box-automation — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited box-automation (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Automate Box operations including file upload/download, content search, folder management, collaboration, metadata queries, and sign requests through Composio's Box toolkit.
RUBE_MANAGE_CONNECTIONS with toolkit boxRUBE_SEARCH_TOOLS first to get current tool schemasGet Rube MCP: Add https://rube.app/mcp as an MCP server in your client configuration. No API keys needed — just add the endpoint and it works.
RUBE_SEARCH_TOOLS respondsRUBE_MANAGE_CONNECTIONS with toolkit boxWhen to use: User wants to upload files to Box or download files from it
Tool sequence:
BOX_SEARCH_FOR_CONTENT - Find the target folder if path is unknown [Prerequisite]BOX_GET_FOLDER_INFORMATION - Verify folder exists and get folder_id [Prerequisite]BOX_LIST_ITEMS_IN_FOLDER - Browse folder contents and discover file IDs [Optional]BOX_UPLOAD_FILE - Upload a file to a specific folder [Required for upload]BOX_DOWNLOAD_FILE - Download a file by file_id [Required for download]BOX_CREATE_ZIP_DOWNLOAD - Bundle multiple files/folders into a zip [Optional]Key parameters:
parent_id: Folder ID for upload destination (use "0" for root folder)file: FileUploadable object with s3key, mimetype, and name for uploadsfile_id: Unique file identifier for downloadsversion: Optional file version ID for downloading specific versionsfields: Comma-separated list of attributes to returnPitfalls:
attributes part of upload must come before the file part or you get HTTP 400 with metadata_after_file_contentshttps://*.app.box.com/files/123 gives file_id "123")When to use: User wants to find files, folders, or web links by name, content, or metadata
Tool sequence:
BOX_SEARCH_FOR_CONTENT - Full-text search across files, folders, and web links [Required]BOX_LIST_ITEMS_IN_FOLDER - Browse contents of a specific folder [Optional]BOX_GET_FILE_INFORMATION - Get detailed metadata for a specific file [Optional]BOX_GET_FOLDER_INFORMATION - Get detailed metadata for a specific folder [Optional]BOX_QUERY_FILES_FOLDERS_BY_METADATA - Search by metadata template values [Optional]BOX_LIST_RECENTLY_ACCESSED_ITEMS - List recently accessed items [Optional]Key parameters:
query: Search string supporting operators ("" exact match, AND, OR, NOT - uppercase only)type: Filter by "file", "folder", or "web_link"ancestor_folder_ids: Limit search to specific folders (comma-separated IDs)file_extensions: Filter by file type (comma-separated, no dots)content_types: Search in "name", "description", "file_content", "comments", "tags"created_at_range / updated_at_range: Date filters as comma-separated RFC3339 timestampslimit: Results per page (default 30)offset: Pagination offset (max 10000)folder_id: For LIST_ITEMS_IN_FOLDER (use "0" for root)Pitfalls:
BOX_SEARCH_FOR_CONTENT requires either query or mdfilters parameterAND, OR, NOT) must be uppercaseBOX_LIST_ITEMS_IN_FOLDER requires pagination via marker or offset/usemarker; partial listings are commonWhen to use: User wants to create, update, move, copy, or delete folders
Tool sequence:
BOX_GET_FOLDER_INFORMATION - Verify folder exists and check permissions [Prerequisite]BOX_CREATE_FOLDER - Create a new folder [Required for create]BOX_UPDATE_FOLDER - Rename, move, or update folder settings [Required for update]BOX_COPY_FOLDER - Copy a folder to a new location [Optional]BOX_DELETE_FOLDER - Move folder to trash [Required for delete]BOX_PERMANENTLY_REMOVE_FOLDER - Permanently delete a trashed folder [Optional]Key parameters:
name: Folder name (no /, \, trailing spaces, or ./..)parent__id: Parent folder ID (use "0" for root)folder_id: Target folder ID for operationsparent.id: Destination fold~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.