Security · inspect by default

/security-uploads

Review file validation, storage, processing, and download access

Use for file receipt, processing and download safety; backend-permissions handles general resource access, and security-fix repairs a confirmed upload flaw.

Make it your own.

In Claude Code, use the slash command and add your context. In Codex, select security-uploads from the just-vibe skill picker, then send the same brief.

Version 0.11.0 also supports /jv security-uploads, /just-vibe security-uploads and /jv:security-uploads in Claude. See shortcut setup and context examples.

Example · inspect
/just-vibe:security-uploads Audit file validation, processing, private storage, and download access.
edge · inspect
/just-vibe:security-uploads Audit private uploads with user filenames and an asynchronous processor.
blocked · inspect
/just-vibe:security-uploads Review upload source without executing hostile files or publishing dangerous test content.

What the agent does

  1. Follow the complete file lifecycle: filename, content and type trust, storage ownership, parser invocation, resource limits and download authorization.
  2. Define safe malicious and invalid-file fixtures covering path, size, type, processing and access.

Inputs

  • upload/download/processing paths, storage policy, file types, and access rules.

Optional context: scope, references, constraints, successCriteria, environment, mode, budget.

Scope

Reads
File validation, size limits, names/paths, processing isolation, storage exposure, and download authorization.
Writes
No source changes in inspect/plan. Save only requested planning artifacts. A separately requested repair uses the relevant implementation workflow.
Mode
Inspect; upload/download/processing paths, storage policy, file types, and access rules.
Prerequisites
Defined application boundary, authorized code/environment, relevant trust/access rules, and evidence sources. Default to defensive inspection; active tests use owned or explicitly authorized isolated targets. Minimize sensitive evidence and never print usable credentials.

Expected output

  • Upload lifecycle/trust map with threat findings, remediation priorities and isolated path, size, type, processing and access test scenarios.

How the work is checked

  • User-supplied filenames cannot escape storage boundaries; private files require authorization at download as well as upload.

When to stop or clarify

  • Do not execute hostile files or upload dangerous content to public services. Missing processor configuration limits assurance.

Handling missing context

Infer
Resolve the requested surface, source/runtime version, reachable callers and actual trust/access boundaries.
Assume
Start with source analysis and bounded owned fixtures; treat scanner output as leads and preserve legitimate controls.
Ask
Ask when target authorization or necessary trust semantics are unresolved before active probing; source inspection need not wait for production access.

Technical guidance

Evidence
Trace receipt, content validation, parser, quarantine, extraction, storage and download authorization.
Method
Apply file and resource limits at each stage, use server-owned names and verify private storage/scan state before processing or serving.
Pitfall
Filename extension and client MIME type do not establish content; archive members and symlinks can escape a checked top-level path.
Check
Use small inert invalid files, bounded archive/path fixtures and a valid upload; verify no pre-scan download or cross-tenant access.

Situational decisions

When scanning occurs asynchronously after upload: Define quarantine/access state so unverified files cannot be consumed through another route.

The coding agent follows this workflow using its available tools. Installation does not grant service access or guarantee an outcome. Read the compatibility notes.

Keep exploring