phoenix-uploads

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive guidelines for implementing file uploads in Phoenix, incorporating security best practices such as server-side validation and non-predictable filename generation.
  • [COMMAND_EXECUTION]: The skill uses standard Elixir file system operations (File.mkdir_p! and File.cp!) to handle uploaded files within the project's own directory structure (priv/static/uploads). These operations are restricted to the application's local scope and are necessary for the intended functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an ingestion surface for user-uploaded files.
  • Ingestion points: allow_upload and consume_uploaded_entries in SKILL.md define how external files enter the application context.
  • Boundary markers: The instructions explicitly mandate server-side validation (Validate file types server-side) and safe filename generation.
  • Capability inventory: Local file writing via File.cp! and directory creation via File.mkdir_p! in SKILL.md's handle_event("save", ...) block.
  • Sanitization: The code example includes a safe_filename private function that uses Ecto.UUID.generate() to replace original client filenames, effectively preventing directory traversal and file overwrite attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:25 AM
Security Audit — agent-trust-hub — phoenix-uploads