Agent skill

Box Automation

by davepoon in davepoon/buildwithclaude

Automate Box cloud storage operations including file upload/download, search, folder management, sharing, collaborations, and metadata queries via Rube MCP (Composio).

MITAuto-check passedProductivity & Automation

Install Box Automation

skills CLI
$ npx skills add davepoon/buildwithclaude --skill box-automation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davepoon/buildwithclaude box-automation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/all-skills/skills/box-automation .claude/skills/box-automation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
box-automation
GitHub stars
3.6k
Used in
7 other repos
Token cost
~3.1k tokens
SKILL.md length
1,373 words
Files
1
Skills in repo
246
Repo updated
First seen
Licence
MIT

At a glance

Automate Box cloud storage operations including file upload/download, search, folder management, sharing, collaborations, and metadata queries via Rube MCP (Composio).

  • Works in 5 steps: Upload and Download Files → Search and Browse Content → Manage Folders → …
  • Tasks that involve App automation through connectors
  • SKILL.md covers Prerequisites, Setup, Core Workflows and Common Patterns, plus 2 more sections
  • Reaches rube.app

What it does

Box Automation is an agent skill from davepoon/buildwithclaude. Automate Box cloud storage operations including file upload/download, search, folder management, sharing, collaborations, and metadata queries via Rube MCP (Composio). Always search tools first for current schemas.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering App automation through connectors and File uploads and storage. It works with Composio. The repository describes itself as: A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw. The licence is MIT.

When your agent uses it

  • Tasks that involve App automation through connectors
  • Tasks that involve File uploads and storage

Example prompts

  • “/box-automation”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Upload and Download Files
  2. Search and Browse Content
  3. Manage Folders
  4. Share Files and Manage Collaborations
  5. Box Sign Requests

What it can do on your machine

Read from SKILL.md and the folder at commit 616deb5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • rube.app

    Also links to:

    • composio.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Box Automation loads about 3.1k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 1,373 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davepoon/buildwithclaude at commit 616deb5, republished under its MIT licence (© davepoon). 1,373 words, ~3,088 tokens.

Download SKILL.mdSave it as .claude/skills/box-automation/SKILL.md (or your agent's skills folder).
name
box-automation
description
Automate Box cloud storage operations including file upload/download, search, folder management, sharing, collaborations, and metadata queries via Rube MCP (Composio). Always search tools first for current schemas.
requires.mcp
rube
category
storage-docs

Box Automation via Rube MCP

Automate Box operations including file upload/download, content search, folder management, collaboration, metadata queries, and sign requests through Composio's Box toolkit.

Toolkit docs: composio.dev/toolkits/box

Prerequisites

  • Rube MCP must be connected (RUBE_SEARCH_TOOLS available)
  • Active Box connection via RUBE_MANAGE_CONNECTIONS with toolkit box
  • Always call RUBE_SEARCH_TOOLS first to get current tool schemas

Setup

Get Rube MCP: Add https://rube.app/mcp as an MCP server in your client configuration. No API keys needed — just add the endpoint and it works.

  1. Verify Rube MCP is available by confirming RUBE_SEARCH_TOOLS responds
  2. Call RUBE_MANAGE_CONNECTIONS with toolkit box
  3. If connection is not ACTIVE, follow the returned auth link to complete Box OAuth
  4. Confirm connection status shows ACTIVE before running any workflows

Core Workflows

1. Upload and Download Files

When to use: User wants to upload files to Box or download files from it

Tool sequence:

  1. BOX_SEARCH_FOR_CONTENT - Find the target folder if path is unknown [Prerequisite]
  2. BOX_GET_FOLDER_INFORMATION - Verify folder exists and get folder_id [Prerequisite]
  3. BOX_LIST_ITEMS_IN_FOLDER - Browse folder contents and discover file IDs [Optional]
  4. BOX_UPLOAD_FILE - Upload a file to a specific folder [Required for upload]
  5. BOX_DOWNLOAD_FILE - Download a file by file_id [Required for download]
  6. BOX_CREATE_ZIP_DOWNLOAD - Bundle multiple files/folders into a zip [Optional]

Key parameters:

  • parent_id: Folder ID for upload destination (use "0" for root folder)
  • file: FileUploadable object with s3key, mimetype, and name for uploads
  • file_id: Unique file identifier for downloads
  • version: Optional file version ID for downloading specific versions
  • fields: Comma-separated list of attributes to return

Pitfalls:

  • Uploading to a folder with existing filenames can trigger conflict behavior; decide overwrite vs rename semantics
  • Files over 50MB should use chunk upload APIs (not available via standard tools)
  • The attributes part of upload must come before the file part or you get HTTP 400 with metadata_after_file_contents
  • File IDs and folder IDs are numeric strings extractable from Box web app URLs (e.g., https://*.app.box.com/files/123 gives file_id "123")
2. Search and Browse Content

When to use: User wants to find files, folders, or web links by name, content, or metadata

Tool sequence:

  1. BOX_SEARCH_FOR_CONTENT - Full-text search across files, folders, and web links [Required]
  2. BOX_LIST_ITEMS_IN_FOLDER - Browse contents of a specific folder [Optional]
  3. BOX_GET_FILE_INFORMATION - Get detailed metadata for a specific file [Optional]
  4. BOX_GET_FOLDER_INFORMATION - Get detailed metadata for a specific folder [Optional]
  5. BOX_QUERY_FILES_FOLDERS_BY_METADATA - Search by metadata template values [Optional]
  6. BOX_LIST_RECENTLY_ACCESSED_ITEMS - List recently accessed items [Optional]

Key parameters:

  • query: Search string supporting operators ("" exact match, AND, OR, NOT - uppercase only)
  • type: Filter by "file", "folder", or "web_link"
  • ancestor_folder_ids: Limit search to specific folders (comma-separated IDs)
  • file_extensions: Filter by file type (comma-separated, no dots)
  • content_types: Search in "name", "description", "file_content", "comments", "tags"
  • created_at_range / updated_at_range: Date filters as comma-separated RFC3339 timestamps
  • limit: Results per page (default 30)
  • offset: Pagination offset (max 10000)
  • folder_id: For LIST_ITEMS_IN_FOLDER (use "0" for root)

Pitfalls:

  • Queries with offset > 10000 are rejected with HTTP 400
  • BOX_SEARCH_FOR_CONTENT requires either query or mdfilters parameter
  • Misconfigured filters can silently omit expected items; validate with small test queries first
  • Boolean operators (AND, OR, NOT) must be uppercase
  • BOX_LIST_ITEMS_IN_FOLDER requires pagination via marker or offset/usemarker; partial listings are common
  • Standard folders sort items by type first (folders before files before web links)
3. Manage Folders

When to use: User wants to create, update, move, copy, or delete folders

Tool sequence:

  1. BOX_GET_FOLDER_INFORMATION - Verify folder exists and check permissions [Prerequisite]
  2. BOX_CREATE_FOLDER - Create a new folder [Required for create]
  3. BOX_UPDATE_FOLDER - Rename, move, or update folder settings [Required for update]
  4. BOX_COPY_FOLDER - Copy a folder to a new location [Optional]
  5. BOX_DELETE_FOLDER - Move folder to trash [Required for delete]
  6. BOX_PERMANENTLY_REMOVE_FOLDER - Permanently delete a trashed folder [Optional]

Key parameters:

  • name: Folder name (no /, \, trailing spaces, or ./..)
  • parent__id: Parent folder ID (use "0" for root)
  • folder_id: Target folder ID for operations
  • parent.id: Destination folder ID for moves via BOX_UPDATE_FOLDER
  • recursive: Set true to delete non-empty folders
  • shared_link: Object with access, password, permissions for creating shared links on folders
  • description, tags: Optional metadata fields

Pitfalls:

  • BOX_DELETE_FOLDER moves to trash by default; use BOX_PERMANENTLY_REMOVE_FOLDER for permanent deletion
  • Non-empty folders require recursive: true for deletion
  • Root folder (ID "0") cannot be copied or deleted
  • Folder names cannot contain /, \, non-printable ASCII, or trailing spaces
  • Moving folders requires setting parent.id via BOX_UPDATE_FOLDER
4. Share Files and Manage Collaborations

When to use: User wants to share files, manage access, or handle collaborations

Tool sequence:

  1. BOX_GET_FILE_INFORMATION - Get file details and current sharing status [Prerequisite]
  2. BOX_LIST_FILE_COLLABORATIONS - List who has access to a file [Required]
  3. BOX_UPDATE_COLLABORATION - Change access level or accept/reject invitations [Required]
  4. BOX_GET_COLLABORATION - Get details of a specific collaboration [Optional]
  5. BOX_UPDATE_FILE - Create shared links, lock files, or update permissions [Optional]
  6. BOX_UPDATE_FOLDER - Create shared links on folders [Optional]

Key parameters:

  • collaboration_id: Unique collaboration identifier
  • role: Access level ("editor", "viewer", "co-owner", "owner", "previewer", "uploader", "viewer uploader", "previewer uploader")
  • status: "accepted", "pending", or "rejected" for collaboration invites
  • file_id: File to share or manage
  • lock__access: Set to "lock" to lock a file
  • permissions__can__download: "company" or "open" for download permissions

Pitfalls:

  • Only certain roles can invite collaborators; insufficient permissions cause authorization errors
  • can_view_path increases load time for the invitee's "All Files" page; limit to 1000 per user
  • Collaboration expiration requires enterprise admin settings to be enabled
  • Nested parameter names use double underscores (e.g., lock__access, parent__id)
Show full SKILL.md (501 more words)Show less
5. Box Sign Requests

When to use: User wants to manage document signature requests

Tool sequence:

  1. BOX_LIST_BOX_SIGN_REQUESTS - List all signature requests [Required]
  2. BOX_GET_BOX_SIGN_REQUEST_BY_ID - Get details of a specific sign request [Optional]
  3. BOX_CANCEL_BOX_SIGN_REQUEST - Cancel a pending sign request [Optional]

Key parameters:

  • sign_request_id: UUID of the sign request
  • shared_requests: Set true to include requests where user is a collaborator (not owner)
  • senders: Filter by sender emails (requires shared_requests: true)
  • limit / marker: Pagination parameters

Pitfalls:

  • Requires Box Sign to be enabled for the enterprise account
  • Deleted sign files or parent folders cause requests to not appear in listings
  • Only the creator can cancel a sign request
  • Sign request statuses include: converting, created, sent, viewed, signed, declined, cancelled, expired, error_converting, error_sending

Common Patterns

ID Resolution

Box uses numeric string IDs for all entities:

  • Root folder: Always ID "0"
  • File ID from URL: https://*.app.box.com/files/123 gives file_id "123"
  • Folder ID from URL: https://*.app.box.com/folder/123 gives folder_id "123"
  • Search to ID: Use BOX_SEARCH_FOR_CONTENT to find items, then extract IDs from results
  • ETag: Use if_match with file's ETag for safe concurrent delete operations
Pagination

Box supports two pagination methods:

  • Offset-based: Use offset + limit (max offset 10000)
  • Marker-based: Set usemarker: true and follow marker from responses (preferred for large datasets)
  • Always paginate to completion to avoid partial results
Nested Parameters

Box tools use double underscore notation for nested objects:

  • parent__id for parent folder reference
  • lock__access, lock__expires__at, lock__is__download__prevented for file locks
  • permissions__can__download for download permissions

Known Pitfalls

ID Formats
  • All IDs are numeric strings (e.g., "123456", not integers)
  • Root folder is always "0"
  • File and folder IDs can be extracted from Box web app URLs
Rate Limits
  • Box API has per-endpoint rate limits
  • Search and list operations should use pagination responsibly
  • Bulk operations should include delays between requests
Parameter Quirks
  • fields parameter changes response shape: when specified, only mini representation + requested fields are returned
  • Search requires either query or mdfilters; both are optional individually but one must be present
  • BOX_UPDATE_FILE with lock set to null removes the lock (raw API only)
  • Metadata query from field format: enterprise_{enterprise_id}.templateKey or global.templateKey
Permissions
  • Deletions fail without sufficient permissions; always handle error responses
  • Collaboration roles determine what operations are allowed
  • Enterprise settings may restrict certain sharing options

Quick Reference

TaskTool SlugKey Params
Search contentBOX_SEARCH_FOR_CONTENTquery, type, ancestor_folder_ids
List folder itemsBOX_LIST_ITEMS_IN_FOLDERfolder_id, limit, marker
Get file infoBOX_GET_FILE_INFORMATIONfile_id, fields
Get folder infoBOX_GET_FOLDER_INFORMATIONfolder_id, fields
Upload fileBOX_UPLOAD_FILEfile, parent_id
Download fileBOX_DOWNLOAD_FILEfile_id
Create folderBOX_CREATE_FOLDERname, parent__id
Update folderBOX_UPDATE_FOLDERfolder_id, name, parent
Copy folderBOX_COPY_FOLDERfolder_id, parent__id
Delete folderBOX_DELETE_FOLDERfolder_id, recursive
Permanently delete folderBOX_PERMANENTLY_REMOVE_FOLDERfolder_id
Update fileBOX_UPDATE_FILEfile_id, name, parent__id
Delete fileBOX_DELETE_FILEfile_id, if_match
List collaborationsBOX_LIST_FILE_COLLABORATIONSfile_id
Update collaborationBOX_UPDATE_COLLABORATIONcollaboration_id, role
Get collaborationBOX_GET_COLLABORATIONcollaboration_id
Query by metadataBOX_QUERY_FILES_FOLDERS_BY_METADATAfrom, ancestor_folder_id, query
List collectionsBOX_LIST_ALL_COLLECTIONS(none)
List collection itemsBOX_LIST_COLLECTION_ITEMScollection_id
List sign requestsBOX_LIST_BOX_SIGN_REQUESTSlimit, marker
Get sign requestBOX_GET_BOX_SIGN_REQUEST_BY_IDsign_request_id
Cancel sign requestBOX_CANCEL_BOX_SIGN_REQUESTsign_request_id
Recent itemsBOX_LIST_RECENTLY_ACCESSED_ITEMS(none)
Create zip downloadBOX_CREATE_ZIP_DOWNLOADitem IDs

Powered by Composio

© davepoon, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/all-skills/skills/box-automation of davepoon/buildwithclaude.

Open the folder on GitHubat commit 616deb5

Used in 7 other repositories

We found 17 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in davepoon/buildwithclaude, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Box Automation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Box Automation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Box Automation this skilldavepoon/buildwithclaude3.6k7 repos~3.1kAutomated safety check: PassMIT
Composioyc-software/qm15k—~1.6kAutomated safety check: PassMIT
Connect Apps with ComposioComposioHQ/awesome-claude-skills77k3 repos~557Automated safety check: PassNone
Abuselpdb AutomationComposioHQ/awesome-claude-skills77k3 repos~738Automated safety check: PassNone
Accredible Certificates AutomationComposioHQ/awesome-claude-skills77k3 repos~790Automated safety check: PassNone
Composio Cloud Toolsquarqlabs/argus279—~543Automated safety check: PassApache-2.0

Similar skills

  • Composio

    yc-software/qm

    Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet.

    15k GitHub stars~1.6k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Connect Apps with Composio

    ComposioHQ/awesome-claude-skills

    Connects an agent to 1000+ external apps through the Composio Tool Router plugin, so it can actually send emails, create issues and post messages instead of only drafting them.

    77k GitHub starsUsed in 3 repos~557 tokens
    Productivity & AutomationAuto-check passed
  • Abuselpdb Automation

    ComposioHQ/awesome-claude-skills

    Automate Abuselpdb tasks via Rube MCP (Composio). An agent skill from ComposioHQ/awesome-claude-skills.

    77k GitHub starsUsed in 3 repos~738 tokens
    Productivity & AutomationAuto-check passed
  • Accredible Certificates Automation

    ComposioHQ/awesome-claude-skills

    Automate Accredible Certificates tasks via Rube MCP (Composio).

    77k GitHub starsUsed in 3 repos~790 tokens
    Productivity & AutomationAuto-check passed
  • Composio Cloud Tools

    quarqlabs/argus

    Routes requests to external SaaS apps such as GitHub, Gmail, Google Calendar, Slack, Notion and Linear through cloud tools, with safeguards on irreversible actions.

    279 GitHub stars~543 tokensUpdated 4 mo ago
    Productivity & AutomationAuto-check passed
  • Active Campaign Automation

    ComposioHQ/awesome-claude-skills

    Automate ActiveCampaign tasks via Rube MCP (Composio). An agent skill from ComposioHQ/awesome-claude-skills.

    77k GitHub starsUsed in 3 repos~758 tokens
    Productivity & AutomationAuto-check passed

More from davepoon/buildwithclaude

All 246 skills in this repo
  • iOS Hig Design Guide

    davepoon/buildwithclaude

    Build, update, and apply iOS design specifications using Apple Human Interface Guidelines (HIG) source data.

    3.6k GitHub stars~735 tokensUpdated today
    Auto-check passed
  • Video Downloader

    davepoon/buildwithclaude

    Download YouTube videos with customizable quality and format options.

    3.6k GitHub starsUsed in 1 repo~871 tokens
    Auto-check passed
  • Qwen Vision

    davepoon/buildwithclaude

    A skill your agent uses when the user asks to "analyze video", "watch this video", "what happens in this video", "describe this clip", "review this footage", "classify these videos", "compare…

    3.6k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Atlas Cloud Media

    davepoon/buildwithclaude

    Discover Atlas Cloud image and video models, inspect their live schemas, and submit one confirmed media generation request with bounded GET polling.

    3.6k GitHub stars~852 tokensUpdated today
    Auto-check passed
  • Browser Extension Launch

    davepoon/buildwithclaude

    面向没有编程经验的用户,把想法做成可试用的浏览器插件,并完成检查、商店材料、审核提交和上线验证;也用于继续已有插件、排错和发布新版。用户说“帮我做个插件”“把插件上架”“继续我的插件”时使用。普通网站开发、仅查询插件知识不触发。

    3.6k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Slack Gif Creator

    davepoon/buildwithclaude

    Toolkit for creating animated GIFs optimized for Slack, with validators for size constraints and composable animation primitives.

    3.6k GitHub starsUsed in 12 repos~4.3k tokens
    Auto-check passed

Works with

Questions about Box Automation

What does Box Automation do?

Automate Box cloud storage operations including file upload/download, search, folder management, sharing, collaborations, and metadata queries via Rube MCP (Composio). Box Automation is an agent skill from davepoon/buildwithclaude. Automate Box cloud storage operations including file upload/download, search, folder management, sharing, collaborations, and metadata queries via Rube MCP (Composio).

When should I use Box Automation?

Box Automation fits situations like: tasks that involve App automation through connectors; tasks that involve File uploads and storage.

How do I install Box Automation in Claude Code?

Run `npx skills add davepoon/buildwithclaude --skill box-automation -a claude-code`. Or copy the skill folder (plugins/all-skills/skills/box-automation in davepoon/buildwithclaude) into .claude/skills/box-automation in your project. Claude Code loads it when a task matches its description.

How do I install Box Automation in Codex?

Run `npx skills add davepoon/buildwithclaude --skill box-automation -a codex`. Or copy the skill folder (plugins/all-skills/skills/box-automation in davepoon/buildwithclaude) into .agents/skills/box-automation in your project. Codex loads it when a task matches its description.

Can I use Box Automation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davepoon/buildwithclaude --skill box-automation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/box-automation, .gemini/skills/box-automation, .github/skills/box-automation and .opencode/skills/box-automation in your project.

What does Box Automation need to run?

SKILL.md names no scripts, command-line tools or credentials: Box Automation is instructions for the agent only.

Does Box Automation access the network?

SKILL.md names 2 domains. In commands or code: rube.app; the agent is likely to contact it when it follows the instructions. As links in the text: composio.dev. This is read from the text; nothing was executed.

Is Box Automation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Box Automation use?

Box Automation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Box Automation use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Box Automation?

Skills that share tags, products or a category with Box Automation: Composio (yc-software/qm, 15k stars), Connect Apps with Composio (ComposioHQ/awesome-claude-skills, 77k stars), Abuselpdb Automation (ComposioHQ/awesome-claude-skills, 77k stars) and Accredible Certificates Automation (ComposioHQ/awesome-claude-skills, 77k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Box Automation?

davepoon (a GitHub user) maintains it in davepoon/buildwithclaude, which has 3,605 GitHub stars. The repository holds 246 skills in this directory. The repository was last updated on October 9, 2026.

Source: davepoon/buildwithclaude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.