uploading-files — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited uploading-files (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Claude Code on the Web has no file-upload widget and no shared mount. Whenever the user needs to get a file (image, PDF, CSV, doc, archive, anything) into the session, route them through a temporary GitHub branch on the working repo's origin remote.
Trigger this skill when:
Don't trigger when the file is already in the repo, on a public URL you can fetch, or short enough to paste inline.
The script lives at /mnt/skills/user/uploading-files/scripts/upload.py once installed. It must be run from inside the working git repo (it uses origin and cwd).
python3 /mnt/skills/user/uploading-files/scripts/upload.py initThis creates upload-<short-session-id> on origin (from the default branch) and prints a GitHub upload URL. Show that URL to the user on its own line, with no surrounding markdown — no **bold**, no [link](...), no backticks. Some chat renderers concatenate trailing punctuation/markup onto the URL when the user clicks it, breaking the branch name. Bare URL only. Then tell them:
Open that link, drag the file(s) into the page, scroll to the bottom and click Commit changes (the default options are fine). Reply here when done.
Then stop and wait for the user. Do not pretend they've uploaded.
After the user confirms the upload:
python3 /mnt/skills/user/uploading-files/scripts/upload.py fetchThis downloads everything on the branch (vs default) into ./.uploads/ (filenames are flattened to basenames) and ensures .uploads/ is in .gitignore. Treat the files in .uploads/ like any other local input.
If the script reports "No files on branch yet", the user probably forgot to click commit. Ask them to refresh the upload page and verify they committed, then re-run fetch.
When the uploaded files are no longer needed — typically after the work is done and anything worth keeping has been moved into the repo proper, and before opening a PR — delete the remote branch:
python3 /mnt/skills/user/uploading-files/scripts/upload.py cleanupLocal files in ./.uploads/ are kept (they're gitignored). If the user might want them again, leave them; otherwise rm -rf .uploads after cleanup.
python3 /mnt/skills/user/uploading-files/scripts/upload.py statusPrints the repo, branch name, whether the branch exists on origin, and the upload URL. Useful when you've context-switched and want to recover the URL without recreating the branch.
upload-<short> where <short> is the first hyphen-segment of $CLAUDE_SESSION_ID, or of the most recent transcript filename under ~/.claude/projects/<encoded-cwd>/, or a UTC timestamp tsYYYYMMDD-HHMMSS as fallback. The same session always resolves to the same branch, so re-running init is idempotent.git remote get-url origin. Must be a github.com remote.$GH_TOKEN (then $GITHUB_TOKEN, $GITHUB_PAT, $GH_PAT). Token needs Contents: write on the working repo.api.github.com and raw.githubusercontent.com..uploads/. If the user uploads two files with the same name in different subdirs, the second overwrites the first. Tell them to rename first if it matters..uploads/ to the working repo. If a file should be persisted, copy it to a proper location first (and git add from there).~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.