本文へ移動
cccskills
無料GitHub で公開

dropbox

Browse, search, read, upload, and share the user's Dropbox — including team/shared folders — through per-user OAuth.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md7.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Dropbox

Use this skill when the user asks about their Dropbox files or folders — listing, searching, reading/downloading, uploading, or sharing.

This is an OAuth connector. The resolved user's Dropbox token already lives on your computer as an environment variable, one per Dropbox API host (the way a logged-in CLI's cached credential would):

  • $VAULT_TOKEN_API_DROPBOXAPI_COM — for api.dropboxapi.com (RPC: list, search, share, move, delete)
  • $VAULT_TOKEN_CONTENT_DROPBOXAPI_COM — for content.dropboxapi.com (download, upload)

Both carry the same Dropbox token (one OAuth grant spans every host), so if a host-specific var is empty, $VAULT_TOKEN_API_DROPBOXAPI_COM works as the bearer for any Dropbox host. Pass it as -H "Authorization: Bearer $VAULT_TOKEN_...". Never ask the user for a token, log it, or use another principal's credential or a service fallback.

If $VAULT_TOKEN_API_DROPBOXAPI_COM is empty: per-user connector tokens are injected only in a direct DM with the user (their personal scope) — in a channel or group they're absent by design, even for a fully-connected user. So don't tell a channel user to reconnect; ask them to DM you to run this. Only if it's empty inside a DM does it mean they haven't connected Dropbox — then point them to the Connectors page.

On 401: the token is expired/invalid → have them reconnect — unless the error body's .tag is missing_scope, in which case the app lacks a permission; name the required_scope it returns (the connected app grants account_info.read, files.metadata.read, files.content.read/write, sharing.read/write).

First: pick the right namespace (team vs personal)

This is the step that makes team and shared folders visible. By default the Dropbox API only lists the user's personal (home) namespace — for a Business member that root is often nearly empty. The team folders they see in the Dropbox web UI live in the team namespace, and the API only shows them when you set the Dropbox-API-Path-Root header.

Resolve the account's namespaces once, then reuse the root_namespace_id for the rest of the session — it doesn't change. This endpoint takes no arguments: send no request body and no Content-Type (adding Content-Type: application/json with an empty body returns a 400):

curl -sS -X POST 'https://api.dropboxapi.com/2/users/get_current_account' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM"

Read root_info from the response. If root_info[".tag"] is team, use its root_namespace_id to see everything (team folders + the member's own files); if it is user (individual account), the default root is fine and no header is needed.

When you have a root_namespace_id, add this header to every files/sharing call so your view matches the web UI (substitute the id):

-H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}'

Prefer referencing items by id ("id:...", returned by list/search) over path strings — ids are stable across namespaces and avoid path-escaping issues.

List a folder

path is "" for the root of the active namespace, or a folder path/id:

curl -sS -X POST 'https://api.dropboxapi.com/2/files/list_folder' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Content-Type: application/json' \
  --data '{"path":"","recursive":false}'

For an ls -R-style or find-across-a-tree request, set "recursive":true to stream the whole subtree in one paginated pass instead of walking folder by folder.

If the response has "has_more":true, page with the returned cursor:

curl -sS -X POST 'https://api.dropboxapi.com/2/files/list_folder/continue' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Content-Type: application/json' \
  --data '{"cursor":"CURSOR"}'

Search

curl -sS -X POST 'https://api.dropboxapi.com/2/files/search_v2' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Content-Type: application/json' \
  --data '{"query":"budget","options":{"max_results":100}}'

If the response has "has_more": true, keep fetching with its cursor via files/search/continue_v2 (same shape as list_folder/continue above) before concluding a file doesn't exist.

Read / download a file

Downloads use the content host and carry their argument in the Dropbox-API-Arg header (no JSON body). Reference the file by id or path:

curl -sS -X POST 'https://content.dropboxapi.com/2/files/download' \
  -H "Authorization: Bearer $VAULT_TOKEN_CONTENT_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Dropbox-API-Arg: {"path":"id:FILE_ID"}' \
  -o inbox/dropbox-file.bin

Keep source paths/ids in your answer so claims can be traced.

Writes require approval

Uploading, sharing, moving, and deleting are writes. Prepare the exact change, name the target file/folder (id + path), and get approval before running it.

Upload bytes you produced (content host; the arg is a header, the file is the body):

curl -sS -X POST 'https://content.dropboxapi.com/2/files/upload' \
  -H "Authorization: Bearer $VAULT_TOKEN_CONTENT_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Dropbox-API-Arg: {"path":"/Reports/q3.pdf","mode":"add","autorename":true}' \
  -H 'Content-Type: application/octet-stream' \
  --data-binary @q3.pdf

Create a shared link (returns a url; a 409 shared_link_already_exists carries the existing link in its metadata — reuse it):

curl -sS -X POST 'https://api.dropboxapi.com/2/sharing/create_shared_link_with_settings' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Content-Type: application/json' \
  --data '{"path":"id:FILE_ID"}'

Move/rename or delete (delete_v2 is recoverable — the file goes to the user's deleted files, not a permanent purge):

curl -sS -X POST 'https://api.dropboxapi.com/2/files/move_v2' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Content-Type: application/json' \
  --data '{"from_path":"id:FILE_ID","to_path":"/Archive/q3.pdf"}'

curl -sS -X POST 'https://api.dropboxapi.com/2/files/delete_v2' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Content-Type: application/json' \
  --data '{"path":"id:FILE_ID"}'

Always report the file path/id and what changed, plus any shared link you created.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

admin

無料

Act for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster & external users, audit/errors/metrics/egress) accepts your token when the user you're talking to is an org admin and started this turn themselves. Use when an admin asks you to inspect or change anything org-wide or in another scope, or anyone asks whether they're an admin.

日本語の概要は準備中です。原文の説明を表示しています。

yc-software/qm1.5万2026年10月11日 更新

browse

無料

Drive a real stealth browser from your shell — act on websites (order food, file an expense, pull data behind a login), with per-person persistent sign-ins via the provider's managed auth (Kernel, Anchor, or Browserbase — picked by which API key you have). Use for ACTING on a site; to just read a page, use curl/wget first. Requires managed model access and a keychain grant for the browser provider key; follow the missing-key steps below.

日本語の概要は準備中です。原文の説明を表示しています。

yc-software/qm1.5万2026年10月11日 更新

cloud-cli

無料

Sign a cloud provider's CLI in (AWS, Google Cloud, Azure, or another) with a device-code flow, then run that CLI as the requesting user. Covers checking the CLI is installed, the login that survives the browser round-trip, and the boundaries on cloud writes.

日本語の概要は準備中です。原文の説明を表示しています。

yc-software/qm1.5万2026年10月11日 更新

composio

無料

Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet. Use QM’s authenticated backend for app discovery, consent, and execution without exposing project keys.

日本語の概要は準備中です。原文の説明を表示しています。

yc-software/qm1.5万2026年10月11日 更新

Connect an administrator-enabled SaaS app for a user with a one-time OAuth consent link.

日本語の概要は準備中です。原文の説明を表示しています。

yc-software/qm1.5万2026年10月11日 更新

Define a Loop — a durable scaffold that works a queue of recurring tasks autonomously (Sentry issues, Front tickets, small perf PRs) with its outputs held for human review. Use when someone wants an agent to keep doing a kind of work on a schedule, rather than one-off. Walks the interview, runs one real item live before arming anything, then writes the playbook and creates the loop.

日本語の概要は準備中です。原文の説明を表示しています。

yc-software/qm1.5万2026年10月11日 更新

yc-software のスキルをすべて見る

このスキルの問題を報告する