npx skills add ...
npx skills add alirezarezvani/claude-skills --skill google-workspace-cli
Google Workspace administration via the gws CLI (github.com/googleworkspace/cli). Install, authenticate, and automate Gmail, Drive, Sheets, Calendar, Docs, Chat, and Tasks. Run security audits and use local recipe templates and persona bundles. Use for Google Workspace admin, gws CLI setup, Gmail automation, Drive management, or Calendar scheduling.
npx skills add alirezarezvani/claude-skills --skill google-workspace-cli
Expert guidance and automation for Google Workspace administration using the open-source gws CLI (github.com/googleworkspace/cli, Apache-2.0). The CLI builds its command surface dynamically from Google's Discovery Service, so it covers every supported Workspace API plus +-prefixed helper commands. This skill adds local Python tools (doctor, auth guide, recipe catalog, security audit, output analyzer).
Verify before scripting:
gwsgenerates commands at runtime from Google's API discovery documents, and the CLI is pre-v1.0. Always confirm a command's exact surface withgws --help,gws <service> --help, orgws schema <service>.<resource>.<method>before putting it in automation. Commands in this skill marked (verify) are illustrative of thegws <service> <resource> <method>pattern and must be checked against your installed version.
Download from github.com/googleworkspace/cli/releases for macOS, Linux, or Windows. Nix users: nix run github:googleworkspace/cli.
| Variable | Purpose |
|---|---|
GOOGLE_WORKSPACE_CLI_CLIENT_ID | OAuth client ID |
GOOGLE_WORKSPACE_CLI_CLIENT_SECRET | OAuth client secret |
GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE | Path to exported credentials JSON |
GOOGLE_WORKSPACE_CLI_TOKEN | Pre-obtained OAuth token |
GOOGLE_WORKSPACE_CLI_CONFIG_DIR | Override default config location |
GOOGLE_WORKSPACE_CLI_LOG | Enable debug logging |
Goal: Automate email operations — send, search, label, and filter management.
Discovery commands follow gws <service> <resource> <method> and take request
parameters as JSON via --params (query/path params) and --json (request body).
Inspect any method's exact schema first:
Use --dry-run first, and --page-all to paginate (one JSON line per page):
Goal: Manage files, create spreadsheets, configure sharing, and export data.
Goal: Schedule events, find available times, and generate standup reports.
Goal: Audit Google Workspace security configuration and generate remediation commands.
| Area | Check | Risk |
|---|---|---|
| Drive | External sharing enabled | Data exfiltration |
| Gmail | Auto-forwarding rules | Data exfiltration |
| Gmail | DMARC/SPF/DKIM records | Email spoofing |
| Calendar | Default sharing visibility | Information leak |
| OAuth | Third-party app grants | Unauthorized access |
| Admin | Super admin count | Privilege escalation |
| Admin | 2-Step verification enforcement | Account takeover |
| Script | Purpose | Usage |
|---|---|---|
gws_doctor.py | Pre-flight diagnostics | python3 scripts/gws_doctor.py [--json] [--services gmail,drive] |
auth_setup_guide.py | Guided auth setup | python3 scripts/auth_setup_guide.py --guide oauth |
gws_recipe_runner.py | Recipe catalog & runner | python3 scripts/gws_recipe_runner.py --list [--persona pm] |
workspace_audit.py | Security/config audit | python3 scripts/workspace_audit.py [--json] [--demo] |
output_analyzer.py | JSON/NDJSON analysis | gws ... --json | python3 scripts/output_analyzer.py --count |
All scripts are stdlib-only, support --json output, and include demo mode with embedded sample data.
--dry-run before bulk destructive operationsgws output is structured JSON — pipe it through output_analyzer.py for filtering and aggregationgws workflow +* helpers for multi-step operations instead of chaining raw commandsgws_recipe_runner.py) as command templates, then verify each against gws --help--page-all emits one JSON line per page (NDJSON) for streaming large result sets--dry-run to preview any request before executing itfields parameter in --params (reduces payload size)pageSize in --params to cap results when browsing--page-all only when you need complete datasets; tune with --page-limit / --page-delay+ helpers (single optimized calls) over hand-chained API calls| Constraint | Impact |
|---|---|
| OAuth tokens expire after 1 hour | Re-auth needed for long-running scripts |
| API rate limits (per-user, per-service) | Bulk operations may hit 429 errors |
| Scope requirements vary by service | Must request correct scopes during auth |
| Pre-v1.0 CLI status | Breaking changes possible between releases |
| Google Cloud project required | Free, but requires setup in Cloud Console |
| Admin API needs admin privileges | Some audit checks require Workspace Admin role |
| Service | Key Scopes |
|---|---|
| Gmail | gmail.modify, gmail.send, gmail.labels |
| Drive | drive.file, drive.metadata.readonly |
| Sheets | spreadsheets |
| Calendar | calendar, calendar.events |
| Admin | admin.directory.user.readonly, admin.directory.group |
| Tasks | tasks |