-media