@1892/fal-image
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches generated image data from Fal.ai's content delivery network (CDN). Additionally, the
compose_instagram.pyscript can fetch images from arbitrary URLs provided via the--inputargument. - [COMMAND_EXECUTION]: The skill includes a utility script (
scripts/compose_instagram.py) that performs image composition, text rendering using local fonts, and file system operations to save the final branded images. - [PROMPT_INJECTION]: The skill processes user-supplied text for both image generation prompts and visual overlays (headlines, subtexts). While this represents a surface for indirect prompt injection, the impact is limited to the content of the generated or modified image.
Audit Metadata