Skip to content
Back to skills

Xdrop

ASecurity

Use this skill when the user wants to send or fetch files through

  • 63 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 2, 2026
ai-agentsgobashrailsapi

Works with

  • terminal
  • cli
  • api

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 2, 2026

npx -y skills add nota-america/forgecat-agent-profiles --skill xdrop --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Xdrop?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Xdrop
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nota-america-xdrop/badge)](https://www.skillsdirectory.com/skills/nota-america-xdrop)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: xdrop
description: Use this skill when the user wants to send or fetch files through
  an Xdrop server from the terminal, asks to automate encrypted Xdrop share-link
  workflows, provides an Xdrop `/t/:transferId#k=...` link to download and
  decrypt locally, or needs Xdrop CLI flags such as `--quiet`, `--json`,
  `--expires-in`, `--output`, or `--api-url`, even if they do not explicitly
  mention the skill name.
---

Use the bundled scripts inside this skill directory.

## Available scripts

- `scripts/upload.mjs` — Upload local files or directories to an Xdrop server and print the share link
- `scripts/download.mjs` — Download an Xdrop share link, decrypt it locally, and save the files

Environment requirements:

- Bun
- Local filesystem access
- Network access to the target Xdrop server

## Upload

```bash
bun scripts/upload.mjs --server <xdrop-site-url> <file-or-directory> [...]
```

Prefer these flags when relevant:

- `--quiet`: suppress progress output and keep stdout clean
- `--json`: return `transferId`, `shareUrl`, and `expiresAt`
- `--expires-in <seconds>`: choose a supported expiry
- `--api-url <url>`: override the default `<server>/api/v1`
- `--name <value>`: set the transfer display name
- `--concurrency <n>`: limit parallel uploads per file

Useful examples:

```bash
bun scripts/upload.mjs --server http://localhost:8080 ./dist/report.pdf
bun scripts/upload.mjs --server http://localhost:8080 --quiet ./archive.zip
bun scripts/upload.mjs --server http://localhost:8080 --expires-in 600 --json ./notes.txt
```

If the user wants verification, upload a small temporary file and then confirm the public transfer API or browser can open the returned link.

## Download

Require the full share link, including `#k=...`. Without the fragment key, the transfer cannot be decrypted.

```bash
bun scripts/download.mjs "<share-url>"
```

Prefer these flags when relevant:

- `--output <dir>`: choose the destination directory
- `--quiet`: suppress progress output and keep stdout clean
- `--json`: return `transferId`, `outputRoot`, and saved file paths
- `--api-url <url>`: override the default `<share-origin>/api/v1`

Useful examples:

```bash
bun scripts/download.mjs "http://localhost:8080/t/abc123#k=..."
bun scripts/download.mjs --output ./downloads "http://localhost:8080/t/abc123#k=..."
bun scripts/download.mjs --quiet --json --output ./downloads "http://localhost:8080/t/abc123#k=..."
```

By default the downloader writes to `./xdrop-<transferId>` and preserves the manifest's relative paths.

## Gotchas

- A download link without the `#k=...` fragment is not decryptable. Ask for the full original share URL.
- Use `--quiet` whenever another command or caller needs to capture stdout. Progress logs otherwise go to stderr, but the final result still matters.

## Guardrails

- Prefer `--quiet` when another command or script needs to capture stdout.
- Keep the full share link fragment intact for downloads.
- Do not bypass the scripts' built-in path sanitization or transfer cleanup behavior with manual ad hoc commands unless the user explicitly asks.

Files in this skill

  • SKILL.md3 KB
  • scripts/download.mjs10.5 KB
  • scripts/upload.mjs19.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…