Use this skill when the user wants to send or fetch files through an Xdrop server from the terminal, asks to automate encrypted Xdrop share-link workflows, provides an Xdrop `/t/:transferId#k=...` link to download and decrypt locally, or needs Xdrop CLI flags such as `--quiet`, `--json`, `--expires-in`, `--output`, or `--api-url`, even if they do not explicitly mention the skill name.
Intro in this page language first. The official description stays in its original wording; we do not rewrite SKILL.md.
What it does
Use this skill when the user wants to send or fetch files through an Xdrop server from the terminal, asks to automate encrypted Xdrop share-link workflows, provides an Xdrop `/t/:transferId#k=...` link to download and decrypt locally, or needs Xdrop CLI flags such as `--quiet`, `--json`, `--expires-in`, `--output`, or `--api-url`, even if they do not explicitly mention the skill name.
When to use it
The official description does not include a separate “Use when”. Per the spec, agents activate this skill when the task matches keywords in that description.
How agents load it
Per Agent Skills progressive disclosure: name and description load at startup (~100 tokens); the full SKILL.md body loads when the skill activates; scripts/, references/, and assets/ load only as needed. This file's sections: Available scripts; Upload; Download; Gotchas; Guardrails.
File analysis
File analysis: besides SKILL.md, the body references scripts/upload.mjs, scripts/download.mjs. Those resources load on demand.
Use this skill when the user wants to send or fetch files through an Xdrop server from the terminal, asks to automate encrypted Xdrop share-link workflows, provides an Xdrop `/t/:transferId#k=...` link to download and decrypt locally, or needs Xdrop CLI flags such as `--quiet`, `--json`, `--expires-in`, `--output`, or `--api-url`, even if they do not explicitly mention the skill name.
DiscoverThe client exposes names and descriptions to the agent.
ActivateYour request or the task context selects the skill and loads its instructions.
Load resourcesReferenced scripts, documentation and assets are used when needed.
Files referenced by the instructions · 2
scripts/upload.mjs
scripts/download.mjs
These paths are extracted from the text. Check the upstream package to verify the files exist.
Choose the target agent and installation scope, keep referenced package files, then verify the skill appears in the client's catalog.
This skill references supporting files. Retrieve the complete directory from the source; copying SKILL.md alone may leave missing dependencies.
Ask your Agent to install
Copy these instructions to a compatible agent and confirm the target directory matches your client.
Install the agent skill "xdrop" into my project. The full SKILL.md and official description are at https://zicq.com/en/skills/skl-e0d8373380b54481-Xdrop.html
Save it as .cursor/skills/xdrop/SKILL.md or .claude/skills/xdrop/SKILL.md and keep the frontmatter name and description exactly as-is.
This skill also ships scripts/, references/, or assets/ — fetch the whole folder from https://github.com/xixu-me/skills instead of creating only a SKILL.md.
The CLI lets you choose the agent interactively. The default scope is the project; use -g for user scope. Confirm package availability with the discovery command, then use npx skills list to inspect installed skills.
Readable layout
---
name: xdrop
description: Use this skill when the user wants to send or fetch files through an Xdrop server from the terminal, asks to automate encrypted Xdrop share-link workflows, provides an Xdrop `/t/:transferId#k=...` link to download and decrypt locally, or needs Xdrop CLI flags such as `--quiet`, `--json`, `--expires-in`, `--output`, or `--api-url`, even if they do not explicitly mention the skill name.
---
Use the bundled scripts inside this skill directory.
## Available scripts
- `scripts/upload.mjs` — Upload local files or directories to an Xdrop server and print the share link
- `scripts/download.mjs` — Download an Xdrop share link, decrypt it locally, and save the files
Environment requirements:
- Bun
- Local filesystem access
- Network access to the target Xdrop server
## Upload
```bash
bun scripts/upload.mjs --server [...]
```
Prefer these flags when relevant:
- `--quiet`: suppress progress output and keep stdout clean
- `--json`: return `transferId`, `shareUrl`, and `expiresAt`
- `--expires-in `: choose a supported expiry
- `--api-url `: override the default `/api/v1`
- `--name `: set the transfer display name
- `--concurrency `: limit parallel uploads per file
Useful examples:
```bash
bun scripts/upload.mjs --server http://localhost:8080 ./dist/report.pdf
bun scripts/upload.mjs --server http://localhost:8080 --quiet ./archive.zip
bun scripts/upload.mjs --server http://localhost:8080 --expires-in 600 --json ./notes.txt
```
If the user wants verification, upload a small temporary file and then confirm the public transfer API or browser can open the returned link.
## Download
Require the full share link, including `#k=...`. Without the fragment key, the transfer cannot be decrypted.
```bash
bun scripts/download.mjs ""
```
Prefer these flags when relevant:
- `--output `: choose the destination directory
- `--quiet`: suppress progress output and keep stdout clean
- `--json`: return `transferId`, `outputRoot`, and saved file paths
- `--api-url `: override the default `/api/v1`
Useful examples:
```bash
bun scripts/download.mjs "http://localhost:8080/t/abc123#k=..."
bun scripts/download.mjs --output ./downloads "http://localhost:8080/t/abc123#k=..."
bun scripts/download.mjs --quiet --json --output ./downloads "http://localhost:8080/t/abc123#k=..."
```
By default the downloader writes to `./xdrop-` and preserves the manifest's relative paths.
## Gotchas
- A download link without the `#k=...` fragment is not decryptable. Ask for the full original share URL.
- Use `--quiet` whenever another command or caller needs to capture stdout. Progress logs otherwise go to stderr, but the final result still matters.
## Guardrails
- Prefer `--quiet` when another command or script needs to capture stdout.
- Keep the full share link fragment intact for downloads.
- Do not bypass the scripts' built-in path sanitization or transfer cleanup behavior with manual ad hoc commands unless the user explicitly asks.