AddThisFeature

Upload Malware Scanning

Quarantine uploaded files until they are known safe.

involved Security & Reliability

What it adds

A quarantine lifecycle for uploads: every new file is unreachable until scanned, with defined handling for scanner failures and infected results.

What your agent is told to do

6
  1. 1

    Give every upload an explicit scan state — pending, clean, infected, or error — and default it to pending the moment the bytes land.

  2. 2

    Make pending and infected files unreachable from every access path in the app, including admin views, previews, thumbnails, and any signed URL. A quarantine with one exception is not a quarantine.

  3. 3

    Scan asynchronously and update the state; do not block the upload request on the scanner.

  4. 4

    Decide and document what an infected file does: delete immediately, or retain for a fixed period for investigation. Both are defensible; an undefined policy is not.

  5. 5

    Tell the user their file was rejected in plain language. Do NOT surface the signature name, the scanner's raw output, or any internal file path — that hands an attacker a feedback loop for tuning their payload.

  6. 6

    Signed-URL issuance and download authorization are owned by Secure File Downloads. Extend that feature to consult scan state rather than building a parallel delivery path here.

Edge cases it handles

7
  • A scanner timeout or outage must fail closed — the file stays pending and inaccessible, and the backlog is retried and alerted on.
  • Files larger than the scanner's limit need an explicit decision, not a silent pass.
  • Archives can hide payloads several layers deep, and zip bombs expand catastrophically. Cap recursion depth and expansion ratio.
  • A file already marked clean can become infected as signatures update. Support re-scanning existing storage.
  • False positives need a human review path, or you will permanently delete a customer's legitimate file.
  • A URL signed while a file was clean must stop working the moment it is marked infected.
  • Uploads that never complete scanning must not accumulate as permanent pending clutter — expire them.

Definition of done

8
  • Every uploaded file has a scan state and starts as pending.
  • Pending and infected files return no bytes from any route, signed or otherwise.
  • Scanner outages and timeouts leave files inaccessible rather than passing them through.
  • The infected-file retention or deletion policy is written down and implemented.
  • User-facing rejection messages contain no signature names or internal paths.
  • A previously clean file can be re-scanned and revoked.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.