procore-data-handling

v2026.09.24

Transfer Procore documents, images, and attachments through the documented upload and secure-download contracts with checksums, bounded retention, and resource association. Use when importing, exporting, or migrating construction files. Trigger with: "upload a file to Procore", "download Procore documents securely", "migrate Procore attachments".

GitHub
安装命令
npx skhub add jeremylongshore/procore-data-handling
Markdown
SKILL.md

Procore Governed File Transfer

Overview

Treat file bytes, upload sessions, returned storage instructions, resource association, and secure downloads as separate contracts. Never infer a permanent public URL or place customer documents in logs or diagnostic bundles.

Prerequisites

  • Approved company, project, target resource, file classification, and retention period
  • Current upload or document endpoint selected for the resource and file size
  • OAuth principal with required tool access and encrypted staging storage

Instructions

Step 1: Inventory the transfer

Record source checksum, media type, size, logical owner, target resource, and duplicate policy. Reject unsupported or unclassified content before upload.

Step 2: Choose the documented flow

Use the current direct, segmented, unified, or resource-specific upload sequence documented for the target. Do not reuse a legacy upload contract merely because it returns an identifier.

Step 3: Upload to provider storage

Follow the returned storage request exactly, including method, fields, segment ordering, and completion step. Never send the Procore Bearer token to an unrelated storage host unless documentation explicitly requires it.

Step 4: Associate the upload

Use the documented upload identifier or attachment-by-reference shape for the target resource. Reconcile the resource after association.

Step 5: Download securely

Treat returned file URLs as opaque and potentially changing. Supply the Bearer token where secure-file guidance requires it and avoid persisting signed or redirect URLs.

Step 6: Verify and expire

Compare checksums or an approved content assertion, record association IDs, then remove temporary bytes and URLs according to retention policy.

Authentication

Procore resource and secure-file requests use an OAuth 2.0 Bearer token and required company context. Storage-upload authorization follows the provider-returned upload contract; do not leak the Procore token across hosts.

Tool Discipline

Use Read and Grep to inspect file metadata, endpoint contracts, and retention rules. Use Write or Edit only for the approved transfer adapter, manifest, test, or redacted receipt; never write customer bytes into source control.

Output

  • Transfer and classification manifest
  • Upload, association, download, and checksum evidence
  • Temporary-storage deletion and retention receipt

Return identifiers and hashes, not file contents or signed URLs.

Examples

A drawing import creates the documented upload session, sends bytes to the returned storage destination, completes the upload, associates its upload ID with the target resource, verifies the resulting metadata, and deletes the encrypted staging copy.

Error Handling

FailureResponse
Storage upload failsPreserve the upload-session reference and retry only as that contract permits.
Association returns 422Validate target resource, upload ID, and endpoint-specific body without re-uploading blindly.
Download URL changes or redirectsTreat it as opaque and follow current secure-file guidance.
Checksum or content assertion failsQuarantine the result and do not publish it downstream.

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/procore-data-handling

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8