skills/affaan-m/ecc/fal-ai-media/Gen Agent Trust Hub

fal-ai-media

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill integrates the fal-ai-mcp-server package via npx to enable media generation capabilities. This is a standard installation method for the service.\n- [DATA_EXFILTRATION]: The skill includes a Python example that interacts with the ElevenLabs API (api.elevenlabs.io) for text-to-speech generation. It correctly advises using environment variables (ELEVENLABS_API_KEY) for authentication rather than hardcoding secrets.\n- [INDIRECT_PROMPT_INJECTION]: The skill takes user-provided prompts and text as input for media generation tools.\n
  • Ingestion points: User prompts in generate tool calls and text input for speech synthesis.\n
  • Boundary markers: None explicitly defined in the skill instructions.\n
  • Capability inventory: Performs network requests to external APIs and writes generated media files to the local disk.\n
  • Sanitization: The skill relies on the safety filters and moderation systems of the integrated AI providers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 08:43 PM
Security Audit — agent-trust-hub — fal-ai-media