fal-ai-skills

Warn

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides explicit instructions for the agent to execute shell commands using npx to install external dependencies and directs the agent to check for the existence of specific files on the local filesystem.
  • [EXTERNAL_DOWNLOADS]: The skill initiates the download and installation of external packages from the fal-ai-community GitHub organization and NPM registry.
  • [PROMPT_INJECTION]: The skill contains a Decision tree section that overrides the agent's default behavior, instructing it to perform automated installation steps and use the '!' command prefix to gain shell execution capabilities in compatible environments like Claude Code.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 25, 2026, 06:33 PM
Security Audit — agent-trust-hub — fal-ai-skills