dropbox-automation

Warn

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the user to configure a remote MCP server endpoint at https://rube.app/mcp. This external service provides the tool definitions and execution logic for the Dropbox automation.
  • [DATA_EXFILTRATION]: Because the skill utilizes an external gateway for all operations, sensitive file metadata and file contents retrieved via tools like DROPBOX_READ_FILE are processed by the rube.app infrastructure. This creates a risk of data exposure to a third party.
  • [PROMPT_INJECTION]: The skill facilitates the ingestion of external data from Dropbox files into the agent's context. This presents an indirect prompt injection surface where adversarial content stored in files could be used to manipulate agent behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 25, 2026, 02:35 PM