Skip to content
Back to skills

Cloud Files

ASecurity

Use when the user or another skill needs to read from or write to the configured LLM root of a remote. Do not use for local files or remote paths outside that LLM root.

  • 4 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 2, 2026
ai-agentsgoapisecurity

Works with

  • cli
  • api
  • mcp

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 20, 2026

npx -y skills add MoeenNehzati/famulus --skill cloud-files --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cloud Files?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cloud Files
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/moeennehzati-cloud-files/badge)](https://www.skillsdirectory.com/skills/moeennehzati-cloud-files)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cloud-files
description: >-
  Use when the user or another skill needs to read from or write to the configured LLM root of a remote. Do not use for local files or remote paths outside that LLM root.
---

<!-- BEGIN BLUEPRINT INTERFACES -->
> Generated from `blueprint.yaml`. Do not edit this block by hand.

### Managed setup

When first exposed to this skill in a session, invoke `famulus_dispatcher.invoke_security_2` once with:

```json
{
  "caller": "cloud-files",
  "interface": "cloud-files.interface.setup",
  "version": 2,
  "arguments": {
    "positionals": [],
    "options": {},
    "stdin": null
  }
}
```

Do not repeat this initial call during the session. Obtain permission before carrying out setup, then follow the returned setup-manager instructions exactly. If the result is busy or failed, stop and report it.

Executable Interfaces:

Send the required `caller` (caller skill), `interface`, `version`, and `arguments`; optional `dry_run` defaults to false. Compact uses ordered `positionals` plus an option mapping; ordered raw argv uses `positionals: []` plus every argv token in list `options`. Never mix forms.
- `cloud-files._rtx.interface.lists-delete` — Delete a file from cloud storage under the lists/ directory.
  - Caller: `cloud-files`
  - Version: 1
  - Security level: 2
  - Alternative: `default`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {}, "positionals": ["lists/<path>"], "stdin": null}
    Required options: []; positional arity: 1..1; stdin: forbidden
- `cloud-files._rtx.interface.lists-read` — Read a file from cloud storage under the lists/ directory.
  - Caller: `cloud-files`
  - Version: 1
  - Security level: 2
  - Alternative: `default`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {}, "positionals": ["lists/<path>"], "stdin": null}
    Required options: []; positional arity: 1..1; stdin: forbidden
- `cloud-files._rtx.interface.lists-write` — Write content (from stdin) to a file in cloud storage under the lists/ directory.
  - Caller: `cloud-files`
  - Version: 1
  - Security level: 2
  - Alternative: `default`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {}, "positionals": ["lists/<path>"], "stdin": null}
    Required options: []; positional arity: 1..1; stdin: permitted
- `cloud-files._rtx.interface.plans-delete` — Delete a file from cloud storage under the plans/ directory.
  - Caller: `cloud-files`
  - Version: 1
  - Security level: 2
  - Alternative: `default`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {}, "positionals": ["plans/<path>"], "stdin": null}
    Required options: []; positional arity: 1..1; stdin: forbidden
- `cloud-files._rtx.interface.plans-read` — Read a file from cloud storage under the plans/ directory.
  - Caller: `cloud-files`
  - Version: 1
  - Security level: 2
  - Alternative: `default`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {}, "positionals": ["plans/<path>"], "stdin": null}
    Required options: []; positional arity: 1..1; stdin: forbidden
- `cloud-files._rtx.interface.plans-write` — Write content (from stdin) to a file in cloud storage under the plans/ directory.
  - Caller: `cloud-files`
  - Version: 1
  - Security level: 2
  - Alternative: `default`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {}, "positionals": ["plans/<path>"], "stdin": null}
    Required options: []; positional arity: 1..1; stdin: permitted
- `cloud-files._rtx.interface.write-config` — Write <CONFIG>/cloud-files/config.json with the given remote LLM root. Owned by cloud-files.
  - Caller: `cloud-files`
  - Version: 1
  - Security level: 2
  - Alternative: `default`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {"--dry-run": true, "--home": "dir", "--remote-llm-root": "path"}, "positionals": [], "stdin": null}
    Required options: ["--home"]; positional arity: 0..0; stdin: forbidden

Instruction Interfaces:

These are LLM-readable instruction surfaces. Read and follow them directly; do not invoke the MCP server for them.
- `connect-google.interface.default@1` — Route Google OAuth-client preparation according to whether a valid Desktop client is already installed.
<!-- END BLUEPRINT INTERFACES -->
When this skill is used, begin with:

Skill: cloud-files

## 0. Boundary

This skill owns Google Drive transport. Other skills should call this skill's
scripts rather than speaking to the Drive API directly.

Install-time config lives at `<CONFIG>/cloud-files/config.json`.
Legacy OAuth credentials live at `<CONFIG>/cloud-files/credentials.json`.

For shared Google setup or Drive reauthorization, first invoke
`connect-google.interface.default`. Its deterministic coordinator creates a
credential file, asks Drive's owner to probe live access, and stores the path
only after verification. Treat only `complete: true` as successful setup; report
an incomplete Drive result and retry through connect-google with the same file.

Existing legacy Drive credentials remain runtime-readable until a verified
credential-file binding replaces them. Do not offer legacy setup as a new route.

## 1. Preapproved LLM-root operations

Use `lists-read`, `lists-write`, `lists-delete` for routine list storage and `plans-read`, `plans-write`, `plans-delete` for plan storage within their respective directories.

Each interface takes a single positional path argument constrained to its directory prefix (`lists/` or `plans/`). Write interfaces read file content from stdin.

## 2. Separately prompted broader reads

A broader read from the Google Drive root is available via a script not registered as a dispatcher interface. It is intentionally not listed in `blueprint.yaml:suggested_permissions`.

If a script exits nonzero, report the visible error and do not infer remote
state beyond what the successful output established.

Files in this skill

  • SKILL.md6.1 KB
  • _rtx/__init__.py58 B
  • _rtx/_cp_llm.py390 B
  • _rtx/_delete_llm_file.py683 B
  • _rtx/_drive_gateway.py31.5 KB
  • _rtx/_ensure_oauth.py13.4 KB
  • _rtx/_ls_llm.py670 B
  • _rtx/_oauth_bootstrap.py8 KB
  • _rtx/_read_llm_file.py679 B
  • _rtx/_read_remote.py393 B
  • _rtx/_rm_llm.py390 B
  • _rtx/_write_llm_file.py681 B
  • _rtx/blueprint.yaml5.4 KB
  • _rtx/blueprints/rtx-delete-llm-file.yaml8.7 KB
  • _rtx/blueprints/rtx-ensure-oauth.yaml23.7 KB
  • _rtx/blueprints/rtx-init.yaml708 B
  • _rtx/blueprints/rtx-oauth-bootstrap.yaml7.4 KB
  • _rtx/blueprints/rtx-read-llm-file.yaml7.3 KB
  • _rtx/blueprints/rtx-write-llm-file.yaml9.6 KB
  • _rtx/tests/test_cloud_files.py17.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…