Use when a user needs a browser-accessible link to preview, present, or send Agent-generated workspace files, an entire project, or the current topic outside Super Magic—especially rendered output such as HTML that messaging or file-viewing channels cannot display directly—or when they need to find, reuse, change, or delete an existing share.
72
88%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Use these Code Mode tools from a Python snippet executed with run_sdk_snippet. Import tool from sdk.tool and call tools with tool.call(...).
list_file_shares with the original exact file_paths before creating anything.inspect_file_share would reduce uncertainty; it is optional assistance, not a mandatory step. Treat its output as static candidates only, then verify candidates against the entry and relevant files. If confirmed local dependencies are omitted, explain that images, styles, fonts, video, or interactions may be missing. When the user has not already requested the related files, ask whether to include them, preferably with an interactive question when available. Do not add unrequested files.create_file_share.list_file_shares again with that final set before creating.entry_file_path.When the original file set already has an active share and the user approves adding dependencies, read that share and call update_file_share with the complete final file_paths and the existing entry_file_path. Do not call create_file_share for this repair; preserve the original resource ID and settings. The file list is a complete replacement, so retain every existing file that should remain shared.
Use the user's language when asking about access. A concise question is:
How should this be shared?
1. Team access: safest; only team members can open it, but it is less convenient for external recipients.
2. Password access: recommended balance of safety and convenience; file and project password shares require VIP.
3. Public access: highest risk; anyone with the link can open it. Use only for intentional public distribution.Use the literal string values shown for fields with alternatives.
list_file_shares(
file_paths: list[str] = [],
status: "active" | "expired" | "deleted" | "all" = "active",
keyword: str | None = None,
current_project_only: bool = True,
page: int = 1,
page_size: int = 20,
)Pass file_paths for exact active-share lookup. Omit it only when browsing file shares. Browsing is limited to the current project unless the user explicitly requests a cross-project search. Exact lookup returns the password when one exists; browsing results do not expose passwords.
For list tools, status="expired" includes shares that passed their expiry time and shares that were manually disabled. status="deleted" means the share record was deleted and the link is unavailable.
create_file_share(
file_paths: list[str],
entry_file_path: str,
access_type: "password" | "team" | "public" = "password",
password: str | None = None,
team_scope: "all" | "designated" = "all",
team_user_ids: list[str] = [],
team_department_ids: list[str] = [],
expire_days: int | None = None,
show_original_info: bool = True,
allow_download: bool = True,
allow_copy: bool = True,
show_file_list: bool = True,
hide_super_magic_watermark: bool = False,
immersive: bool = False,
)file_paths and entry_file_path are required. The entry file must also appear in file_paths. Paths must remain inside the current workspace and already have MagicFS file IDs.
access_type="password". Omit password to generate a secure password.access_type="team" and keep team_scope="all".access_type="team", team_scope="designated", and provide at least one user or department ID.access_type="public" only after explicit user approval.expire_days=None means permanent; otherwise use an integer from 1 to 365.show_original_info=False hides original author information and does not require VIP.allow_copy=False prevents viewers from copying shared files into their workspace.hide_super_magic_watermark=True requires VIP and hides only the bottom-right “Created by Super Magic” watermark, not all product branding.immersive=True opens the entry file in a full-screen immersive presentation and hides both the share-page header and the file-preview header.from sdk.tool import tool
result = tool.call("list_file_shares", {
"file_paths": ["site/index.html", "site/styles.css", "site/app.js"],
})
print(result.content)Read result.data["items"]. Reuse one unambiguous result when the user requested no changes. Ask the user to choose when more than one result exists.
result = tool.call("create_file_share", {
"file_paths": ["site/index.html", "site/styles.css", "site/app.js"],
"entry_file_path": "site/index.html",
})
print(result.content)The omitted password is generated securely. Return both the URL and password.
result = tool.call("create_file_share", {
"file_paths": ["public/product-guide.pdf"],
"entry_file_path": "public/product-guide.pdf",
"access_type": "public",
})Use this only when the user clearly accepts public access.
delete_share(
share_ref: str,
confirmed: bool,
)share_ref accepts a numeric resource ID or a complete /share/files/{id} or /share/topic/{id} URL. For a topic share, pass its topic ID directly because it is the share resource ID.
delete_share with confirmed=True.confirmed=True only when the user's words clearly authorize deletion of the now-unambiguous share. A question such as “Do we still need this?” is not authorization.result = tool.call("delete_share", {
"share_ref": "https://example.com/share/files/123456",
"confirmed": True,
})
print(result.content)Always check result.ok.
result.content first to understand what happened.result.data:
result.data["items"];share_url, password, resource_id, and operation.share_url that is present in result.data. Password-share URLs returned by the tools already include the password query parameter when the password is known; pass them through unchanged. Never invent or rewrite a link.delete_share.confirmed=True without explicit user authorization.f9973c5
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.