Google Workspace
Plan, audit, and safely execute Google Workspace admin, Gmail, Calendar, Drive, Groups, and user lifecycle work. Use when Codex is asked to help with Workspa... Skill: Google Workspace Owner: patrick-erichsen-2 Summary: Plan, audit, and safely execute Google Workspace admin, Gmail, Calendar, Drive, Groups, and user lifecycle work. Use when Codex is asked to help with Workspa... Tags: latest:1.0.0 Version history: v1.0.0 | 2026-06-17T22:51:52.506Z | user Initial owner-scoped publish smoke Archive index: Archive v1.0.0: 6 files, 5399 bytes Files: agents/openai.yaml (223b), ref
Rank
62
Safety
84
Downloads
2.3k
Updated
Oct 9, 2026
Version
1.0.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.3K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.3K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.0.0release · observed Jun 17, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s179jqny1cgx553xanb7mgrwz185p0c2:google-workspace- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-patrick-erichsen-2-google-workspace/snapshot"
Documentation
CLAWHUB
8,274 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: google-workspace description: Plan, audit, and safely execute Google Workspace admin, Gmail, Calendar, Drive, Groups, and user lifecycle work. Use when Codex is asked to help with Workspace migrations, account cleanups, permission audits, group rollouts, mailbox/calendar changes, or API/GAM/gcloud command planning. --- # Google Workspace Use this skill to turn Google Workspace administration requests into safe, reviewable plans and commands. Default to read-only discovery before proposing changes, and keep destructive operations behind explicit confirmation. ## Workflow 1. Identify the workspace surface: Admin Directory, Gmail, Calendar, Drive, Groups, Vault, or shared drives. 2. Establish the actor and auth path: browser admin console, `gam`, `gcloud`, service account with domain-wide delegation, or direct Google API calls. 3. Gather read-only evidence first: - affected users, groups, aliases, calendars, labels, drives, or files - current ownership and permission state - exact scope of change and rollback path 4. Produce a preview plan with commands or API calls marked as `read`, `proposed write`, or `rollback`. 5. Ask for approval before any write, delete, transfer, suspend, archive, or sharing-change operation. ## Command Guidance Prefer commands that can be copied and audited. Use placeholders for domains, users, groups, and file IDs until the user provides real values. For `gam`, prefer patterns like: ```bash gam info user [email protected] gam print groups member [email protected] gam print drivefileacls query "owner = '[email protected]'" ``` For `gcloud`, first confirm the active project and account: ```bash gcloud config list account project gcloud auth list ``` For direct API calls, name the API, HTTP method, endpoint, required OAuth scope, and dry-run/read-only equivalent when one exists. ## Safety Rules - Never invent customer domains, user emails, group names, file IDs, or org-unit paths. - Treat suspended users, external sharing, delegated mailboxes, super-admin accounts, Vault holds, and shared drive ownership as high-risk. - Before bulk changes, generate a CSV or JSON input schema and a rollback export. - For deletions, prefer suspend/archive/transfer workflows unless the user has explicitly requested irreversible deletion. - For mail/calendar migrations, separate identity mapping, data transfer, delegation, forwarding, and retention policy steps. ## Reusable Resources - Read `references/scopes.md` when selecting API scopes or explaining OAuth permissions. - Run `scripts/workspace-change-plan.mjs <input.json>` to turn a small JSON change set into a Markdown rollout checklist. Example input: ```json { "title": "Sales group cleanup", "owner": "[email protected]", "changes": [ { "kind": "group-membership", "target": "[email protected]", "action": "remove stale members", "risk": "medium", "rollback": "restore exported membership CSV"
_meta.json
{
"ownerId": "kn7485dek1erzmvwaqz77rm5vh85pyb3",
"slug": "google-workspace",
"version": "1.0.0",
"publishedAt": 1781736712506
}references/scopes.md
# Google Workspace Scopes Use the narrowest scope that supports the requested operation. Prefer read-only scopes during discovery. ## Common Read Scopes | Surface | Scope | Use | | --- | --- | --- | | Admin Directory users | `https://www.googleapis.com/auth/admin.directory.user.readonly` | List or inspect users, aliases, org units, and profile metadata | | Admin Directory groups | `https://www.googleapis.com/auth/admin.directory.group.readonly` | Inspect groups and memberships | | Gmail metadata | `https://www.googleapis.com/auth/gmail.metadata` | Inspect message metadata without message bodies | | Calendar read | `https://www.googleapis.com/auth/calendar.readonly` | Inspect calendars and events | | Drive metadata | `https://www.googleapis.com/auth/drive.metadata.readonly` | Inspect file IDs, owners, MIME types, and permission metadata | ## Write Scopes Escalate to write scopes only after the user approves the exact change plan. | Surface | Scope | Typical write | | --- | --- | --- | | Users | `https://www.googleapis.com/auth/admin.directory.user` | Create, suspend, rename, or update users | | Groups | `https://www.googleapis.com/auth/admin.directory.group` | Create groups or update group settings | | Group members | `https://www.googleapis.com/auth/admin.directory.group.member` | Add or remove group members | | Gmail settings | `https://www.googleapis.com/auth/gmail.settings.basic` | Labels, filters, forwarding, POP/IMAP settings | | Calendar | `https://www.googleapis.com/auth/calendar` | Create, update, or delete events/calendars | | Drive | `https://www.googleapis.com/auth/drive` | Transfer ownership or change sharing | ## Domain-Wide Delegation Checklist 1. Confirm the service account email and client ID. 2. Confirm the exact OAuth scopes approved in Admin Console. 3. Confirm the subject user being impersonated. 4. Confirm the API endpoint and expected audit log. 5. Run read-only verification before writes.
skill-card.md
## Description: Plan, audit, and safely execute Google Workspace admin, Gmail, Calendar, Drive, Groups, and user lifecycle work. This skill is ready for commercial/non-commercial use. ## Publisher: [patrick-erichsen-2](https://clawhub.ai/user/patrick-erichsen-2) ### License/Terms of Use: MIT-0 ## Use Case: Developers, IT administrators, and Workspace operators use this skill to plan and review Google Workspace administration, migration, account lifecycle, permission audit, group, mailbox, calendar, Drive, and API command work before execution. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Generated commands or API calls could affect users, groups, mailboxes, calendars, Drive permissions, ownership, or sharing state. Mitigation: Require explicit human approval before write, deletion, ownership transfer, suspension, archive, or sharing-change operations. Risk: Overbroad OAuth scopes could grant more Workspace access than the task requires. Mitigation: Prefer read-only discovery scopes first and escalate to write scopes only after the exact change plan is approved. Risk: Bulk changes can be hard to reverse without current state evidence. Mitigation: Export affected users, groups, permissions, or settings and define a rollback path before applying writes. ## Reference(s): - [Google Workspace OAuth Scopes](references/scopes.md) - [ClawHub Skill Page](https://clawhub.ai/patrick-erichsen-2/skills/google-workspace) ## Skill Output: **Output Type(s):** [text, markdown, shell commands, configuration, guidance] **Output Format:** [Markdown with command examples, API call descriptions, change plans, and rollout checklists] **Output Parameters:** [1D] **Other Properties Related to Output:** [Uses placeholders for domains, users, groups, and file IDs until real values are supplied; generated write operations require explicit human approval.] ## Skill Version(s): 1.0.0 (source: ClawHub release evidence) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
agents/openai.yaml
interface: display_name: "Google Workspace" short_description: "Plan and verify safe Google Workspace admin and migration work." default_prompt: "Use $google-workspace to plan a Google Workspace admin change safely."
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/patrick-erichsen-2/skills/google-workspace",
"sourceUrl": "https://clawhub.ai/patrick-erichsen-2/skills/google-workspace",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T16:13:59.917Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-patrick-erichsen-2-google-workspace/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-patrick-erichsen-2-google-workspace/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T16:13:59.917Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.3K downloads",
"href": "https://clawhub.ai/patrick-erichsen-2/google-workspace",
"sourceUrl": "https://clawhub.ai/patrick-erichsen-2/google-workspace",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T16:13:59.917Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.0",
"href": "https://clawhub.ai/patrick-erichsen-2/google-workspace",
"sourceUrl": "https://clawhub.ai/patrick-erichsen-2/google-workspace",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-06-17T22:51:52.506Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-patrick-erichsen-2-google-workspace/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-patrick-erichsen-2-google-workspace/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.0",
"description": "Initial owner-scoped publish smoke",
"href": "https://clawhub.ai/patrick-erichsen-2/google-workspace",
"sourceUrl": "https://clawhub.ai/patrick-erichsen-2/google-workspace",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-06-17T22:51:52.506Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
