box

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Box

Box

Use Box as the cloud file system for file operations, collaboration, metadata, and document work. Run operations with Hermes'
terminal
tool and use the Box CLI; use the SDK guide when building an application.
将 Box 用作云文件系统,以执行文件操作、协作、元数据管理及文档处理工作。借助 Hermes 的
terminal
工具并使用 Box CLI 运行操作;构建应用程序时请遵循 SDK 指南。

When to Use

适用场景

  • Organizing, uploading, versioning, moving, sharing, or collaborating on Box files and folders
  • Searching Box content or existing metadata
  • Asking questions about Box files, extracting metadata, or generating text grounded in a file
  • Processing a Box folder at scale without downloading every source file
  • Building a Box-backed application, integration, or webhook handler
  • 对 Box 文件和文件夹进行整理、上传、版本控制、移动、共享或协作
  • 搜索 Box 内容或现有元数据
  • 询问有关 Box 文件的问题、提取元数据,或基于文件生成文本
  • 批量处理 Box 文件夹,无需下载每个源文件
  • 构建基于 Box 的应用程序、集成或 Webhook 处理程序

Start broad file-system conversations

开启宽泛的文件系统对话

When someone is exploring a cloud file system for Hermes, first give a short fit assessment: Box is useful when a team needs cloud file storage, sharing, search, metadata, and document work. Then ask whether they want to connect a Box account with OAuth or build a Box-backed application or integration with an SDK.
OAuth makes Hermes act as the Box account authorized in the browser. That account's Box permissions determine what Hermes can access. To give Hermes narrower access, authorize an account that is invited only to the required files, folders, or Hubs.
Do not run setup, show a command cookbook, propose account plans or folder taxonomies, or load every reference for a broad exploratory question. Wait for the user's answer, then load only the relevant path. When a request already names a concrete outcome, skip this discovery step and handle that outcome directly.
Start normal CLI work with the official Box CLI OAuth app. It covers ordinary content work and Box AI. Use a custom User Authentication (OAuth 2.0) Platform App only when the requested operation needs an additional OAuth scope, such as webhook management. This remains an OAuth flow; do not substitute a server-side or impersonation identity.
当有人为 Hermes 探索云文件系统时,首先给出简短的适配评估:当团队需要云文件存储、共享、搜索、元数据管理及文档处理工作时,Box 会非常实用。然后询问他们是否希望通过 OAuth 连接 Box 账户,或是使用 SDK 构建基于 Box 的应用程序或集成。
OAuth 可让 Hermes 充当浏览器中已授权的 Box 账户。该账户的 Box 权限决定了 Hermes 可访问的内容范围。若要为 Hermes 设置更窄的访问权限,请仅授权一个被邀请访问所需文件、文件夹或 Hub 的账户。
对于宽泛的探索性问题,不要执行设置操作、展示命令手册、提议账户方案或文件夹分类法,也不要加载所有参考资料。等待用户回复后,仅加载相关路径。如果请求已明确指定具体结果,则跳过此探索步骤,直接处理该结果。
使用官方 Box CLI OAuth 应用启动常规 CLI 工作,它涵盖普通内容处理和 Box AI。仅当请求的操作需要额外的 OAuth 权限(如 Webhook 管理)时,才使用自定义的 User Authentication (OAuth 2.0) 平台应用。这仍属于 OAuth 流程;请勿替换为服务器端身份或模拟身份。

Perform chosen setup interactively

交互式执行选定的设置操作

When a user selects an authentication path or asks Hermes to connect Box, perform the setup through
terminal
; do not turn the next response into instructions for the user to copy. Take the next safe action yourself, and pause only for an approval, browser sign-in, administrator action, or secret that Hermes cannot safely supply.
  • If
    box
    is missing, ask for any terminal approval required to install
    @box/cli
    under the current Hermes home at
    tools/box-cli
    ; then verify it with the shell-appropriate command in CLI guide. Do not attempt a global npm install, use
    sudo
    , change npm's global prefix, or change
    PATH
    .
  • Before OAuth, ask: “Is Hermes running on the same computer as the browser you will use to authorize Box, or on a remote host such as a VPS, container, or cloud VM?” Use normal
    box login
    only for the same-computer path. Use
    box login --code
    only for the remote/headless path. Do not infer runtime topology from the operating system alone; read OAuth setup after the user answers.
  • Before starting browser authorization, state that Hermes will act as the Box account signed in there. If the user wants narrower access, they can authorize an account that is invited only to the required files, folders, or Hubs. Do not make that account an administrator to unlock an exceptional operation.
  • If a custom OAuth Platform App is necessary, use the CLI's interactive Platform App flow. Ask the user to enter its client secret only in the local CLI prompt; never request it in chat, write it to Hermes configuration, or commit it.
  • If an install, browser authorization, environment switch, or permission change needs approval, request that approval and resume the setup after it is granted. Do not replace the action with a command list.
当用户选择认证路径或要求 Hermes 连接 Box 时,通过
terminal
执行设置操作;不要将下一次回复变成供用户复制的指令。自行执行下一步安全操作,仅在需要批准、浏览器登录、管理员操作或 Hermes 无法安全提供的密钥时暂停。
  • 如果缺少
    box
    命令,请求获得终端权限以在当前 Hermes 主目录下的
    tools/box-cli
    安装
    @box/cli
    ;然后使用 CLI guide 中适合当前 shell 的命令进行验证。不要尝试全局 npm 安装、使用
    sudo
    、更改 npm 的全局前缀或修改
    PATH
  • 在 OAuth 认证前,询问:“Hermes 是否与你将用于授权 Box 的浏览器运行在同一台计算机上,还是运行在远程主机(如 VPS、容器或云虚拟机)上?” 仅当在同一计算机上时使用常规的
    box login
    ;仅当在远程/无头环境下时使用
    box login --code
    。不要仅根据操作系统推断运行时拓扑;用户回复后请查阅 OAuth setup
  • 在启动浏览器授权前,说明 Hermes 将充当登录的 Box 账户。如果用户希望限制访问范围,他们可以仅授权一个被邀请访问所需文件、文件夹或 Hub 的账户。不要为了解锁特殊操作而将该账户设为管理员。
  • 如果需要自定义 OAuth 平台应用,请使用 CLI 的交互式平台应用流程。仅让用户在本地 CLI 提示符中输入其客户端密钥;切勿在聊天中请求密钥、将其写入 Hermes 配置或提交到代码仓库。
  • 如果安装、浏览器授权、环境切换或权限变更需要批准,请请求批准,获得批准后再继续设置。不要将操作替换为命令列表。

Start each task

启动每项任务

  1. Confirm the CLI and current actor. Probe with
    command -v box
    on POSIX shells or
    Get-Command box -ErrorAction SilentlyContinue
    in PowerShell. If
    box
    is on
    PATH
    , use it. If Hermes installed the CLI under its current home, use the shell-appropriate verified runner in CLI guide in place of every leading
    box
    . Then run
    box users:get me --json --fields id,name,login
    with that runner. If this succeeds, record the actor and continue. Do not ask about authentication again. Treat
    folders:items 0
    only as a listing of the actor's root; it is not proof that a shared file, folder, or Hub is inaccessible. For a known file or folder, verify its ID directly; for a Hub, use the Hubs discovery path in Box Hubs.
  2. If authentication is absent, ask to connect a Box account with OAuth, then ask whether Hermes and the authorization browser run on the same computer or on separate hosts. Read OAuth setup.
  3. Read the relevant reference before operating. Use documented commands first; only run subcommand help when the request needs an option not covered by the reference or the installed CLI rejects the documented form.
Examples labeled
bash
use POSIX continuation syntax. In PowerShell, run the Box command on one line or replace each trailing
\
with PowerShell's backtick continuation. Do not paste POSIX variable assignments into PowerShell.
  1. 确认 CLI 和当前执行者。在 POSIX shell 中使用
    command -v box
    ,或在 PowerShell 中使用
    Get-Command box -ErrorAction SilentlyContinue
    进行检测。如果
    box
    PATH
    中,则直接使用。如果 Hermes 在当前主目录下安装了 CLI,请使用 CLI guide 中适合当前 shell 的验证运行器替代所有开头的
    box
    。然后使用该运行器执行
    box users:get me --json --fields id,name,login
    。 如果执行成功,记录执行者并继续。不要再询问认证相关问题。仅将
    folders:items 0
    视为执行者根目录的列表;这不能证明共享文件、文件夹或 Hub 无法访问。对于已知的文件或文件夹,直接验证其 ID;对于 Hub,请使用 Box Hubs 中的 Hub 发现路径。
  2. 如果未进行认证,请询问是否通过 OAuth 连接 Box 账户,然后询问 Hermes 和授权浏览器是否运行在同一台计算机或不同主机上。查阅 OAuth setup
  3. 操作前查阅相关参考资料。优先使用文档化的命令;仅当请求需要参考资料未涵盖的选项,或已安装的 CLI 拒绝文档化的命令形式时,才查看子命令帮助。
标记为
bash
的示例使用 POSIX 续行语法。在 PowerShell 中,请将 Box 命令放在一行,或将每个末尾的
\
替换为 PowerShell 的反引号续行符。不要将 POSIX 变量赋值粘贴到 PowerShell 中。

Extend the CLI without pausing

无需暂停即可扩展 CLI 功能

When the Box CLI lacks a dedicated subcommand, use
box request
for the matching REST endpoint and continue the ordinary operation. Do not ask the user to choose merely because the implementation uses REST; it is the same Box task and preserves the configured CLI identity. Read REST API fallback when the endpoint needs a request body or custom header.
Ask before a delete, a collaboration/shared-link or permission change, an identity change, a broad or costly batch mutation, or when the target or scope is ambiguous. Otherwise perform the requested operation and verify it.
当 Box CLI 缺少专用子命令时,使用
box request
调用匹配的 REST 端点,继续执行常规操作。不要仅仅因为实现使用 REST 就让用户选择;这仍是相同的 Box 任务,且会保留已配置的 CLI 身份。当端点需要请求体或自定义标头时,请查阅 REST API fallback
在执行删除、协作/共享链接或权限变更、身份变更、大范围或高成本的批量变更,或目标/范围不明确时,请先询问用户。否则,请执行请求的操作并进行验证。

Choose the right path

选择正确的路径

NeedRead
CLI conventions, environments, JSON, or REST escape hatchCLI guide
Files, folders, versions, links, or collaborationsContent workflows
Search, metadata, Box AI, or AI unitsSearch and AI
Curated large-scale Q&A or a reusable knowledge baseBox Hubs
Many files or a resumable batchBulk operations
Application code or a Box SDKSDK development
Webhooks or Events APIWebhooks and events
CLI unavailable or a missing CLI operationREST API fallback
Auth, permissions, rate limits, or API errorsTroubleshooting
需求查阅文档
CLI 约定、环境、JSON 或 REST 替代方案CLI guide
文件、文件夹、版本、链接或协作Content workflows
搜索、元数据、Box AI 或 AI 单元Search and AI
精心策划的大规模问答或可重用知识库Box Hubs
多文件或可恢复的批量操作Bulk operations
应用程序代码或 Box SDKSDK development
Webhook 或 Events APIWebhooks and events
CLI 不可用或缺少 CLI 操作REST API fallback
认证、权限、速率限制或 API 错误Troubleshooting

Content handling policy

内容处理策略

For semantic analysis of Box-hosted content, prefer Box AI: it preserves Box permissions, processes source files through Box's governed AI integration, keeps source-file bodies out of Hermes' coding-model context, and scales document work without downloading every file. Do not criticize or block another workflow; use it when the user explicitly chooses it.
Use existing Box metadata or metadata queries for deterministic lookups. Otherwise use Box AI:
  • ai:ask
    for Q&A, summaries, and comparisons
  • ai:extract-structured
    for known fields or metadata templates
  • ai:extract
    for flexible key-value extraction
  • ai:text-gen
    for writing grounded in one Box file
For Q&A over more than 25 files or a reusable curated knowledge base, prefer Box AI for Hubs. Discover an existing accessible Hub first; only create or populate one after the user approves the shared-resource change. If no Hub is available and the user does not want one created, narrow a one-off request with search or metadata. Do not use a Hub for metadata extraction or text generation. Read Box Hubs.
When the user asks to extract metadata from a Box file, treat it as a request to persist the result unless they ask for a preview. Use structured extraction with inline fields when the desired schema is known and freeform extraction when the fields are exploratory. Reuse a compatible existing enterprise template when one represents every requested field. Otherwise store flat scalar results in the built-in
global.properties
metadata instance, or upload a JSON sidecar beside the source file when the result contains nested objects, tables, or values that must retain their types. Read every write back and compare it with the intended result. Never silently substitute a file description, attach a partial or unrelated template, truncate fields, or discard fields.
Do not create or change metadata templates. Box does not permit creation of global templates, and enterprise-template administration is outside Hermes' normal OAuth content workflow. If the user needs reusable typed enterprise metadata and no compatible template exists, explain that a Box Admin or authorized Co-Admin must create it separately, leave existing structured metadata unchanged, and report the persisted
global.properties
instance or JSON sidecar instead. Read Search and AI for the complete extraction and writeback workflow.
Before the first Box AI request, state that Box AI must be enabled, consumes AI units, and remains limited to the current actor's permissions; do not wait for acknowledgement. An AI response returned to Hermes can still contain sensitive information. Confirm only when a material batch's file scope or expected AI-unit use is ambiguous, or when the user has not explicitly requested that scale. See Search and AI.
对 Box 托管的内容进行语义分析时,优先使用 Box AI:它会保留 Box 权限,通过 Box 受管控的 AI 集成处理源文件,将源文件内容排除在 Hermes 的编码模型上下文之外,并且无需下载每个文件即可扩展文档处理工作。不要批评或阻止其他工作流;仅当用户明确选择时才使用其他工作流。
对于确定性查找,请使用现有的 Box 元数据或元数据查询。否则,请使用 Box AI:
  • ai:ask
    用于问答、摘要和比较
  • ai:extract-structured
    用于已知字段或元数据模板
  • ai:extract
    用于灵活的键值提取
  • ai:text-gen
    用于基于单个 Box 文件的文本生成
对于超过 25 个文件的问答或可重用的精心策划知识库,优先使用适用于 Hub 的 Box AI。首先查找现有的可访问 Hub;仅在用户批准共享资源变更后才创建或填充 Hub。如果没有可用的 Hub 且用户不想创建,请通过搜索或元数据缩小一次性请求的范围。不要将 Hub 用于元数据提取或文本生成。查阅 Box Hubs
当用户要求从 Box 文件中提取元数据时,除非他们要求预览,否则将其视为持久化结果的请求。当所需架构已知时,使用带内联字段的结构化提取;当字段处于探索阶段时,使用自由格式提取。如果存在兼容的现有企业模板且涵盖所有请求字段,请重用该模板。否则,将扁平标量结果存储在内置的
global.properties
元数据实例中;如果结果包含嵌套对象、表格或必须保留类型的值,则在源文件旁边上传 JSON 辅助文件。回读所有写入内容并与预期结果进行比较。切勿静默替换文件描述、附加部分或无关模板、截断字段或丢弃字段。
不要创建或修改元数据模板。Box 不允许创建全局模板,且企业模板管理超出了 Hermes 常规 OAuth 内容工作流的范围。如果用户需要可重用的类型化企业元数据且没有兼容模板,请说明 Box 管理员或授权的协管员必须单独创建它,保持现有结构化元数据不变,并报告持久化的
global.properties
实例或 JSON 辅助文件。查阅 Search and AI 获取完整的提取和回写工作流。
在首次发起 Box AI 请求前,说明 Box AI 必须已启用、会消耗 AI 单元,并且权限仅限于当前执行者;无需等待确认。返回给 Hermes 的 AI 响应仍可能包含敏感信息。仅当批量操作的文件范围或预期 AI 单元使用情况不明确,或用户未明确请求该规模时,才进行确认。请参阅 Search and AI

Operate safely

安全操作

  • Prefer IDs to paths and verify the current actor before diagnosing a missing file.
  • Use
    --json
    and
    --fields
    to keep output small. For mutations, inventory first, confirm ambiguous or large scope, then read back the result.
  • Run ordered CLI mutations serially so progress and recovery are unambiguous. Use documented bulk input support or bounded SDK concurrency for scalable work.
  • Do not create a shared link merely to provide navigation. Shared links change access and require explicit confirmation.
  • Do not put secrets in chat, command output, source control, or logs.
  • 优先使用 ID 而非路径,在诊断文件缺失前验证当前执行者。
  • 使用
    --json
    --fields
    缩小输出范围。对于变更操作,先盘点内容,确认不明确或大范围的操作,然后回读结果。
  • 按顺序串行执行 CLI 变更操作,以便明确进度和恢复方式。对于可扩展的工作,使用文档化的批量输入支持或有限的 SDK 并发。
  • 不要仅仅为了提供导航而创建共享链接。共享链接会改变访问权限,需要明确确认。
  • 不要在聊天、命令输出、版本控制或日志中放置机密信息。

Report results

报告结果

For every individually reported Box item, include its ID and a clickable navigation link:
  • File:
    https://app.box.com/file/<FILE_ID>
  • Folder:
    https://app.box.com/folder/<FOLDER_ID>
  • Hub:
    https://app.box.com/hubs/<HUB_ID>
For large batches, link the source and destination folders plus exceptions instead of listing hundreds of items. A human may not be able to open content that is only visible to the connected Box account; state that clearly. Include the actor and verification performed in every write summary.
对于每个单独报告的 Box 项,包含其 ID 和可点击的导航链接:
  • 文件:
    https://app.box.com/file/<FILE_ID>
  • 文件夹:
    https://app.box.com/folder/<FOLDER_ID>
  • Hub:
    https://app.box.com/hubs/<HUB_ID>
对于大规模批量操作,链接源文件夹和目标文件夹以及异常项,而非列出数百个项。人类可能无法打开仅对已连接的 Box 账户可见的内容;请明确说明这一点。在每个写入摘要中包含执行者和执行的验证操作。

Verify

验证

After any write, fetch the file or folder with the same actor or list its parent and confirm the returned ID and name. For a metadata write, retrieve the metadata instance and compare every returned field with the intended value; an HTTP success alone is not verification. Report missing, normalized, or rejected values. For a disposable setup check, create a smoke folder, verify it, then delete it only if the user authorized cleanup.
任何写入操作完成后,使用同一执行者获取文件或文件夹,或列出其父级并确认返回的 ID 和名称。对于元数据写入操作,检索元数据实例并将每个返回字段与预期值进行比较;仅 HTTP 成功并不代表验证通过。报告缺失、标准化或被拒绝的值。对于一次性设置检查,创建一个测试文件夹,进行验证,仅在用户授权清理时才删除它。