Phy Fal Model Selector
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill is mostly a harmless model-selection cheat-sheet and asks for no credentials, but its runtime instructions reference missing local resources (references/) and the package source is unclear, so some parts don't add up.
This skill appears to be a read-only guide for selecting fal.ai models and does not request credentials or install anything, which is good. However: (1) the SKILL.md tells the agent to 'Read references/' for full parameters but no references folder is included — ask the publisher for the missing files or an updated package before trusting automated use; (2) verify model IDs, pricing, and provider labels against fal.ai's official docs (and your billing settings) before using them in production, since inaccuracies could cause unexpected API calls or charges; (3) the source is listed as unknown and homepage is canlah.ai — if provenance matters, confirm the publisher identity or prefer an official/verified skill; (4) because the skill can be invoked autonomously by the agent (platform default), avoid granting any credentials to the agent at the same time and watch the first few runs manually. If the publisher provides the missing references/manifest and provenance, re-run evaluation — that could change this assessment to benign.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
