Skip to content

Latest commit

 

History

12 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

CypherScan for Ghost

Protect Ghost uploads before they reach production.

CypherScan securely scans every uploaded file using a presigned upload workflow and can automatically block suspicious or malicious files before they become available inside Ghost CMS.


Features

  • Secure presigned upload workflow
  • Malware detection
  • Secret detection
  • Automatic malicious file blocking
  • Configurable fail-open / fail-closed behavior
  • Local storage compatibility
  • Configurable request timeout
  • Debug logging
  • Lightweight Ghost storage adapter

Requirements

  • Ghost CMS 6.x
  • Node.js 20+
  • CypherScan API key

Installation

Clone or install the storage adapter inside your Ghost installation:

content/adapters/storage/cypherscan

Configure Ghost to use the adapter for images, media and files.

Restart Ghost.


Configuration

Example:

{
  "storage": {
    "active": "cypherscan",

    "images": {
      "adapter": "cypherscan"
    },

    "media": {
      "adapter": "cypherscan"
    },

    "files": {
      "adapter": "cypherscan"
    },

    "cypherscan": {
      "apiKey": "YOUR_API_KEY",
      "apiBaseUrl": "https://cyphernetsecurity.com",
      "timeout": 30000,
      "failOpen": true,
      "debug": false
    }
  }
}

How it works

When a file is uploaded:

  1. The storage adapter requests a presigned upload URL from the CypherScan API.
  2. The file is uploaded securely to temporary object storage.
  3. CypherScan scans the uploaded object.
  4. A scan verdict is returned.
  5. Clean files remain available.
  6. Suspicious or malicious files are automatically blocked.

Architecture

Ghost Upload
      │
      ▼
CypherScan Storage Adapter
      │
      ▼
Request Presigned Upload URL
      │
      ▼
Temporary Secure Upload
      │
      ▼
CypherScan Scan
      │
      ▼
Verdict
      │
      ├── Clean ─────► Upload allowed
      │
      └── Blocked ───► Upload rejected

Example

Upload detected

        │

        ▼

Presigned Upload

        │

        ▼

CypherScan Scan

        │

        ▼

Verdict: Clean

        │

        ▼

File available inside Ghost

Fail Open / Fail Closed

CypherScan supports two operating modes.

Fail Open

Uploads continue if the scanning service is temporarily unavailable.

Recommended for development environments.

Fail Closed

Uploads are rejected when the scan cannot be completed.

Recommended for production environments requiring strict upload enforcement.


Debug logging

When debug is enabled, the adapter logs:

  • File name
  • MIME type
  • File size
  • Scan status
  • Scan verdict
  • Scan ID
  • Upload decision

Tested

Validated with:

  • Clean image uploads
  • Malware detection (EICAR)
  • API unavailable (failOpen=true)
  • API unavailable (failOpen=false)
  • Local storage
  • Ghost CMS 6.x

CypherScan Agent

Ghost adapter scans use the canonical CypherScan API workflow:

  1. POST /api/v1/upload/presign
  2. Upload the file to the returned temporary URL
  3. POST /api/v1/scan with the returned objectKey

The adapter sends a stable client identity to CypherScan:

x-cypherscan-client: ghost-plugin

The presigned storage PUT remains storage-only and does not receive CypherScan authentication or client headers.

With an active CypherScan Agent subscription, successful authenticated scans automatically become API_INTEGRATION Agent observations. No second Agent event call is required.

Agent can then use those observations for meaningful-change detection, bounded verification, Controller attention decisions, alerts, and activity history.


Roadmap

  • Scan history
  • Detailed scan reports
  • Quarantine support
  • Policy-based upload rules

License

MIT License

Copyright (c) 2026 CypherNet Security Inc.

See the LICENSE file for details.


Links

Built by CypherNet Security Inc.

About

Secure Ghost file uploads using CypherScan's presigned upload and malware scanning workflow.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages