Agent skill

Dropbox

by yc-software in yc-software/qm

Browse, search, read, upload, and share the user's Dropbox — including team/shared folders — through per-user OAuth.

MITAuto-check passedBackend & APIs

Install Dropbox

skills CLI
$ npx skills add yc-software/qm --skill dropbox -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yc-software/qm dropbox --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills-seed/dropbox .claude/skills/dropbox && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dropbox
GitHub stars
15k
Token cost
~1.8k tokens
SKILL.md length
621 words
Files
1
Skills in repo
29
Repo updated
First seen
Licence
MIT

At a glance

Browse, search, read, upload, and share the user's Dropbox — including team/shared folders — through per-user OAuth.

  • Tasks that involve OAuth and OpenID Connect
  • SKILL.md covers First: pick the right…, List a folder, Search and Read / download a file, plus 1 more section
  • Calls curl; reaches api.dropboxapi.com and content.dropboxapi.com

What it does

Dropbox is an agent skill from yc-software/qm. Browse, search, read, upload, and share the user's Dropbox — including team/shared folders — through per-user OAuth.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with Dropbox. The repository describes itself as: Multiplayer agent harness for work. The licence is MIT.

When your agent uses it

  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/dropbox”

What it can do on your machine

Read from SKILL.md and the folder at commit 23af31b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.dropboxapi.com
    • content.dropboxapi.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dropbox loads about 1.8k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 621 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yc-software/qm at commit 23af31b, republished under its MIT licence (© yc-software). 621 words, ~1,782 tokens.

Download SKILL.mdSave it as .claude/skills/dropbox/SKILL.md (or your agent's skills folder).
name
dropbox
description
Browse, search, read, upload, and share the user's Dropbox — including team/shared folders — through per-user OAuth.
requiredCapabilities
egress:api.dropboxapi.com, egress:content.dropboxapi.com

Dropbox

Use this skill when the user asks about their Dropbox files or folders — listing, searching, reading/downloading, uploading, or sharing.

This is an OAuth connector. The resolved user's Dropbox token already lives on your computer as an environment variable, one per Dropbox API host (the way a logged-in CLI's cached credential would):

  • $VAULT_TOKEN_API_DROPBOXAPI_COM — for api.dropboxapi.com (RPC: list, search, share, move, delete)
  • $VAULT_TOKEN_CONTENT_DROPBOXAPI_COM — for content.dropboxapi.com (download, upload)

Both carry the same Dropbox token (one OAuth grant spans every host), so if a host-specific var is empty, $VAULT_TOKEN_API_DROPBOXAPI_COM works as the bearer for any Dropbox host. Pass it as -H "Authorization: Bearer $VAULT_TOKEN_...". Never ask the user for a token, log it, or use another principal's credential or a service fallback.

If $VAULT_TOKEN_API_DROPBOXAPI_COM is empty: per-user connector tokens are injected only in a direct DM with the user (their personal scope) — in a channel or group they're absent by design, even for a fully-connected user. So don't tell a channel user to reconnect; ask them to DM you to run this. Only if it's empty inside a DM does it mean they haven't connected Dropbox — then point them to the Connectors page.

On 401: the token is expired/invalid → have them reconnect — unless the error body's .tag is missing_scope, in which case the app lacks a permission; name the required_scope it returns (the connected app grants account_info.read, files.metadata.read, files.content.read/write, sharing.read/write).

First: pick the right namespace (team vs personal)

This is the step that makes team and shared folders visible. By default the Dropbox API only lists the user's personal (home) namespace — for a Business member that root is often nearly empty. The team folders they see in the Dropbox web UI live in the team namespace, and the API only shows them when you set the Dropbox-API-Path-Root header.

Resolve the account's namespaces once, then reuse the root_namespace_id for the rest of the session — it doesn't change. This endpoint takes no arguments: send no request body and no Content-Type (adding Content-Type: application/json with an empty body returns a 400):

bash
curl -sS -X POST 'https://api.dropboxapi.com/2/users/get_current_account' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM"

Read root_info from the response. If root_info[".tag"] is team, use its root_namespace_id to see everything (team folders + the member's own files); if it is user (individual account), the default root is fine and no header is needed.

When you have a root_namespace_id, add this header to every files/sharing call so your view matches the web UI (substitute the id):

-H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}'

Prefer referencing items by id ("id:...", returned by list/search) over path strings — ids are stable across namespaces and avoid path-escaping issues.

Show full SKILL.md (206 more words)Show less

List a folder

path is "" for the root of the active namespace, or a folder path/id:

bash
curl -sS -X POST 'https://api.dropboxapi.com/2/files/list_folder' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Content-Type: application/json' \
  --data '{"path":"","recursive":false}'

For an ls -R-style or find-across-a-tree request, set "recursive":true to stream the whole subtree in one paginated pass instead of walking folder by folder.

If the response has "has_more":true, page with the returned cursor:

bash
curl -sS -X POST 'https://api.dropboxapi.com/2/files/list_folder/continue' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Content-Type: application/json' \
  --data '{"cursor":"CURSOR"}'
bash
curl -sS -X POST 'https://api.dropboxapi.com/2/files/search_v2' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Content-Type: application/json' \
  --data '{"query":"budget","options":{"max_results":100}}'

If the response has "has_more": true, keep fetching with its cursor via files/search/continue_v2 (same shape as list_folder/continue above) before concluding a file doesn't exist.

Read / download a file

Downloads use the content host and carry their argument in the Dropbox-API-Arg header (no JSON body). Reference the file by id or path:

bash
curl -sS -X POST 'https://content.dropboxapi.com/2/files/download' \
  -H "Authorization: Bearer $VAULT_TOKEN_CONTENT_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Dropbox-API-Arg: {"path":"id:FILE_ID"}' \
  -o inbox/dropbox-file.bin

Keep source paths/ids in your answer so claims can be traced.

Writes require approval

Uploading, sharing, moving, and deleting are writes. Prepare the exact change, name the target file/folder (id + path), and get approval before running it.

Upload bytes you produced (content host; the arg is a header, the file is the body):

bash
curl -sS -X POST 'https://content.dropboxapi.com/2/files/upload' \
  -H "Authorization: Bearer $VAULT_TOKEN_CONTENT_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Dropbox-API-Arg: {"path":"/Reports/q3.pdf","mode":"add","autorename":true}' \
  -H 'Content-Type: application/octet-stream' \
  --data-binary @q3.pdf

Create a shared link (returns a url; a 409 shared_link_already_exists carries the existing link in its metadata — reuse it):

bash
curl -sS -X POST 'https://api.dropboxapi.com/2/sharing/create_shared_link_with_settings' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Content-Type: application/json' \
  --data '{"path":"id:FILE_ID"}'

Move/rename or delete (delete_v2 is recoverable — the file goes to the user's deleted files, not a permanent purge):

bash
curl -sS -X POST 'https://api.dropboxapi.com/2/files/move_v2' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Content-Type: application/json' \
  --data '{"from_path":"id:FILE_ID","to_path":"/Archive/q3.pdf"}'

curl -sS -X POST 'https://api.dropboxapi.com/2/files/delete_v2' \
  -H "Authorization: Bearer $VAULT_TOKEN_API_DROPBOXAPI_COM" \
  -H 'Dropbox-API-Path-Root: {".tag":"root","root":"ROOT_NAMESPACE_ID"}' \
  -H 'Content-Type: application/json' \
  --data '{"path":"id:FILE_ID"}'

Always report the file path/id and what changed, plus any shared link you created.

© yc-software, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills-seed/dropbox of yc-software/qm.

Open the folder on GitHubat commit 23af31b

Compare with similar skills

Dropbox next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dropbox compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dropbox this skillyc-software/qm15k—~1.8kAutomated safety check: PassMIT
Configuration Registrationsgreenpau/caddy-security2.3k—~1.6kAutomated safety check: PassApache-2.0
DropboxLeoYeAI/openclaw-master-skills2.2k—~4.3kAutomated safety check: PassMIT
Dropbox BusinessLeoYeAI/openclaw-master-skills2.2k—~6.9kAutomated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT

Similar skills

  • Configuration Registrations

    greenpau/caddy-security

    Configure local user signup, domain/MX rules, terms, confirmation, dropbox storage, and messaging.

    2.3k GitHub stars~1.6k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Dropbox

    LeoYeAI/openclaw-master-skills

    Dropbox API integration with managed OAuth. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.3k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Dropbox Business

    LeoYeAI/openclaw-master-skills

    Dropbox Business API integration with managed OAuth. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~6.9k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Stripe Apps

    fossasia/eventyay

    A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.

    1.7k GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed

More from yc-software/qm

All 29 skills in this repo
  • Admin

    yc-software/qm

    Act for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster & external users, audit/errors/metrics/egress)…

    15k GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Browse

    yc-software/qm

    Drive a real stealth browser from your shell — act on websites (order food, file an expense, pull data behind a login), with per-person persistent sign-ins via the provider's managed auth (Kernel…

    15k GitHub stars~4k tokensUpdated yesterday
    Auto-check passed
  • Composio

    yc-software/qm

    Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet.

    15k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Dev Instance

    yc-software/qm

    Run the current worktree as a production-shaped local dev instance with web, Slack, or both, on a real LLM + Postgres.

    15k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • GitHub GitLab

    yc-software/qm

    Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.

    15k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Google Workspace

    yc-software/qm

    Read and act on the user's Gmail, Google Calendar, and Google Tasks through per-user OAuth.

    15k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Dropbox

What does Dropbox do?

Browse, search, read, upload, and share the user's Dropbox — including team/shared folders — through per-user OAuth. Dropbox is an agent skill from yc-software/qm. Browse, search, read, upload, and share the user's Dropbox — including team/shared folders — through per-user OAuth.

When should I use Dropbox?

Dropbox fits situations like: tasks that involve OAuth and OpenID Connect.

How do I install Dropbox in Claude Code?

Run `npx skills add yc-software/qm --skill dropbox -a claude-code`. Or copy the skill folder (skills-seed/dropbox in yc-software/qm) into .claude/skills/dropbox in your project. Claude Code loads it when a task matches its description.

How do I install Dropbox in Codex?

Run `npx skills add yc-software/qm --skill dropbox -a codex`. Or copy the skill folder (skills-seed/dropbox in yc-software/qm) into .agents/skills/dropbox in your project. Codex loads it when a task matches its description.

Can I use Dropbox in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yc-software/qm --skill dropbox -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dropbox, .gemini/skills/dropbox, .github/skills/dropbox and .opencode/skills/dropbox in your project.

What does Dropbox need to run?

Going by SKILL.md and its folder, Dropbox needs the command-line tools its instructions call (curl).

Does Dropbox access the network?

SKILL.md names 2 domains. In commands or code: api.dropboxapi.com and content.dropboxapi.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Dropbox safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dropbox use?

Dropbox is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dropbox use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dropbox?

Skills that share tags, products or a category with Dropbox: Configuration Registrations (greenpau/caddy-security, 2.3k stars), Dropbox (LeoYeAI/openclaw-master-skills, 2.2k stars), Dropbox Business (LeoYeAI/openclaw-master-skills, 2.2k stars) and Fortify Development (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dropbox?

yc-software (a GitHub organization) maintains it in yc-software/qm, which has 15,357 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 6, 2026.

Source: yc-software/qm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.