SKILL.md
Box Automation via Rube MCP
Automate Box operations including file upload/download, content search, folder management, collaboration, metadata queries, and sign requests through Composio's Box toolkit.
Prerequisites
- Rube MCP must be connected (RUBESEARCHTOOLS available)
- Active Box connection via
RUBEMANAGECONNECTIONSwith toolkitbox - Always call
RUBESEARCHTOOLSfirst to get current tool schemas
Setup
Get Rube MCP: Add https://rube.app/mcp as an MCP server in your client configuration. No API keys needed — just add the endpoint and it works.
- Verify Rube MCP is available by confirming
RUBESEARCHTOOLSresponds - Call
RUBEMANAGECONNECTIONSwith toolkitbox - If connection is not ACTIVE, follow the returned auth link to complete Box OAuth
- Confirm connection status shows ACTIVE before running any workflows
Core Workflows
1. Upload and Download Files
When to use: User wants to upload files to Box or download files from it
Tool sequence:
BOXSEARCHFOR_CONTENT- Find the target folder if path is unknown [Prerequisite]BOXGETFOLDERINFORMATION- Verify folder exists and get folderid [Prerequisite]BOXLISTITEMSINFOLDER- Browse folder contents and discover file IDs [Optional]BOXUPLOADFILE- Upload a file to a specific folder [Required for upload]BOXDOWNLOADFILE- Download a file by file_id [Required for download]BOXCREATEZIP_DOWNLOAD- Bundle multiple files/folders into a zip [Optional]
Key parameters:
parent_id: Folder ID for upload destination (use"0"for root folder)file: FileUploadable object withs3key,mimetype, andnamefor uploadsfile_id: Unique file identifier for downloadsversion: Optional file version ID for downloading specific versionsfields: Comma-separated list of attributes to return
Pitfalls:
- Uploading to a folder with existing filenames can trigger conflict behavior; decide overwrite vs rename semantics
- Files over 50MB should use chunk upload APIs (not available via standard tools)
- The
attributespart of upload must come before thefilepart or you get HTTP 400 withmetadataafterfile_contents - File IDs and folder IDs are numeric strings extractable from Box web app URLs (e.g.,
https://*.app.box.com/files/123gives file_id"123")
2. Search and Browse Content
When to use: User wants to find files, folders, or web links by name, content, or metadata
Tool sequence:
BOXSEARCHFOR_CONTENT- Full-text search across files, folders, and web links [Required]BOXLISTITEMSINFOLDER- Browse contents of a specific folder [Optional]BOXGETFILE_INFORMATION- Get detailed metadata for a specific file [Optional]BOXGETFOLDER_INFORMATION- Get detailed metadata for a specific folder [Optional]BOXQUERYFILESFOLDERSBY_METADATA- Search by metadata template values [Optional]BOXLISTRECENTLYACCESSEDITEMS- List recently accessed items [Optional]
Key parameters:
query: Search string supporting operators (""exact match,AND,OR,NOT- uppercase only)type: Filter by"file","folder", or"web_link"ancestorfolderids: Limit search to specific folders (comma-separated IDs)file_extensions: Filter by file type (comma-separated, no dots)contenttypes: Search in"name","description","filecontent","comments","tags"createdatrange/updatedatrange: Date filters as comma-separated RFC3339 timestampslimit: Results per page (default 30)offset: Pagination offset (max 10000)folderid: ForLISTITEMSINFOLDER(use"0"for root)
Pitfalls:
- Queries with offset > 10000 are rejected with HTTP 400
BOXSEARCHFOR_CONTENTrequires eitherqueryormdfiltersparameter- Misconfigured filters can silently omit expected items; validate with small test queries first
- Boolean operators (
AND,OR,NOT) must be uppercase BOXLISTITEMSINFOLDERrequires pagination viamarkeroroffset/usemarker; partial listings are common- Standard folders sort items by type first (folders before files before web links)
3. Manage Folders
When to use: User wants to create, update, move, copy, or delete folders
Tool sequence:
BOXGETFOLDER_INFORMATION- Verify folder exists and check permissions [Prerequisite]BOXCREATEFOLDER- Create a new folder [Required for create]BOXUPDATEFOLDER- Rename, move, or update folder settings [Required for update]BOXCOPYFOLDER- Copy a folder to a new location [Optional]BOXDELETEFOLDER- Move folder to trash [Required for delete]BOXPERMANENTLYREMOVE_FOLDER- Permanently delete a trashed folder [Optional]
Key parameters:
name: Folder name (no/,\, trailing spaces, or./..)parent__id: Parent folder ID (use"0"for root)folder_id: Target folder ID for operationsparent.id: Destination folder ID for moves viaBOXUPDATEFOLDERrecursive: Settrueto delete non-empty foldersshared_link: Object withaccess,password,permissionsfor creating shared links on foldersdescription,tags: Optional metadata fields
Pitfalls:
BOXDELETEFOLDERmoves to trash by default; useBOXPERMANENTLYREMOVE_FOLDERfor permanent deletion- Non-empty folders require
recursive: truefor deletion - Root folder (ID
"0") cannot be copied or deleted - Folder names cannot contain
/,\, non-printable ASCII, or trailing spaces - Moving folders requires setting
parent.idviaBOXUPDATEFOLDER
4. Share Files and Manage Collaborations
When to use: User wants to share files, manage access, or handle collaborations
Tool sequence:
BOXGETFILE_INFORMATION- Get file details and current sharing status [Prerequisite]BOXLISTFILE_COLLABORATIONS- List who has access to a file [Required]BOXUPDATECOLLABORATION- Change access level or accept/reject invitations [Required]BOXGETCOLLABORATION- Get details of a specific collaboration [Optional]BOXUPDATEFILE- Create shared links, lock files, or update permissions [Optional]BOXUPDATEFOLDER- Create shared links on folders [Optional]
Key parameters:
collaboration_id: Unique collaboration identifierrole: Access level ("editor","viewer","co-owner","owner","previewer","uploader","viewer uploader","previewer uploader")status:"accepted","pending", or"rejected"for collaboration invitesfile_id: File to share or managelock__access: Set to"lock"to lock a filepermissionscandownload:"company"or"open"for download permissions
Pitfalls:
- Only certain roles can invite collaborators; insufficient permissions cause authorization errors
canviewpathincreases load time for the invitee's "All Files" page; limit to 1000 per user- Collaboration expiration requires enterprise admin settings to be enabled
- Nested parameter names use double underscores (e.g.,
lockaccess,parentid)
5. Box Sign Requests
When to use: User wants to manage document signature requests
Tool sequence:
BOXLISTBOXSIGNREQUESTS- List all signature requests [Required]BOXGETBOXSIGNREQUESTBYID- Get details of a specific sign request [Optional]BOXCANCELBOXSIGNREQUEST- Cancel a pending sign request [Optional]
Key parameters:
signrequestid: UUID of the sign requestshared_requests: Settrueto include requests where user is a collaborator (not owner)senders: Filter by sender emails (requiresshared_requests: true)limit/marker: Pagination parameters
Pitfalls:
- Requires Box Sign to be enabled for the enterprise account
- Deleted sign files or parent folders cause requests to not appear in listings
- Only the creator can cancel a sign request
- Sign request statuses include:
converting,created,sent,viewed,signed,declined,cancelled,expired,errorconverting,errorsending
Common Patterns
ID Resolution
Box uses numeric string IDs for all entities:
- Root folder: Always ID
"0" - File ID from URL:
https://*.app.box.com/files/123gives file_id"123" - Folder ID from URL:
https://*.app.box.com/folder/123gives folder_id"123" - Search to ID: Use
BOXSEARCHFOR_CONTENTto find items, then extract IDs from results - ETag: Use
if_matchwith file's ETag for safe concurrent delete operations
Pagination
Box supports two pagination methods:
- Offset-based: Use
offset+limit(max offset 10000) - Marker-based: Set
usemarker: trueand followmarkerfrom responses (preferred for large datasets) - Always paginate to completion to avoid partial results
Nested Parameters
Box tools use double underscore notation for nested objects:
parent__idfor parent folder referencelockaccess,lockexpiresat,lockisdownloadpreventedfor file lockspermissionscandownloadfor download permissions
Known Pitfalls
ID Formats
- All IDs are numeric strings (e.g.,
"123456", not integers) - Root folder is always
"0" - File and folder IDs can be extracted from Box web app URLs
Rate Limits
- Box API has per-endpoint rate limits
- Search and list operations should use pagination responsibly
- Bulk operations should include delays between requests
Parameter Quirks
fieldsparameter changes response shape: when specified, only mini representation + requested fields are returned- Search requires either
queryormdfilters; both are optional individually but one must be present BOXUPDATEFILEwithlockset tonullremoves the lock (raw API only)- Metadata query
fromfield format:enterprise{enterpriseid}.templateKeyorglobal.templateKey
Permissions
- Deletions fail without sufficient permissions; always handle error responses
- Collaboration roles determine what operations are allowed
- Enterprise settings may restrict certain sharing options
Quick Reference
| Task | Tool Slug | Key Params |
|---|---|---|
| Search content | BOXSEARCHFOR_CONTENT |
query, type, ancestorfolderids |
| List folder items | BOXLISTITEMSINFOLDER |
folder_id, limit, marker |
| Get file info | BOXGETFILE_INFORMATION |
file_id, fields |
| Get folder info | BOXGETFOLDER_INFORMATION |
folder_id, fields |
| Upload file | BOXUPLOADFILE |
file, parent_id |
| Download file | BOXDOWNLOADFILE |
file_id |
| Create folder | BOXCREATEFOLDER |
name, parent__id |
| Update folder | BOXUPDATEFOLDER |
folder_id, name, parent |
| Copy folder | BOXCOPYFOLDER |
folder_id, parent__id |
| Delete folder | BOXDELETEFOLDER |
folder_id, recursive |
| Permanently delete folder | BOXPERMANENTLYREMOVE_FOLDER |
folder_id |
| Update file | BOXUPDATEFILE |
file_id, name, parent__id |
| Delete file | BOXDELETEFILE |
fileid, ifmatch |
| List collaborations | BOXLISTFILE_COLLABORATIONS |
file_id |
| Update collaboration | BOXUPDATECOLLABORATION |
collaboration_id, role |
| Get collaboration | BOXGETCOLLABORATION |
collaboration_id |
| Query by metadata | BOXQUERYFILESFOLDERSBY_METADATA |
from, ancestorfolderid, query |
| List collections | BOXLISTALL_COLLECTIONS |
(none) |
| List collection items | BOXLISTCOLLECTION_ITEMS |
collection_id |
| List sign requests | BOXLISTBOXSIGNREQUESTS |
limit, marker |
| Get sign request | BOXGETBOXSIGNREQUESTBYID |
signrequestid |
| Cancel sign request | BOXCANCELBOXSIGNREQUEST |
signrequestid |
| Recent items | BOXLISTRECENTLYACCESSEDITEMS |
(none) |
| Create zip download | BOXCREATEZIP_DOWNLOAD |
item IDs |
When to Use
This skill is applicable to execute the workflow or actions described in the overview.
Example
User request:
Automate Box operations including file upload/download, content search, folder management, collaboration, metadata queries, and sign requests through Composio's Box toolkit.
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.