Fal.ai API

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's requirements, instructions, and included code are consistent with a fal.ai media-generation client and only request the single API key they need.

This skill appears to be a straightforward client for fal.ai and is coherent with its description, but before installing: 1) Verify you trust the skill source — the package has no homepage and the registry owner is an ID only; 2) Confirm the network endpoints (https://queue.fal.run) are legitimate for fal.ai in your environment; 3) Because it will call out to the network and requires your FAL_KEY, prefer an API key with limited scope/ephemeral creds if the service supports them; 4) Note the script may invoke the local 'clawdbot' command to read saved config if FAL_KEY is not set — if you have clawdbot installed, inspect its config and consider running the script in an isolated environment; 5) If you need higher assurance, review the bundled fal_api.py source (it’s included) or run it in a sandbox before giving production credentials.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.