box-automation
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and workflow instructions for interacting with the Box API via a third-party MCP server (Rube). It appropriately describes OAuth authentication requirements and standard file/folder operations.
- [EXTERNAL_DOWNLOADS]: The skill mentions adding an MCP server from
https://rube.app/mcp. This is a well-known service for AI agent tool integration and is documented neutrally as a configuration step. - [COMMAND_EXECUTION]: While the skill describes tools that perform file operations (upload, delete, zip), these are standard cloud storage interactions authorized by the user via OAuth and do not represent arbitrary shell command execution.
Audit Metadata