Atlas / MCP servers / amgadabdelhafez / Dropbox Integration

Dropbox IntegrationSAFE

mcp/amgadabdelhafez/dropbox-integration

MCP Server for Dropbox

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
25 18r · 4w · 3d
Transport
stdio
License
MIT
Stars
30
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides integration with Dropbox, allowing MCP-compatible clients to interact with Dropbox through a set of powerful tools.

Important Disclaimer: This project is not affiliated with, endorsed by, or sponsored by Dropbox. It is an independent integration that works with Dropbox's public API.

Table of Contents

  • Quick Start
  • Installation
  • Authentication
  • Available Tools
  • Required Dropbox Permissions
  • Usage Examples
  • Development
  • License

Quick Start

  1. Clone the repository
  2. Run npm install to install dependencies
  3. Run npm run build to build the project
  4. Run npm run setup
  5. Configure your MCP client to use the server

Prerequisites

Register a Dropbox app at Dropbox App Console:

  • Choose "Scoped access" API
  • Choose the access type your app needs
  • Name your app and click "Create app"
  • Under "Permissions", select the desired permissions for the actions you will be using, for example:
  • files.metadata.read
  • files.content.read
  • files.content.write
  • sharing.write
  • account_info.read
  • Add http://localhost as your redirect URI
  • Note your App key and App secret

Installation

  1. Clone the repository
git clone https://github.com/your-username/dbx-mcp-server.git
cd dbx-mcp-server
  1. Install dependencies and build
npm install
npm run build
  1. Run the setup script
npm run setup
  1. Add to MCP settings

Add the following to your MCP settings file:

{
"mcpServers": {
"dbx": {
"command": "node",
"args": ["/path/to/dbx-mcp-server/build/index.js"]
}
}
}

Authentication

The server uses OAuth 2.0

Read from source at commit 7c87610f8c63OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add dbx-mcp-server --env DROPBOX_ACCESS_TOKEN=${DROPBOX_ACCESS_TOKEN} --env DROPBOX_APP_KEY=${DROPBOX_APP_KEY} --env DROPBOX_APP_SECRET=${DROPBOX_APP_SECRET} --env MAX_TOKEN_REFRESH_RETRIES=${MAX_TOKEN_REFRESH_RETRIES} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "dbx-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "DROPBOX_ACCESS_TOKEN": "${DROPBOX_ACCESS_TOKEN}",
        "DROPBOX_APP_KEY": "${DROPBOX_APP_KEY}",
        "DROPBOX_APP_SECRET": "${DROPBOX_APP_SECRET}",
        "MAX_TOKEN_REFRESH_RETRIES": "${MAX_TOKEN_REFRESH_RETRIES}"
      }
    }
  }
}
03

Exposed tools (25)

18 read · 4 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
copy_itemreadCopy a file or folder to a new location
create_folderwriteCreate a new folder (integrates with Dropbox)
dbx_helpreadGet help with file operations and commands (integrates with Dropbox)
delete_itemdestructiveLegacy delete operation (deprecated, use safe_delete_item instead)
download_filereadDownload a file to local disk and return the file path. Files are saved to the
file1readPath to the first file
file2readPath to the second file
fileTypesreadComma-separated list of file extensions to include (e.g.,
file_comparereadCompare two files and highlight differences
file_comparisonreadCompare two files
file_detailreadProvide detailed analysis of a specific file
file_reviewreadReview files in a specified folder and provide analysis
folder_reviewreadReview contents of a folder
get_account_inforeadGet information about the connected account (integrates with Dropbox)
get_file_contentreadGet the content of a file (integrates with Dropbox)
get_file_metadatareadGet metadata for a file or folder
get_sharing_linkwriteCreate a shared link for a file or folder
list_filesreadList files in a folder (integrates with Dropbox)
move_itemwriteMove or rename a file or folder
operationdestructiveThe operation to review (e.g., delete, move, copy)
pathreadThe file/folder path involved
review_operationreadReview a file operation before executing it (integrates with Dropbox)
safe_delete_itemdestructiveSafely delete a file or folder with recycle bin support, confirmation, and audit logging
search_file_dbreadAdvanced search for files and folders with filtering capabilities (integrates with Dropbox)
upload_filewriteUpload a file (integrates with Dropbox)
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_item, operation, safe_delete_item
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/dropbox/account.test.ts:4
import { decryptData } from '../../src/security-utils.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/resource/handler.test.ts:4
jest.mock('../../src/config.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/resource/handler.test.ts:5
jest.mock('../../src/auth.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/resource/handler.test.ts:6
jest.mock('../../src/dbx-api.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/resource/handler.test.ts:9
import { ResourceHandler } from '../../src/resource/resource-handler.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
axios, crypto-js, dotenv, dropbox, httpx, open, winston, @babel/core
Why it matters. 24 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7c87610f8c63full audit observations/trust-audit/mcp-server/amgadabdelhafez__dropbox-integration.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087c87610f8c63SAFEB89first audit
06

Questions

What is the Dropbox Integration MCP server?

MCP Server for Dropbox

What tools does Dropbox Integration expose?

25 in total: 18 read-only, 4 that write, and 3 that can delete or overwrite (delete_item, operation, safe_delete_item). Every one is listed on this page with its risk.

Is Dropbox Integration safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Dropbox Integration need?

It reads DROPBOX_ACCESS_TOKEN, DROPBOX_APP_KEY, DROPBOX_APP_SECRET, MAX_TOKEN_REFRESH_RETRIES, TOKEN_ENCRYPTION_KEY, TOKEN_REFRESH_RETRY_DELAY_MS, TOKEN_REFRESH_THRESHOLD_MINUTES and TOKEN_STORE_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Dropbox Integration run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as dbx-mcp-server at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (7c87610f8c63), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement