Skills dropbox-automation
📦

dropbox-automation

Content revision r2 High Risk ⚙️ External commands🌐 Network access

Automate Dropbox File Workflows

Managing Dropbox through changing API schemas can make routine file workflows slow and error-prone. This skill provides structured Rube MCP sequences for searching, transferring, sharing, and organizing Dropbox content.

Supports: Claude Codex Code(CC)
⚠️ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "dropbox-automation" from https://skillstore.io/skills/sickn33-dropbox-automation.md and its manifest at https://skillstore.io/api/skills/sickn33-dropbox-automation/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "dropbox-automation". Find the latest quarterly plan in the Strategy folder.

Expected outcome:

Found Quarterly Plan Q3.docx in Strategy/Planning. The result includes its canonical path and modified date after every search page was checked.

Using "dropbox-automation". Upload logo-final.png to the Client Assets folder without replacing anything.

Expected outcome:

The upload is ready for Client Assets/logo-final.png in add mode. No existing file will be overwritten without confirmation.

Using "dropbox-automation". Share the approved campaign brief with viewer access.

Expected outcome:

An existing viewer link was found and reused. Its audience, expiration, password requirement, and download permission were summarized for review.

Security Audit

High Risk
v5 • 7/23/2026 Open versioned report

Static backtick and reconnaissance alerts are false positives caused by Markdown inline code and Dropbox workflow prose. The Rube endpoint is a real network dependency, with third-party OAuth access and unguarded high-impact Dropbox operations. Publication should require clear consent and confirmation controls for account access, sharing, overwrite, move, and delete actions.

1
Files scanned
239
Lines analyzed
1
Review items
0
False positives ignored

Confirmed security concerns (2)

High
High-Impact Dropbox Actions Lack Confirmation Controls
The skill supports public or editor links, ownership transfer, overwrite, move, and batch deletion without requiring a preview or explicit user confirmation.
The cited workflows expose sharing and destructive controls, while no confirmation step appears in those sequences. This can disclose or alter cloud data after ambiguous requests.
Medium
Third-Party Dropbox OAuth Trust Boundary
Setup routes Dropbox access through Rube MCP and asks users to complete OAuth from a returned link. The external service can mediate sensitive account data and actions.
Lines 21-26 explicitly require the external MCP endpoint and a Dropbox OAuth connection. The trust boundary is direct, although it supports the stated function.
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Hardcoded URL
**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API k
Line 21 instructs users to connect their client to the external Rube MCP endpoint. This intended dependency creates a real network and third-party trust boundary.
Audited by: codex View Audit History →
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/sickn33-dropbox-automation/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/sickn33-dropbox-automation/security.svg)](https://skillstore.io/skills/sickn33-dropbox-automation?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/sickn33-dropbox-automation?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-dropbox-automation/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/sickn33-dropbox-automation.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA · BibTeX · CFF)

APA citation

sickn33. (2026). dropbox-automation security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-dropbox-automation/audits/5

BibTeX citation

@techreport{sickn33-sickn33-dropbox-automation-2026, author = {sickn33}, title = {dropbox-automation security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/sickn33-dropbox-automation/audits/5}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "dropbox-automation security audit report (audit version 5)" version: "unspecified" type: report authors: - name: "sickn33" date-released: "2026-07-23" url: "https://skillstore.io/skills/sickn33-dropbox-automation/audits/5" identifiers: - type: other value: "skillstore:sickn33-dropbox-automation:audit:5" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
69
Community
83
Spec Compliance

What You Can Build

Organize project deliverables

Search, upload, and organize project deliverables while preserving canonical paths and handling naming conflicts.

Prepare client asset delivery

Export Dropbox Paper, package folders, and prepare controlled sharing links for clients or partners.

Maintain shared storage

Inventory shared folders, review metadata, and plan approved batch moves or deletions with status tracking.

Try These Prompts

Find a Dropbox file
Search Dropbox for files named [name] within [folder]. Show each canonical path, file type, and modified date, including all result pages.
Upload with conflict protection
Upload [local file] to [Dropbox path] in add mode. If the name exists, stop and show conflict options before changing anything.
Create a controlled sharing link
Find [Dropbox path] and check for an existing link. Reuse it when suitable; otherwise propose audience, access, expiration, password, and download settings.
Reorganize a folder in batches
Inventory [source folder] recursively and propose moves into [destination structure]. Preview every batch, identify conflicts, request approval, execute approved changes, then poll completion.

Best Practices

  • Retrieve current tool schemas before choosing parameters or executing a Dropbox workflow.
  • Resolve canonical paths and preview affected items before uploads, moves, deletes, or sharing changes.
  • Use restricted audiences, expirations, passwords, and explicit approval for sensitive files and destructive operations.

Avoid

  • Do not assume a remembered tool schema or reuse stale cursors and job identifiers.
  • Do not create duplicate links, overwrite files, or execute batch changes without reviewing existing state.
  • Do not expose confidential content through public or editor links without explicit authorization.

Frequently Asked Questions

Does this skill connect directly to Dropbox?
No. It uses Rube MCP and requires an active Dropbox OAuth connection managed through that service.
Can it search file contents and folders?
Yes. Search can use text, path scope, categories, extensions, and filename-only matching, with pagination for additional results.
Can it upload and download every Dropbox item?
It supports common files, folder archives, shared-link downloads, and Dropbox Paper exports. Dropbox size, type, permission, and entry limits still apply.
Can it create public sharing links?
Yes. Link settings can include public, team, or disabled audiences. Review audience, access, expiration, password, and download permissions before creation.
Will it confirm destructive changes automatically?
No. The source guidance does not enforce confirmation. Require a preview and explicit approval before overwrite, move, ownership transfer, or delete actions.
How does it handle changing tool schemas?
It directs the agent to search Rube MCP for the current Dropbox tool schema before running a workflow.

Developer Details

Author

sickn33

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

88a8e9a07f4c54ab105c1c41b6267c287146b07b

Maintenance freshness

7/26/2026

Usage

9 downloads · 129 views

File structure

📄 SKILL.md

More from sickn33

View all
View all