# Storage Upload

> Handle file uploads with Supabase Storage in Next.js — buckets, RLS on objects, signed URLs, image handling, and size/type validation. Use when adding avatars, portfolio images, document uploads, or any user file.

- **Type:** Skill
- **Install:** `agentstack add skill-m-binimran-dev-pack-storage-upload`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [m-binimran](https://agentstack.voostack.com/s/m-binimran)
- **Installs:** 0
- **Category:** [Databases](https://agentstack.voostack.com/c/databases)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [m-binimran](https://github.com/m-binimran)
- **Source:** https://github.com/m-binimran/dev-pack/tree/main/skills/storage-upload

## Install

```sh
agentstack add skill-m-binimran-dev-pack-storage-upload
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# storage-upload

User files are untrusted input. Validate, scope access, and never expose a writable public bucket.

## Process
1. **Bucket per purpose, private by default.** Public bucket only for genuinely public assets. Set
   `fileSizeLimit` and `allowedMimeTypes` on the bucket.
2. **RLS on `storage.objects`:** users may only write/read paths they own — e.g. key prefixed with their
   `auth.uid()`. Policies mirror the `rls-policy` skill (using + with check).
3. **Validate before upload:** size and MIME on the client for UX, and again server-side / via bucket limits
   for safety. Reject executables and oversized files.
4. **Serve privately via signed URLs:** `createSignedUrl(path, expiresIn)` with a short TTL. Don't hand out
   permanent public URLs for private content.
5. **Images:** store an original; render through `next/image` (or a transform) — sized to avoid CLS.
   Strip EXIF if privacy matters.

## Output
- Bucket config, the storage RLS policies, the upload handler (with validation), and how files are served
  (signed URL vs public).

## Guardrails
- Never make a user-writable bucket public-read without considering what else lands in it.
- Path scoping by `auth.uid()` is mandatory for private user files.
- Size/type limits enforced server-side (bucket), not just in the UI.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [m-binimran](https://github.com/m-binimran)
- **Source:** [m-binimran/dev-pack](https://github.com/m-binimran/dev-pack)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-m-binimran-dev-pack-storage-upload
- Seller: https://agentstack.voostack.com/s/m-binimran
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
