file-upload-security

SKILLWorkflowcommunauté
v0.0.0GoldenWing-360MITMis à jour il y a 18 jSource →

Accept user file uploads without introducing remote code execution, stored XSS, or polyglot attacks. Covers magic-byte validation, strict type allowlists, image re-encoding to defang embedded payloads, EXIF stripping, virus scanning, path-safe storage keys, and serving via a separate origin with Con

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
15Étoiles du dépôt
1Clients
1Formats
il y a 18 jDernière mise à jour
Skill
AuteurGoldenWing-360
Version0.0.0
LicenceMIT
CatégorieWorkflow
Formatsskill.md
PromptNon publié
Compatibilité
Claude✓ Pris en charge
Cursor
Copilot
ChatGPT
Gemini
À propos

Accept user file uploads without introducing remote code execution, stored XSS, or polyglot attacks. Covers magic-byte validation, strict type allowlists, image re-encoding to defang embedded payloads, EXIF stripping, virus scanning, path-safe storage keys, and serving via a separate origin with Content-Disposition. Invoke when adding upload to a new endpoint or migrating from local-disk storage t

Mots-clés
skillclaude