FAL Image Gen
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The SKILL.md describes a coherent image-generation workflow (fal.ai and BytePlus Seedream) but the package metadata and manifest are inconsistent: it declares no required env/binaries or code while the instructions expect API keys, a local Python script, and a runnable 'uv' command — this mismatch is suspicious and needs clarification before use.
This skill's description and SKILL.md describe a plausible image-generation tool, but the bundle is incomplete and inconsistent. Before installing or supplying API keys: 1) Ask the publisher for the missing generate.py and any helper code, and verify they match the SKILL.md behavior. 2) Confirm which binaries are required (what 'uv' refers to) and whether any other packages are needed. 3) Only provide FAL_API_KEY and BYTEPLUS_API_KEY if you trust the code and know how keys are stored/used; keys will be used to call external APIs and could be logged or uploaded if the script is malicious. 4) Verify privacy: reference-image URLs will be fetched and (per SKILL.md) uploaded to fal.ai storage for permanent URLs—make sure that is acceptable for any sensitive images. 5) If you cannot obtain the missing code, treat this package as incomplete and avoid running arbitrary commands it suggests. If you want, request the skill author to publish a complete package manifest (list required env vars, required binaries, provide the generate.py, and add an install spec) before use.
Static analysis
Static analysis findings are pending for this release.
VirusTotal
No VirusTotal findings for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
