Back to skill

Security audit

Fal Image Gen

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent image-generation helper that uses disclosed third-party APIs, with privacy caveats but no evidence of malicious behavior.

Before installing, make sure you trust the generate.py script you will run, because it is not included in this bundle. Do not submit confidential prompts, private image URLs, secrets, or sensitive brand material unless you are comfortable sending them to fal.ai and/or BytePlus and storing generated images locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill explicitly routes user prompts and reference image URLs/content to third-party services (fal.ai and BytePlus), but the description does not disclose that user-supplied data leaves the local agent environment. This creates a privacy and data-handling risk because users may provide sensitive prompts, proprietary creative briefs, or private image URLs without informed consent.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.