Fal.ai API
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's requirements, instructions, and included code are consistent with a fal.ai media-generation client and only request the single API key they need.
This skill appears to be a straightforward client for fal.ai and is coherent with its description, but before installing: 1) Verify you trust the skill source — the package has no homepage and the registry owner is an ID only; 2) Confirm the network endpoints (https://queue.fal.run) are legitimate for fal.ai in your environment; 3) Because it will call out to the network and requires your FAL_KEY, prefer an API key with limited scope/ephemeral creds if the service supports them; 4) Note the script may invoke the local 'clawdbot' command to read saved config if FAL_KEY is not set — if you have clawdbot installed, inspect its config and consider running the script in an isolated environment; 5) If you need higher assurance, review the bundled fal_api.py source (it’s included) or run it in a sandbox before giving production credentials.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
