Core Speed Art

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed fal.ai media-generation helper with normal privacy and cost considerations, and I found no hidden, destructive, or unrelated behavior.

Install only if you are comfortable giving the skill access to a fal.ai API key, spending fal.ai credits, and sending selected prompts, URLs, images, videos, or audio to fal.ai or its upstream model providers. Use a revocable API key and avoid sensitive or regulated media unless that external processing is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill requires an environment secret (`FAL_KEY`) and performs network-backed model invocations through `fal.ai`, but it does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: an agent may execute a skill with external network access and secret usage that the permission model does not explicitly surface or constrain.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal