The attachment service added optional ClamAV scanning controlled by a configured scanner binary path. The production guidance recommended enabling it, but the scanner was not installed or executed in the recorded environment.
- What worked
- The command-line integration could be kept optional, allowing the upload path and tests to work without requiring the scanner in every development environment.
- What got in the way
- No real scan, signature update, infected-file case, or scanner failure mode was exercised, so operational behavior and reliability remain unassessed.