Agent skill

Storage Uploads

by WrongStack in WrongStack/WrongStack

Implement owned file/object storage and upload/download flows with validated metadata, access and lifecycle.

MITAuto-check passedBackend & APIs

Install Storage Uploads

skills CLI
$ npx skills add WrongStack/WrongStack --skill storage-uploads -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WrongStack/WrongStack storage-uploads --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/storage-uploads .claude/skills/storage-uploads && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
storage-uploads
GitHub stars
371
Token cost
~834 tokens
SKILL.md length
287 words
Files
1
Skills in repo
100
Repo updated
First seen
Licence
MIT

At a glance

Implement owned file/object storage and upload/download flows with validated metadata, access and lifecycle.

  • Works in 6 steps: Define object ownership, allowed… → Validate upload metadata and content at… → Scope signed URLs/temporary credentials… → …
  • Working with S3/R2-compatible storage
  • SKILL.md covers Selection card, Overview, Rules and Workflow, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Storage Uploads is an agent skill from WrongStack/WrongStack. Implement owned file/object storage and upload/download flows with validated metadata, access and lifecycle. Use when working with S3/R2-compatible storage, attachments or multipart uploads; separate transient transfer state from durable application ownership.

Its SKILL.md is about 830 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering File uploads and storage. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.

When your agent uses it

  • Working with S3/R2-compatible storage
  • Multipart uploads
  • Separate transient transfer state from durable application ownership

Example prompts

  • “/storage-uploads”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Define object ownership, allowed content/size, retention and access before choosing bucket/key layout.
  2. Validate upload metadata and content at the appropriate trusted boundary; client MIME/extension alone is insufficient.
  3. Scope signed URLs/temporary credentials by operation, object and expiry; avoid broad public access as a workaround.
  4. Model incomplete/multipart uploads, retries, orphan objects and application database references.
  5. Keep private objects isolated by authorization, not guess-resistant names alone.
  6. Distinguish checksum/integrity, malware/content checks and successful upload; they are different evidence.

What it can do on your machine

Read from SKILL.md and the folder at commit a744bdc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • developers.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Storage Uploads loads about 834 tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 287 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~834

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WrongStack/WrongStack at commit a744bdc, republished under its MIT licence (© WrongStack). 287 words, ~834 tokens.

Download SKILL.mdSave it as .claude/skills/storage-uploads/SKILL.md (or your agent's skills folder).
name
storage-uploads
description
Implement owned file/object storage and upload/download flows with validated metadata, access and lifecycle. Use when working with S3/R2-compatible storage, attachments or multipart uploads; separate transient transfer state from durable application ownership.
trigger
Implement owned file/object storage and upload/download flows with validated metadata, access and lifecycle. Use when working with S3/R2-compatible storage…
version
1.0.1
required-capabilities
filesystem.read
optional-capabilities
filesystem.write, execution.shell, verification.run, web.research
metadata.routing-group
data
metadata.domain
data

Storage Uploads

Selection card

  • Task: Implement owned object storage and upload lifecycle. / TR: Sahipliği tanımlı nesne deposu ve yükleme yaşam döngüsü uygula.
  • Start: Identify the data owner, query/schema, consistency and recovery contract.
  • Finish: apply the acceptance checks below; report observed results and unresolved constraints.

Overview

Implement owned file/object storage and upload/download flows with validated metadata, access and lifecycle.

Checked AWS S3 JavaScript SDK target: 3.1148.0 on 2026-10-09. Verify provider-specific API/binding support; S3-compatible does not mean every operation or signature setting is identical.

Rules

  1. Define object ownership, allowed content/size, retention and access before choosing bucket/key layout.
  2. Validate upload metadata and content at the appropriate trusted boundary; client MIME/extension alone is insufficient.
  3. Scope signed URLs/temporary credentials by operation, object and expiry; avoid broad public access as a workaround.
  4. Model incomplete/multipart uploads, retries, orphan objects and application database references.
  5. Keep private objects isolated by authorization, not guess-resistant names alone.
  6. Distinguish checksum/integrity, malware/content checks and successful upload; they are different evidence.

Workflow

  1. Inspect provider/bucket policies, SDK/bindings and existing file metadata.
  2. Implement bounded upload/download and durable reference transitions.
  3. Test size/type rejection, unauthorized access, retry and incomplete transfer cleanup.
  4. Verify retrieval/expiry/retention in an isolated authorized storage environment.
  5. Record provider-specific constraints and actual object/application consistency.

Before returning

Ownership/access and transfer limits explicit; interrupted/retried operations handled; private objects protected; integrity and live storage proof scoped.

Sources

Versioned facts checked 2026-10-09; refresh authoritative sources before new installs/upgrades. AWS S3 docs, Cloudflare R2.

Skills in scope

  • api-design — api design contracts and verification.
  • data-governance — data governance contracts and verification.
  • database-development — implement database access, models and queries with explicit consistency, transactions and bounded results.
  • backup-recovery — design and verify backups and restoration for owned databases, files and application state.

© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/core/skills/storage-uploads of WrongStack/WrongStack.

Open the folder on GitHubat commit a744bdc

Compare with similar skills

Storage Uploads next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Storage Uploads compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Storage Uploads this skillWrongStack/WrongStack371—~834Automated safety check: PassMIT
Stripe Projectsfossasia/eventyay1.7k5 repos~2kAutomated safety check: NotesApache-2.0
FoundatioFoundatioFx/Foundatio2.1k—~3.9kAutomated safety check: PassApache-2.0
Spatialduckdb/duckdb-skills6031 repos~1kAutomated safety check: NotesMIT
R Oopab604/claude-code-r-skills2072 repos~1.9kAutomated safety check: PassMIT
Edgestore Setupedgestorejs/edgestore454—~1.8kAutomated safety check: PassMIT

Similar skills

  • Stripe Projects

    fossasia/eventyay

    A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.

    1.7k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check: notes
  • Foundatio

    FoundatioFx/Foundatio

    A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.

    2.1k GitHub stars~3.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Spatial

    duckdb/duckdb-skills

    Official

    Answer questions about spatial data using DuckDB. An agent skill from duckdb/duckdb-skills.

    603 GitHub starsUsed in 1 repo~1k tokens
    Backend & APIsAuto-check: notes
  • R Oop

    ab604/claude-code-r-skills

    R object-oriented programming guide for S7, S3, S4, and vctrs.

    207 GitHub starsUsed in 2 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Edgestore Setup

    edgestorejs/edgestore

    A skill your agent uses when adding, extending, or troubleshooting EdgeStore file uploads, upload UI, or bucket access policies in a TypeScript/React application.

    454 GitHub stars~1.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • S3 Explore

    duckdb/duckdb-skills

    Official

    Explore and query data on S3, Cloudflare R2, GCS, MinIO, or any S3-compatible storage.

    603 GitHub starsUsed in 1 repo~848 tokens
    Backend & APIsAuto-check: notes

More from WrongStack/WrongStack

All 100 skills in this repo
  • Tech Stack

    WrongStack/WrongStack

    Validate and upgrade dependencies against live registries and official migration guides in any ecosystem.

    371 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Skill Creator

    WrongStack/WrongStack

    Create, improve and validate WrongStack SKILL.md bundles with precise discovery, progressive resources and current runtime contracts.

    371 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Bug Hunter

    WrongStack/WrongStack

    A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…

    371 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Design Craft

    WrongStack/WrongStack

    Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.

    371 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Design Critique

    WrongStack/WrongStack

    A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…

    371 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Mailbox Bridge

    WrongStack/WrongStack

    A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

    371 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Storage Uploads

What does Storage Uploads do?

Implement owned file/object storage and upload/download flows with validated metadata, access and lifecycle. Storage Uploads is an agent skill from WrongStack/WrongStack. Implement owned file/object storage and upload/download flows with validated metadata, access and lifecycle.

When should I use Storage Uploads?

Storage Uploads fits situations like: working with S3/R2-compatible storage; multipart uploads; separate transient transfer state from durable application ownership.

How do I install Storage Uploads in Claude Code?

Run `npx skills add WrongStack/WrongStack --skill storage-uploads -a claude-code`. Or copy the skill folder (packages/core/skills/storage-uploads in WrongStack/WrongStack) into .claude/skills/storage-uploads in your project. Claude Code loads it when a task matches its description.

How do I install Storage Uploads in Codex?

Run `npx skills add WrongStack/WrongStack --skill storage-uploads -a codex`. Or copy the skill folder (packages/core/skills/storage-uploads in WrongStack/WrongStack) into .agents/skills/storage-uploads in your project. Codex loads it when a task matches its description.

Can I use Storage Uploads in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill storage-uploads -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/storage-uploads, .gemini/skills/storage-uploads, .github/skills/storage-uploads and .opencode/skills/storage-uploads in your project.

What does Storage Uploads need to run?

SKILL.md names no scripts, command-line tools or credentials: Storage Uploads is instructions for the agent only.

Does Storage Uploads access the network?

SKILL.md names 2 domains. As links in the text: docs.aws.amazon.com and developers.cloudflare.com. This is read from the text; nothing was executed.

Is Storage Uploads safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Storage Uploads use?

Storage Uploads is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Storage Uploads use?

About 834 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Storage Uploads?

Skills that share tags, products or a category with Storage Uploads: Stripe Projects (fossasia/eventyay, 1.7k stars), Foundatio (FoundatioFx/Foundatio, 2.1k stars), Spatial (duckdb/duckdb-skills, 603 stars) and R Oop (ab604/claude-code-r-skills, 207 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Storage Uploads?

WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 371 GitHub stars. The repository holds 100 skills in this directory. The repository was last updated on October 10, 2026.

Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.