If the user has an antivirus installed, we could use it to scan received files... This could be done by the ft-handler or by an observer that starts the job when the ft is finished
Doesn't a normal antivirus do it when an inode is modified anyway?
tbh I never installed an antivirus on linux, so I have no idea
If you don't use one you've got no idea if this is a good feature to add or not. We should always fix problems we know exist, rather than trying to make up potential problems on behalf of users and then fixing them.