r2-upload
Upload files to Cloudflare R2, AWS S3, or any S3-compatible storage (like MinIO) and generate secure, time-limited presigned download links with con…
它会碰到什么
扫了多少11 个文本文件,113 KB
它会碰到什么执行命令读凭据读文件写文件联网
命中总数21 处
命中统计严重 1 · 高 5 · 中 7 · 低 8
逐条看命中(6 条严重或高危)
- 严重
src/index.ts:46yaml-unsafereturn yaml.load(configContent) as Config;
- 高
src/index.ts:39cred-envreadconst configPath = process.env.R2_UPLOAD_CONFIG || join(homedir(), '.r2-upload.yml');
- 高
src/index.ts:237cred-envreadconst bucketName = bucket || process.env.R2_DEFAULT_BUCKET || config.default;
- 高
src/index.ts:293cred-envreadconst bucketName = bucket || process.env.R2_DEFAULT_BUCKET || config.default;
- 高
src/index.ts:338cred-envreadconst bucketName = bucket || process.env.R2_DEFAULT_BUCKET || config.default;
- 高
src/index.ts:364cred-envreadconst bucketName = bucket || process.env.R2_DEFAULT_BUCKET || config.default;
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Send Me My Files - R2 Upload with Short Lived Signed URLs
Upload files to Cloudflare R2 or any S3-compatible storage and generate presigned download links.
Features
- Upload files to R2/S3 buckets
- Generate presigned download URLs (configurable expiration)
- Support for any S3-compatible storage (R2, AWS S3, MinIO, etc.)
- Multiple bucket configurations
- Automatic content-type detection
Configuration
Create ~/.r2-upload.yml (or set R2_UPLOAD_CONFIG env var):
# Default bucket (used when no bucket specified)
default: my-bucket
# Bucket configurations
buckets:
my-bucket:
endpoint: https://abc123.r2.cloudflarestorage.com
access_key_id: your_access_key
secret_access_key: your_secret_key
bucket_name: my-bucket
public_url: https://files.example.com # Optional: custom domain
region: auto # For R2, use "auto"
# Additional buckets
personal:
endpoint: https://xyz789.r2.cloudflarestorage.com
access_key_id: ...
secret_access_key: ...
bucket_name: personal-files
region: auto
Cloudflare R2 Setup
- Go to Cloudflare Dashboard → R2
- Create a bucket
- Go to R2 API Tokens:
https://dash.cloudflare.com/<ACCOUNT_ID>/r2/api-tokens - Create a new API token
- Important: Apply to specific bucket (select your bucket)
- Permissions: Object Read & Write
- Copy the Access Key ID and Secret Access Key
- Use endpoint format:
https://<account_id>.r2.cloudflarestorage.com - Set
region: auto
AWS S3 Setup
aws-bucket:
endpoint: https://s3.us-east-1.amazonaws.com
access_key_id: ...
secret_access_key: ...
bucket_name: my-aws-bucket
region: us-east-1
Usage
Upload a file
r2-upload /path/to/file.pdf
# Returns: https://files.example.com/abc123/file.pdf?signature=...
Upload with custom path
r2-upload /path/to/file.pdf --key uploads/2026/file.pdf
Upload to specific bucket
r2-upload /path/to/file.pdf --bucket personal
Custom expiration (default: 5 minutes)
r2-upload /path/to/file.pdf --expires 24h
r2-upload /path/to/file.pdf --expires 1d
r2-upload /path/to/file.pdf --expires 300 # seconds
Public URL (no signature)
r2-upload /path/to/file.pdf --public
Tools
r2_upload- Upload file and get presigned URLr2_list- List recent uploadsr2_delete- Delete a file
Environment Variables
R2_UPLOAD_CONFIG- Path to config file (default:~/.r2-upload.yml)R2_DEFAULT_BUCKET- Override default bucketR2_DEFAULT_EXPIRES- Default expiration in seconds (default: 300 = 5 minutes)
Notes
- Uploaded files are stored with their original filename unless
--keyis specified - Automatic UUID prefix added to prevent collisions (e.g.,
abc123/file.pdf) - Content-Type automatically detected from file extension
- Presigned URLs expire after the configured duration
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。