fal-ai-media

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and executes the fal-ai-mcp-server package via npx. This is a standard deployment method for the official fal.ai MCP integration.
  • [COMMAND_EXECUTION]: Configures an MCP server that runs shell commands using npx to facilitate media generation tasks.
  • [DATA_EXFILTRATION]: Provides examples for interacting with the ElevenLabs API using Python's requests library. The implementation uses environment variables (os.environ) for API key storage, adhering to secure development practices.
  • [PROMPT_INJECTION]: The skill ingests untrusted user data for media generation prompts.
  • Ingestion points: Prompts for images, videos, and text-to-speech (SKILL.md)
  • Boundary markers: Absent
  • Capability inventory: MCP generation tools, Python requests (SKILL.md)
  • Sanitization: Absent
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 07:43 AM
Security Audit — agent-trust-hub — fal-ai-media