s3-upload-handler
Add S3 Uploads to Your App
Building file uploads takes UI, client logic, and server routes. This skill guides Claude, Codex, and Claude Code through S3 upload patterns for web apps.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "s3-upload-handler" from https://skillstore.io/skills/aayushbaniya2006-s3-upload-handler.md and its manifest at https://skillstore.io/api/skills/aayushbaniya2006-s3-upload-handler/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "s3-upload-handler". Add a profile image uploader to my account settings page.
Expected outcome:
The assistant recommends the button variant, lists the required route and callback, and notes where to store the returned image URL.
Using "s3-upload-handler". I need a project asset dropzone with five files and image-only uploads.
Expected outcome:
The assistant describes the dropzone configuration, file limits, accepted image types, and expected upload completion behavior.
Using "s3-upload-handler". Review my presigned upload route before production.
Expected outcome:
The assistant reports missing access checks, server-side validation needs, private object storage recommendations, and safer object key handling.
Security Audit
High RiskMost external-command findings are false positives from Markdown inline code and fenced TypeScript examples, with no shell execution. The AWS credential and .env.local guidance is confirmed as sensitive secret handling, and the presigned upload example adds a high-risk concern because it lacks visible access control and uses public-read uploads.
Confirmed security concerns (3)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (17)
🔑 Env variables (6)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/aayushbaniya2006-s3-upload-handler/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/aayushbaniya2006-s3-upload-handler?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/aayushbaniya2006-s3-upload-handler?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/aayushbaniya2006-s3-upload-handler/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/aayushbaniya2006-s3-upload-handler.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
AayushBaniya2006. (2026). s3-upload-handler security audit report (audit version 8) [Author version unspecified]. Skillstore. https://skillstore.io/skills/aayushbaniya2006-s3-upload-handler/audits/8BibTeX citation
@techreport{aayushbaniya2006-aayushbaniya2006-s3-upload-handler-2026,
author = {AayushBaniya2006},
title = {s3-upload-handler security audit report (audit version 8)},
institution = {Skillstore},
year = {2026},
number = {8},
url = {https://skillstore.io/skills/aayushbaniya2006-s3-upload-handler/audits/8},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "s3-upload-handler security audit report (audit version 8)"
version: "unspecified"
type: report
authors:
- name: "AayushBaniya2006"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/aayushbaniya2006-s3-upload-handler/audits/8"
identifiers:
- type: other
value: "skillstore:aayushbaniya2006-s3-upload-handler:audit:8"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Add User Avatar Uploads
Use the button variant to guide a simple single-file upload flow for profile images.
Build Project File Dropzones
Use the dropzone pattern with file count and size limits for multi-file workflows.
Upload Generated Server Files
Use the server utility pattern when API routes or server actions create files before storage.
Try These Prompts
Use this skill to plan a simple S3 upload flow for a Next.js page. Recommend the component, required props, and setup steps.
Use this skill to design a custom S3 upload interface with ClientS3Uploader. Include state handling, progress expectations, and error handling.
Use this skill to outline a server-side S3 upload path for generated files. Include content type, object path, and response handling.
Use this skill to review a presigned S3 upload route. Identify missing authentication, authorization, validation, object ACL, and key naming controls.
Best Practices
- Use least-privilege IAM permissions and deployment platform secrets for AWS access.
- Validate file size, MIME type, extension, ownership, and object key prefix on the server.
- Keep uploaded objects private by default and grant read access through signed URLs or controlled delivery.
Avoid
- Do not expose long-lived AWS credentials in prompts, logs, code, or committed environment files.
- Do not trust client-provided fileName, fileType, or upload path without server validation.
- Do not use public-read uploads unless the product explicitly requires public objects.
Frequently Asked Questions
Does this skill include the S3 uploader source code?
Which upload patterns does it cover?
Can it help with presigned URLs?
Is the example production ready?
What tools can use this skill?
What project style does it assume?
Developer Details
Author
AayushBaniya2006License
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
c1fdca50ff516318f65fed0d7f9e82797c5171dc
Maintenance freshness
7/18/2026
Usage
6 downloads · 246 views
File structure
📄 SKILL.md