Back to skill

Security audit

Phy Fal Model Selector

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward fal.ai model-selection guide, with no executable code or hidden system access.

Installers should understand this skill may be invoked for general image or video generation questions, not only explicit fal.ai requests. That is a routing/noise concern rather than a security concern; users who do not want fal.ai recommendations for generic media tasks may prefer a narrower trigger description.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
97% confidence
Finding
The skill advertises broad trigger phrases like "generate video," "edit image," "remove background," and "which model should I use," which are common requests that may appear in many unrelated contexts. This can cause the skill to activate too often, leading to incorrect routing, interference with other skills, or unwanted influence over model/API selection decisions.

Static analysis

No suspicious patterns detected.