phoenix-uploads
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive guidelines for implementing file uploads in Phoenix, incorporating security best practices such as server-side validation and non-predictable filename generation.
- [COMMAND_EXECUTION]: The skill uses standard Elixir file system operations (
File.mkdir_p!andFile.cp!) to handle uploaded files within the project's own directory structure (priv/static/uploads). These operations are restricted to the application's local scope and are necessary for the intended functionality. - [INDIRECT_PROMPT_INJECTION]: The skill defines an ingestion surface for user-uploaded files.
- Ingestion points:
allow_uploadandconsume_uploaded_entriesinSKILL.mddefine how external files enter the application context. - Boundary markers: The instructions explicitly mandate server-side validation (
Validate file types server-side) and safe filename generation. - Capability inventory: Local file writing via
File.cp!and directory creation viaFile.mkdir_p!inSKILL.md'shandle_event("save", ...)block. - Sanitization: The code example includes a
safe_filenameprivate function that usesEcto.UUID.generate()to replace original client filenames, effectively preventing directory traversal and file overwrite attacks.
Audit Metadata