Back to skill

Security audit

fal

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward fal.ai integration, but users should know that prompts and selected files are sent to fal.ai and generated outputs are saved locally.

Install only if you are comfortable sending prompts, parameters, and any uploaded media files to fal.ai. Do not upload confidential files or sensitive personal media unless that use is approved, and periodically clean ~/.fal/sessions/${CLAUDE_SESSION_ID}/ if generated outputs should not remain on disk.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The upload command posts a user-supplied local file to a remote fal CDN without any embedded user-facing warning or confirmation requirement. Because local files may contain sensitive or proprietary data, silent upload behavior materially increases the risk of unintended exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README includes very broad natural-language examples such as 'Generate an image of a sunset over mountains' and 'Turn this photo into a video,' which can encourage automatic invocation of the skill without the user explicitly choosing the external fal.ai service. In a skill that sends prompts and potentially files to a third-party API and downloads outputs locally, overly generic activation examples increase the chance of unintended external data transfer and side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README describes uploading files, submitting jobs, and polling fal.ai, but it does not clearly warn that prompts, media, and uploaded files may be transmitted to external fal.ai services. In this context, omission of a third-party data-transfer warning is dangerous because users may provide sensitive images, audio, or text without realizing that the content leaves the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README describes uploading files, submitting jobs, and polling fal.ai, but it does not clearly warn that prompts, media, and uploaded files may be transmitted to external fal.ai services. In this context, omission of a third-party data-transfer warning is dangerous because users may provide sensitive images, audio, or text without realizing that the content leaves the local environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The skill persists generated media to a session-scoped directory under the user's home folder, which can retain potentially sensitive images or videos beyond the immediate interaction. Without retention guidance, permission controls, or cleanup behavior, this increases exposure to local data leakage or unintended reuse.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

Save generated files to session folder:

bash
mkdir -p ~/.fal/sessions/${CLAUDE_SESSION_ID}

Downloaded images/videos go to: ~/.fal/sessions/${CLAUDE_SESSION_ID}/

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill sends user prompts, model inputs, and likely generated outputs to fal.ai APIs, but the description does not clearly warn users that their data leaves the local environment and is processed by a third party. This creates a privacy and consent risk, especially if users provide sensitive text, images, audio, or other files under the assumption the operation is local.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

Search for models matching $1:

bash
curl -s "https://api.fal.ai/v1/models?q=$1&limit=15" \
  -H "Authorization: Key $FAL_KEY" | jq -r '.models[] | "• \(.endpoint_id) — \(.metadata.display_name) [\(.metadata.category)]"'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

Search for models matching $1:

bash
curl -s "https://api.fal.ai/v1/models?q=$1&limit=15" \
  -H "Authorization: Key $FAL_KEY" | jq -r '.models[] | "• \(.endpoint_id) — \(.metadata.display_name) [\(.metadata.category)]"'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Search for models matching $1:

bash
curl -s "https://api.fal.ai/v1/models?q=$1&limit=15" \
  -H "Authorization: Key $FAL_KEY" | jq -r '.models[] | "• \(.endpoint_id) — \(.metadata.display_name) [\(.metadata.category)]"'

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This command sends a JSON payload to fal.ai's remote queue endpoint, which is expected functionality for a hosted AI service but still constitutes external data transmission. In this skill context, prompts and other parameters may contain sensitive information, so the lack of explicit guardrails and disclosure makes the transmission security-relevant.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

Step 2: Submit to queue

bash
curl -s -X POST "https://queue.fal.run/$1" \
  -H "Authorization: Key $FAL_KEY" \
  -H "Content-Type: application/json" \
  -d '<JSON_PAYLOAD>'

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The result-handling flow explicitly instructs saving downloaded images or videos to persistent session storage, but does not mention retention, cleanup, or sensitivity of stored outputs. Since generated media can contain private user content or proprietary prompts rendered into assets, disk persistence is a meaningful confidentiality risk.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
RESULT=$(curl -s "https://queue.fal.run/$1/requests/$REQUEST_ID" \
  -H "Authorization: Key $FAL_KEY")

# Create session output folder
mkdir -p ~/.fal/sessions/${CLAUDE_SESSION_ID}

# Download images/videos

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file includes a natural-language/config example that sets "language": "en" for Whisper input. Because the document does not explain that language should be selected based on user preference or locale, it can encourage a fixed-language behavior that conflicts with language/locale choice expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.