@1892/fal-image

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches generated image data from Fal.ai's content delivery network (CDN). Additionally, the compose_instagram.py script can fetch images from arbitrary URLs provided via the --input argument.
  • [COMMAND_EXECUTION]: The skill includes a utility script (scripts/compose_instagram.py) that performs image composition, text rendering using local fonts, and file system operations to save the final branded images.
  • [PROMPT_INJECTION]: The skill processes user-supplied text for both image generation prompts and visual overlays (headlines, subtexts). While this represents a surface for indirect prompt injection, the impact is limited to the content of the generated or modified image.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 03:10 AM
Security Audit — agent-trust-hub — @1892/fal-image