anonymous-file-upload — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited anonymous-file-upload (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Originless is a privacy-first, decentralized file hosting backend using IPFS.
Key Principles:
Endpoints:
If Docker is available, the best setup is running Originless locally:
docker run -d --restart unless-stopped --name originless \
-p 3232:3232 \
-p 4001:4001/tcp \
-p 4001:4001/udp \
-v originlessd:/data \
-e STORAGE_MAX=200GB \
ghcr.io/besoeasy/originlessThat is where http://localhost:3232/upload comes from in the examples below.
Upload a local file to Originless/IPFS.
For .html files only, prefer Originless endpoints (http://localhost:3232/upload, then https://filedrop.besoeasy.com/upload) and do not route HTML uploads to Blossom fallback servers.
Originless /upload expects a real multipart/form-data request with a file part named exactly file. Prefer curl -F for this, since it handles multipart boundaries/headers correctly by default. If another client/runtime is used, it must fully replicate curl -F "file=@..." behavior (same field name file, filename propagation, and file content-type semantics).
Usage:
# HTML upload (Originless only)
curl -X POST -F "file=@/path/to/index.html" http://localhost:3232/upload || \
curl -X POST -F "file=@/path/to/index.html" https://filedrop.besoeasy.com/upload
# Self-hosted
curl -X POST -F "file=@/path/to/file.pdf" http://localhost:3232/upload
# Public gateway
curl -X POST -F "file=@/path/to/file.pdf" https://filedrop.besoeasy.com/upload
# Fallback strategy for non-HTML files (Originless first, then Blossom servers)
SERVERS=(
"http://localhost:3232/upload"
"https://filedrop.besoeasy.com/upload"
"https://blossom.primal.net/upload"
"https://24242.io/upload"
)
MAX_RETRIES=7
for ((i=0; i<MAX_RETRIES; i++)); do
idx=$((i % ${#SERVERS[@]}))
target="${SERVERS[$idx]}"
echo "Trying: $target"
if curl -fsS -X POST -F "file=@/path/to/file.pdf" "$target"; then
echo "Upload succeeded via $target"
break
fi
if [[ $i -eq $((MAX_RETRIES-1)) ]]; then
echo "All upload attempts failed after $MAX_RETRIES retries"
exit 1
fi
doneResponse:
{
"status": "success",
"cid": "QmX5ZTbH9uP3qMq7L8vN2jK3bR9wC4eF6gD7h",
"url": "https://dweb.link/ipfs/QmX5ZTbH9uP3qMq7L8vN2jK3bR9wC4eF6gD7h?filename=file.pdf",
"size": 245678,
"type": "application/pdf",
"filename": "file.pdf"
}When to use:
Blossom compatibility note:
/upload fails, probe server capabilities first (for example /.well-known/nostr/nip96.json) and adapt to server-specific upload endpoints.Mirror remote URL content to IPFS.
Usage:
curl -X POST http://localhost:3232/remoteupload \
-H "Content-Type: application/json" \
-d '{"url":"https://example.com/image.png"}'When to use:
Create client-side encrypted uploads for private sharing.
Workflow:
{cid}#{decryption_key}Example:
const encrypted = await encryptWithPassphrase(content, passphrase);
const response = await fetch('http://localhost:3232/upload', {
method: 'POST',
body: formDataWithEncrypted(encrypted)
});
const shareLink = `${response.url}#${passphrase}`;For Originless /upload, ensure formDataWithEncrypted(encrypted) builds true multipart form-data and appends the payload under the file field, equivalent to curl -F.
When to use:
Pin CIDs for permanent storage (requires Daku authentication).
Generate Daku Credentials:
node -e "const { generateKeyPair } = require('daku'); const keys = generateKeyPair(); console.log('Public:', keys.publicKey); console.log('Private:', keys.privateKey);"Pin a CID:
curl -X POST http://localhost:3232/pin/add \
-H "daku: YOUR_DAKU_TOKEN" \
-H "Content-Type: application/json" \
-d '{"cids": ["QmHash1", "QmHash2"]}'List pins:
curl -H "daku: YOUR_DAKU_TOKEN" http://localhost:3232/pin/listRemove pin:
curl -X POST http://localhost:3232/pin/remove \
-H "daku: YOUR_DAKU_TOKEN" \
-H "Content-Type: application/json" \
-d '{"cid": "QmHash"}'When to use:
User wants to share file?
├─ Must content persist permanently?
│ ├─ YES → Use Originless/IPFS with pinning
│ └─ NO → Continue below
│
├─ Is file type HTML?
│ ├─ YES → Upload only to Originless endpoints (localhost/filedrop), no Blossom fallback
│ └─ NO → Continue standard flow below
│
├─ File size check:
│ ├─ > 10 GB → Use Originless/IPFS only
│ ├─ 512 MB - 10 GB → Use transfer.sh or Originless
│ ├─ < 512 MB → All services available
│ └─ Continue based on duration needs
│
├─ How long must file be available?
│ ├─ Permanent → Originless/IPFS with pinning
│ ├─ Up to 1 year → 0x0.st or Originless
│ ├─ Up to 14 days → transfer.sh
│ └─ Temporary → Any service
│
├─ Is privacy critical?
│ ├─ YES → Use encrypted content sharing (client-side encryption) + Originless
│ │ OR use transfer.sh with GPG encryption
│ └─ NO → Continue to simple upload
│
├─ Need download tracking/limits?
│ ├─ YES → Use transfer.sh
│ └─ NO → Continue to simple upload
│
├─ Quick temporary share?
│ ├─ YES → temp.sh (3 days, up to 4GB) or 0x0.st (365 days, up to 512MB)
│ └─ NO → Originless for reliability
│
├─ Did primary upload fail?
│ ├─ YES → Try fallback: transfer.sh → 0x0.st → temp.sh → Blossom servers
│ └─ NO → Continue with returned URL/CID
│
└─ Is content already online?
├─ YES → Use Originless /remoteupload to mirror it
└─ NO → Direct uploadUpload files to 0x0.st - a simple, no-frills file hosting service.
Features:
Usage:
# Basic upload
curl -F "file=@/path/to/file.pdf" https://0x0.st
# With custom filename
curl -F "file=@/path/to/data.json" https://0x0.st
# Upload with custom expiration (in days, max 365)
curl -F "file=@/path/to/image.png" -F "expires=30" https://0x0.st
# Upload with secret token for deletion
curl -F "file=@/path/to/document.pdf" -F "secret=" https://0x0.stResponse: Returns a direct URL to the uploaded file:
https://0x0.st/XaBc.pdfDelete uploaded file (if secret token was provided):
curl -F "token=YOUR_SECRET_TOKEN" -F "delete=" https://0x0.st/XaBc.pdfWhen to use:
Limitations:
Upload files to temp.sh — a simple, no-auth file sharing service.
Features:
Usage:
# Basic upload
curl -F "file=@/path/to/file.pdf" https://temp.sh/upload
# Any file type
curl -F "[email protected]" https://temp.sh/upload
# Upload from stdin (text)
echo "Hello world" | curl -F "file=@-" https://temp.sh/upload
# Upload directory (tar first)
tar czf - mydir/ | curl -F "file=@-;filename=mydir.tar.gz" https://temp.sh/uploadResponse: Returns a direct download URL:
https://temp.sh/abc123Download:
curl -L https://temp.sh/abc123 -o file.pdfShareX config (Windows):
# Download from https://temp.sh/temp.sh.sxcuWhen to use:
Limitations:
Upload files to transfer.sh - a popular temporary file hosting service.
Features:
Usage:
# Basic upload
curl --upload-file /path/to/file.pdf https://transfer.sh/file.pdf
# Upload with custom expiration (max 14 days)
curl --upload-file /path/to/image.png https://transfer.sh/image.png?expires=7d
# Download count limit
curl --upload-file /path/to/data.zip https://transfer.sh/data.zip?downloads=5
# Upload with encryption (requires gpg)
cat /path/to/secret.txt | gpg -ac -o- | curl -X PUT --upload-file "-" https://transfer.sh/secret.txt.gpg
# Upload from stdin
cat /path/to/file.txt | curl --upload-file "-" https://transfer.sh/file.txt
# Upload directory (tar + gzip)
tar czf - /path/to/directory | curl --upload-file "-" https://transfer.sh/directory.tar.gz
# Multiple files
curl --upload-file /path/to/file1.txt https://transfer.sh/file1.txt && \
curl --upload-file /path/to/file2.txt https://transfer.sh/file2.txtResponse: Returns a direct URL to the uploaded file:
https://transfer.sh/random/file.pdfDownload uploaded file:
curl https://transfer.sh/random/file.pdf -o file.pdf
# Download and decrypt (if encrypted with gpg)
curl https://transfer.sh/random/secret.txt.gpg | gpg -d > secret.txtAdvanced options:
# Get download count
curl -H "X-Transfer-Count: true" https://transfer.sh/random/file.pdf
# Upload with basic auth protection
curl -u username:password --upload-file /path/to/file.pdf https://transfer.sh/file.pdfWhen to use:
Limitations:
Comparison:
| Service | Max Size | Max Duration | Encryption | Persistence | Best For |
|---|---|---|---|---|---|
| temp.sh | 4 GB | 3 days | None | Temporary | Quick shares, medium files |
| Originless/IPFS | ~200GB (configurable) | Permanent (if pinned) | Client-side | Decentralized | Long-term, censorship-resistant |
| transfer.sh | 10 GB | 14 days | GPG optional | Temporary | Large temporary files |
| 0x0.st | 512 MB | 365 days | None | Temporary | Quick sharing, small files |
Originless/IPFS Endpoints:
| Endpoint | Method | Auth | Purpose |
|---|---|---|---|
/upload | POST | No | Upload local file |
/remoteupload | POST | No | Mirror remote URL |
/pin/add | POST | Daku | Pin CID permanently |
/pin/list | GET | Daku | List pinned CIDs |
/pin/remove | POST | Daku | Unpin a CID |
Alternative Services Quick Commands:
| Service | Upload Command | Max Size | Expiration |
|---|---|---|---|
| temp.sh | curl -F "[email protected]" https://temp.sh/upload | 4 GB | 3 days |
| 0x0.st | curl -F "[email protected]" https://0x0.st | 512 MB | 365 days |
| transfer.sh | curl --upload-file file.pdf https://transfer.sh/file.pdf | 10 GB | 14 days |
| Originless | curl -F "[email protected]" http://localhost:3232/upload | ~200GB | Permanent* |
*Permanent if pinned, otherwise subject to garbage collection
Recommended fallback servers:
Gateway URLs:
Docker (Recommended):
docker run -d --restart unless-stopped --name originless \
-p 3232:3232 \
-p 4001:4001/tcp \
-p 4001:4001/udp \
-v originlessd:/data \
-e STORAGE_MAX=200GB \
ghcr.io/besoeasy/originlessAccess:
TRUE PRIVACY:
CLIENT-SIDE ENCRYPTION:
CAVEATS:
Screenshot sharing (permanent):
# Save to IPFS for permanent storage
curl -F "[email protected]" http://localhost:3232/uploadScreenshot sharing (temporary):
# Quick share with 0x0.st
curl -F "[email protected]" https://0x0.st
# Or with transfer.sh for larger files
curl --upload-file screenshot.png https://transfer.sh/screenshot.pngNostr media attachment:
# Upload image and embed IPFS URL in Nostr event
curl -F "[email protected]" https://filedrop.besoeasy.com/upload
# Returns: https://dweb.link/ipfs/QmX...Anonymous paste (14-day expiration):
# Quick text sharing
echo "Secret message" | curl --upload-file "-" https://transfer.sh/message.txtAnonymous paste (permanent):
# Permanent text storage
echo "Important note" > note.txt
curl -F "[email protected]" http://localhost:3232/uploadLarge file transfer:
# For files 1-10 GB, use transfer.sh
curl --upload-file large-video.mp4 https://transfer.sh/video.mp4
# For files > 10 GB, use Originless/IPFS
curl -F "[email protected]" http://localhost:3232/uploadEncrypted temporary sharing:
# Using transfer.sh with GPG
cat sensitive.pdf | gpg -ac -o- | curl -X PUT --upload-file "-" https://transfer.sh/sensitive.pdf.gpg
# Share URL + passphrase separatelyOriginless/IPFS:
Alternative Services:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.