Skip to content
Back to skills

Image Upload

ASecurity

Debug an image upload pipeline end to end — mime sniffing, EXIF strip, orientation, resize, size limits, storage

  • 3 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 3, 2026
ai-agentsrustgoapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill image-upload --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Image Upload?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Image Upload
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-image-upload/badge)](https://www.skillsdirectory.com/skills/black141312-image-upload)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: image-upload
description: Debug an image upload pipeline end to end — mime sniffing, EXIF strip, orientation, resize, size limits, storage
category: visual-test
---

# Image Upload

Reach for this when uploads fail, get rejected, come out rotated, or land corrupted in storage. Debug the pipeline stage by stage, not all at once.

1. Capture the raw bytes the server actually received (log to a temp file before any processing) — most "corrupt image" bugs are a truncated or wrongly-encoded multipart body.
2. Verify type by content, not extension: sniff the magic bytes (`file`, libmagic) and reject on the sniffed mime; a `.png` that's really a polyglot/SVG is a security bug.
3. Check orientation: read the EXIF `Orientation` tag — if you strip EXIF without baking rotation into pixels first, portrait photos render sideways.
4. Strip metadata after applying orientation: remove EXIF/GPS/ICC (or transcode) so you don't leak location and don't ship surprise color profiles.
5. Enforce limits in order — byte size, then decoded dimensions (the decompression-bomb guard), then re-encode to a safe format at a capped resolution.
6. Confirm the stored object: re-download it, check mime/dimensions/byte size, and render it to verify the round trip, not just the HTTP 200.

## Rules
- Never trust the client filename or `Content-Type`; sniff magic bytes server-side and decide from that.
- Apply EXIF orientation to pixels BEFORE stripping metadata, or rotated images become permanently sideways.
- Guard decoded dimensions, not just file size — a 2KB PNG can decode to gigapixels (decompression bomb / OOM).
- Strip GPS/EXIF for privacy and re-encode through a trusted decoder to neutralize embedded payloads.
- Verify by reading the object back from storage and rendering it; a 200 response doesn't prove the bytes are intact.
- Test the ugly cases: HEIC, CMYK JPEG, animated GIF/WebP, SVG, and zero-byte uploads each break a different stage.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…