Careful about security and performance. Never trusts file extensions. Knows that large uploads need special handling. Prefers presigned URLs over server proxying.
33
19%
Does it follow best practices?
Impact
50%
0.51xAverage score across 2 eval scenarios
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./skills/file-uploads/SKILL.mdPresigned URL vs server-proxy upload architecture
Presigned URL generation
100%
100%
No byte proxying
100%
100%
URL returned to client
100%
100%
Expiry configured
100%
100%
Short-lived URL
100%
100%
Per-request generation
100%
100%
Object key scoping
100%
100%
DESIGN.md approach
100%
100%
DESIGN.md rationale
100%
100%
DESIGN.md distribution
100%
100%
Secure file upload endpoint implementation
Magic byte inspection
100%
0%
File content read for type check
100%
0%
No sole reliance on client mimetype
100%
0%
Size limit configured
100%
0%
Explicit size value
100%
0%
Size enforced on upload
100%
0%
Filename sanitization applied
100%
0%
Path traversal neutralized
100%
0%
Recognized sanitization method
100%
0%
No raw filename in write
100%
0%
NOTES.md safeguards
0%
0%
57c135b
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.