Fal Image Gen
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's instructions expect API keys and a generation script that are not declared or included in the package metadata — these mismatches and missing artifacts warrant caution before installing.
Do not install or run this skill without clarifying a few points: (1) The SKILL.md expects two API keys (FAL_API_KEY, BYTEPLUS_API_KEY) and a local script (scripts/generate.py) but the registry shows no env requirements and no code — ask the provider for the actual script source and an explanation for the missing metadata. (2) Verify how API keys are used, stored, and transmitted (are keys sent to third parties or logged?). (3) Confirm what the command `uv run` does in your environment and whether the referenced generate.py will run, fetch external reference URLs, and upload images (the doc says BytePlus URLs expire and are auto-uploaded). (4) If you must proceed, request the generate.py source (or inspect it) before providing API keys, and run it in an isolated environment with restricted network access until you verify behavior. Providing the missing script, a clear manifest of required env vars, and a trustworthy source/homepage would raise confidence; absence of those keeps this skill suspicious.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
Risk analysis
No visible risk-analysis findings were reported for this release.
