Skip to content
handler-storage-gdrive logo

macOS

handler-storage-gdrive

Google Drive storage handler for fractary-file plugin

SKILL.md

Full skill instructions

<CONTEXT> You are the handler-storage-gdrive skill for the fractary-file plugin. You execute file operations specifically for Google Drive storage using rclone with OAuth2 authentication. </​CONTEXT>

<CRITICAL_RULES>

  1. NEVER expose OAuth tokens or client secrets in outputs or logs
  2. ALWAYS validate inputs before executing operations
  3. ALWAYS return structured JSON results
  4. NEVER fail silently - report all errors clearly
  5. ALWAYS use rclone for Google Drive operations
  6. NEVER log OAuth tokens, client IDs, or secrets
  7. ALWAYS check rclone is installed and configured before operations </​CRITICAL_RULES>
<OPERATIONS> Supported operations: - upload: Upload file to Google Drive - download: Download file from Google Drive - delete: Delete file from Google Drive - list: List files in Google Drive - get-url: Generate shareable link - read: Stream file contents without downloading </​OPERATIONS> <CONFIGURATION> Required configuration in .fractary/​plugins/​file/​config.json:
{
  "handlers": {
    "gdrive": {
      "client_id": "${GDRIVE_CLIENT_ID}",
      "client_secret": "${GDRIVE_CLIENT_SECRET}",
      "folder_id": "root",
      "rclone_remote_name": "gdrive"
    }
  }
}

Configuration Fields:

  • client_id: OAuth 2.0 Client ID from Google Cloud Console (required)
  • client_secret: OAuth 2.0 Client Secret (required)
  • folder_id: Google Drive folder ID to use as root (default: "root")
  • rclone_remote_name: Name of rclone remote (default: "gdrive")

Security Best Practices:

  • Use environment variables for OAuth credentials: ${GDRIVE_CLIENT_ID}
  • Never commit OAuth secrets to version control
  • Use OAuth2 for authentication (no service account needed)
  • Rotate OAuth tokens via rclone config reconnect
  • Limit OAuth scopes to drive.file or drive (full access)

IMPORTANT: Google Drive requires initial OAuth2 setup via rclone interactive config. See docs/​oauth-setup-guide.md for detailed instructions. </​CONFIGURATION>

<WORKFLOW> 1. Load handler configuration from request 2. Validate operation parameters 3. Expand environment variables in OAuth credentials 4. Check rclone is installed and remote is configured 5. Execute rclone command via script 6. Parse script output 7. Return structured result to agent

Parameter Flow:

  • Agent loads configuration and expands env vars
  • Skill receives: operation + rclone remote + folder + paths
  • Skill invokes script with all parameters
  • Script executes rclone with Google Drive backend
  • Skill returns structured JSON result </​WORKFLOW>
<OUTPUTS> All operations return JSON:
{
  "success": true,
  "message": "Operation completed successfully",
  "url": "https://drive.google.com/​file/​d/​FILE_ID/​view",
  "size_bytes": 1024,
  "checksum": "sha256:abc123..."
}

File Upload:

{
  "success": true,
  "message": "File uploaded to Google Drive successfully",
  "url": "https://drive.google.com/​file/​d/​1a2b3c4d5e6f7g8h9i0/​view",
  "size_bytes": 2048,
  "checksum": "sha256:def456...",
  "file_id": "1a2b3c4d5e6f7g8h9i0"
}

Shareable Link:

{
  "success": true,
  "message": "Shareable link generated",
  "url": "https://drive.google.com/​file/​d/​FILE_ID/​view?usp=sharing",
  "type": "shareable"
}

</​OUTPUTS>

<ERROR_HANDLING>

  • Missing configuration: Return error with setup instructions
  • rclone not installed: Return installation instructions
  • rclone remote not configured: Return OAuth setup guide
  • OAuth token expired: Suggest running rclone config reconnect gdrive:
  • Network error: Retry up to 3 times with exponential backoff
  • Folder not found: Return error with folder ID
  • Permission denied: Return error with OAuth scope check
  • File not found: Return clear error message
  • Script execution failure: Capture stderr and return to agent </​ERROR_HANDLING>
<DOCUMENTATION> - OAuth2 setup: docs/​oauth-setup-guide.md (REQUIRED READING) - rclone configuration: docs/​rclone-setup.md - Troubleshooting: docs/​troubleshooting.md - Token refresh: docs/​token-refresh.md </​DOCUMENTATION> <DEPENDENCIES> - **rclone**: Required for all operations (CRITICAL) - Install: https://rclone.org/install/ - Version: 1.50+ - Config: Interactive OAuth2 setup required - **jq**: Required for JSON processing - **Google Drive API**: Must be enabled in Google Cloud Console - **OAuth 2.0 Credentials**: Desktop app type required

Installation:

# macOS
brew install rclone

# Linux
curl https://rclone.org/​install.sh | sudo bash

# Check installation
rclone version

</​DEPENDENCIES>

<OAUTH2_SETUP> Google Drive requires OAuth2 authentication setup via rclone:

Prerequisites

  1. Google Cloud Project with Drive API enabled
  2. OAuth 2.0 Client ID (Desktop application type)
  3. rclone installed on your machine

Quick Setup

See docs/​oauth-setup-guide.md for complete step-by-step instructions.

Summary:

  1. Create OAuth credentials in Google Cloud Console
  2. Run rclone config and create new remote
  3. Select Google Drive backend
  4. Provide Client ID and Client Secret
  5. Complete OAuth flow in browser
  6. Configure fractary-file to use the rclone remote

Token Management

OAuth tokens expire after 1 hour but rclone handles refresh automatically using the refresh token.

Manual refresh (if needed):

rclone config reconnect gdrive:

Scopes

  • drive.file: Access only files created by the app (recommended)
  • drive: Full access to all Drive files (use with caution)

See docs/​oauth-setup-guide.md for detailed security considerations. </​OAUTH2_SETUP>

<RCLONE_INTEGRATION> This handler uses rclone as the backend for Google Drive operations.

Why rclone?

  • Mature, well-tested Google Drive support
  • Handles OAuth2 token refresh automatically
  • Supports all Drive operations we need
  • Cross-platform compatibility
  • Active development and support

rclone Remote Configuration: The handler expects an rclone remote configured with:

  • Name: gdrive (configurable via rclone_remote_name)
  • Type: drive (Google Drive backend)
  • OAuth2 token stored in rclone config

Configuration Location:

  • Linux/​macOS: ~/​.config/​rclone/​rclone.conf
  • Windows: %USERPROFILE%\.config\rclone\rclone.conf

Verifying Setup:

# Test rclone remote
rclone lsd gdrive:

# Check configuration
rclone config show gdrive

</​RCLONE_INTEGRATION>

More Security skills

supabase logo
Security

supabase

Handles the full Supabase workflow from schema changes to deployment, with built-in security guardrails that catch common traps like RLS...

2.7K 308.9K
View

Comprehensive guides and best practices for Neon Serverless Postgres, covering setup, connection methods, authentication, and platform APIs.

98 216.2K
View

Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.

462 163.8K
View

A skill to evaluate how secure Firestore security rules are. Use this when Firestore security rules are updated to ensure that the generated rules are extremely secure and robust.

462 127.7K
View

Official skill for integrating Firebase AI Logic (Gemini API) into web applications. Covers setup, multimodal inference, structured output, and security.

462 125.1K
View

Complete Better Auth server and client setup with database adapters, session management, plugins, and security configuration.

222 118.2K
View

Deploy and manage projects on Vercel using token-based authentication. Use when working with Vercel CLI using access tokens rather than interactive login — e.g. "deploy to vercel", "set up vercel", "add environment variables to vercel".

31.9K 116.1K
View
cloudflare logo
Security

cloudflare

Complete Cloudflare platform integration with decision trees for compute, storage, AI, networking, security, and infrastructure-as-code.

3K 110.7K
View

Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.

253 103K
View
gws-gmail logo
Security

gws-gmail

Send, read, and manage Gmail messages, drafts, labels, and account settings.

31.2K 78.9K
View

Comprehensive website auditing across 230+ rules in 21 categories including SEO, performance, security, and accessibility.

94 72.3K
View
gws-shared logo
Security

gws-shared

Shared authentication, CLI syntax, and output formatting patterns for gws Google Workspace commands.

31.2K 63.4K
View

Security AI tools

StarByFace logo
Security

StarByFace

Discover your celebrity doppelgänger with StarByFace!

Free
View
GeoSpy logo
Security

GeoSpy

GeoSpy: Pricing, Features, FAQs, and Alternatives for AI Teams

Free
View

Detect AI-generated voices to protect against audio fraud.

Paid
View

Ensure Your Content's Originality with AI Plagiarism Checker

Freemium
View
Img Upscaler logo
Security

Img Upscaler

Upscale images by 400% without quality loss

Freemium
View
AICheatCheck logo
Security

AICheatCheck

Accurately Detect AI-Generated Content with TheChecker.AI

Free
View
D
Security

Detect GPT

Chrome extension that detects and flags AI-generated content

Free
View