{"id":"15443249-6a58-4fd7-b0da-04f5c0f8d588","entityType":"agent","slug":"clawhub-hith3sh-google-admin-workspace","name":"Google Admin","canonicalUrl":"https://www.xpersona.co/agent/clawhub-hith3sh-google-admin-workspace","canonicalPath":"/agent/clawhub-hith3sh-google-admin-workspace","generatedAt":"2026-10-09T19:15:56.250Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T11:54:16.889Z","emptyReason":null},"description":"Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and in... Skill: Google Admin Owner: hith3sh Summary: Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and in... Tags: latest:1.0.5 Version history: v1.0.5 | 2026-06-09T07:08:56.007Z | user Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2.7K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s173vws87a7ss71xf9rq53k5gd8568kv:google-admin-workspace","sourceUrl":"https://clawhub.ai/hith3sh/google-admin-workspace","homepage":"https://clawhub.ai/hith3sh/skills/google-admin-workspace","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/hith3sh/google-admin-workspace","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/hith3sh/skills/google-admin-workspace","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":69,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and in..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T11:54:16.889Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T11:54:16.889Z","emptyReason":null},"stars":null,"forks":null,"downloads":2733,"packageName":null,"latestVersion":"1.0.5","tractionLabel":"2.7K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T11:54:16.889Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T11:54:16.889Z","lastCrawledAt":"2026-10-09T11:54:16.889Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T11:54:16.889Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.5","createdAt":"2026-06-09T07:08:56.007Z","changelog":"Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic source.","fileCount":3,"zipByteSize":5812},{"version":"1.0.4","createdAt":"2026-06-09T04:52:42.260Z","changelog":"- Removed the sample file skill-card.md. - No user-facing changes to skill usage, features, or documentation.","fileCount":3,"zipByteSize":5633},{"version":"1.0.1","createdAt":"2026-06-08T16:36:31.554Z","changelog":"- Added a Google Admin branding image to the documentation. - Removed the file skill-card.md. - No changes to functionality or features; documentation only.","fileCount":3,"zipByteSize":5666},{"version":"0.1.1","createdAt":"2026-06-07T13:29:41.879Z","changelog":"Full rewrite to new standard: added tool reference tables, 3-step GIF table, architecture diagram, code examples, error handling, and troubleshooting.","fileCount":3,"zipByteSize":5475},{"version":"0.1.0","createdAt":"2026-05-16T17:49:41.068Z","changelog":"- Initial release of google-admin-workspace skill. - Manage Google Workspace users, groups, domains, devices, and directory data from chat via ClawLink integration. - Utilizes hosted authentication and tool discovery—no need for manual Google Admin API configuration. - Includes setup guides for installing ClawLink and connecting Google Admin. - Enforces best practices for secure actions, live catalog checks, and confirmation before write operations.","fileCount":3,"zipByteSize":3519}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173vws87a7ss71xf9rq53k5gd8568kv:google-admin-workspace","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-google-admin-workspace/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-google-admin-workspace/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-google-admin-workspace/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-google-admin-workspace/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-google-admin-workspace/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-google-admin-workspace/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T19:15:56.249Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-google-admin-workspace/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-google-admin-workspace/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-google-admin-workspace/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-google-admin-workspace/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T11:54:16.889Z","emptyReason":null},"readme":"Skill: Google Admin\n\nOwner: hith3sh\n\nSummary: Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and in...\n\nTags: latest:1.0.5\n\nVersion history:\n\nv1.0.5 | 2026-06-09T07:08:56.007Z | user\n\nAdd UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic source.\n\nv1.0.4 | 2026-06-09T04:52:42.260Z | auto\n\n- Removed the sample file skill-card.md.\n- No user-facing changes to skill usage, features, or documentation.\n\nv1.0.1 | 2026-06-08T16:36:31.554Z | auto\n\n- Added a Google Admin branding image to the documentation.\n- Removed the file skill-card.md.\n- No changes to functionality or features; documentation only.\n\nv0.1.1 | 2026-06-07T13:29:41.879Z | user\n\nFull rewrite to new standard: added tool reference tables, 3-step GIF table, architecture diagram, code examples, error handling, and troubleshooting.\n\nv0.1.0 | 2026-05-16T17:49:41.068Z | auto\n\n- Initial release of google-admin-workspace skill.\n- Manage Google Workspace users, groups, domains, devices, and directory data from chat via ClawLink integration.\n- Utilizes hosted authentication and tool discovery—no need for manual Google Admin API configuration.\n- Includes setup guides for installing ClawLink and connecting Google Admin.\n- Enforces best practices for secure actions, live catalog checks, and confirmation before write operations.\n\nArchive index:\n\nArchive v1.0.5: 3 files, 5812 bytes\n\nFiles: skill-card.md (2772b), SKILL.md (13537b), _meta.json (141b)\n\nFile v1.0.5:SKILL.md\n\n---\nname: google-admin-workspace\ndescription: Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and inspect users, create or update user accounts, manage groups and memberships, review organization units and directory metadata, or manage devices and admin resources in Google Workspace.\n---\n\n# Google Admin\n\n![Google Admin](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/google-admin.png)\n\nAccess Google Workspace Admin SDK via the Google Admin API with OAuth authentication. Manage users, groups, domains, devices, and directory data.\n\nThis skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=google-admin-workspace) for hosted connection flows and credentials so you do not need to configure Google Admin API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect Google Admin |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n| Run the install command in OpenClaw | Sign in and approve the device | Open the dashboard and connect Google Admin |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│ Google Admin SDK │\n│   (User Chat)   │     │   (OAuth)    │     │   (REST)         │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin    │                       │\n         │  2. Pair Device       │                       │\n         │  3. Connect Google Admin                       │\n         │                       │  4. Secure Token      │\n         │                       │  5. Proxy Requests    │\n         │                       │                       │\n         ▼                       ▼                       ▼\n   ┌──────────┐           ┌──────────┐           ┌──────────┐\n   │  SKILL   │           │ Dashboard│           │ Google   │\n   │  File    │           │ Auth     │           │ Workspace│\n   └──────────┘           └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for Google Admin again.\"\n\n## Quick Start\n\n```bash\n# List all users in the domain\nclawlink_call_tool --tool \"google_admin_list_all_users\" --params '{}'\n\n# Get a specific user\nclawlink_call_tool --tool \"google_admin_get_a_user\" --params '{\"user_key\": \"user@example.com\"}'\n\n# List groups\nclawlink_call_tool --tool \"google_admin_list_all_groups\" --params '{}'\n```\n\n## Authentication\n\nAll Google Admin tool calls are authenticated automatically by ClawLink using the user's connected Google Workspace admin account.\n\n**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Google Admin API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=google-admin and connect Google Admin.\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `google-admin` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration google-admin\n```\n\n**Response:** Returns the live tool catalog for Google Admin.\n\n### Reconnect\n\nIf Google Admin tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=google-admin\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration google-admin`\n\n## Security & Permissions\n\n- Access is scoped to the Google Workspace domain and resources the connected admin account can manage.\n- **All write operations require explicit user confirmation.** Before executing any create, update, or delete call, confirm the target resource and intended effect with the user.\n- Destructive actions (deleting users, removing groups) are marked as high-impact and must be confirmed.\n- This skill requires Google Workspace admin privileges. Personal Gmail accounts do not have access to the Admin SDK.\n\n## Tool Reference\n\n### Users\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_users` | List all users in the domain | Read |\n| `google_admin_get_a_user` | Get user details by email or ID | Read |\n| `google_admin_create_user` | Create a new user account | Write |\n| `google_admin_update_user` | Update user fields (name, departments, etc.) | Write |\n| `google_admin_delete_user` | Delete a user account | Write |\n| `google_admin_add_user_alias` | Add an email alias to a user | Write |\n| `google_admin_turn_off_2_step_verification` | Disable 2SV for a user (admin only) | Write |\n\n### Groups\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_groups` | List all groups in the domain | Read |\n| `google_admin_get_group` | Get group details | Read |\n| `google_admin_create_group` | Create a new group | Write |\n| `google_admin_delete_group` | Delete a group | Write |\n| `google_admin_add_user_to_group` | Add a user to a group | Write |\n| `google_admin_remove_user_from_group` | Remove a user from a group | Write |\n\n### Organization Units\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_organization_units` | List all organization units | Read |\n| `google_admin_get_organization_unit` | Get OU details | Read |\n| `google_admin_move_users_and_printers_to_ou` | Move users or printers to an OU | Write |\n\n### Devices\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_devices` | List all devices in the domain | Read |\n| `google_admin_get_device` | Get device details | Read |\n| `google_admin_update_device` | Update device status or attributes | Write |\n\n### Domain Management\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_get_domain_info` | Get domain information | Read |\n| `google_admin_list_domains` | List all domains in the account | Read |\n\n## Code Examples\n\n### List all users\n\n```bash\nclawlink_call_tool --tool \"google_admin_list_all_users\" \\\n  --params '{\n    \"customer\": \"my_customer\",\n    \"max_results\": 100\n  }'\n```\n\n### Create a new user\n\n```bash\nclawlink_call_tool --tool \"google_admin_create_user\" \\\n  --params '{\n    \"primary_email\": \"newuser@example.com\",\n    \"name\": {\n      \"given_name\": \"New\",\n      \"family_name\": \"User\"\n    },\n    \"password\": \"secure-password-here\"\n  }'\n```\n\n### Add user to group\n\n```bash\nclawlink_call_tool --tool \"google_admin_add_user_to_group\" \\\n  --params '{\n    \"group_email\": \"engineering@example.com\",\n    \"user_email\": \"newuser@example.com\",\n    \"role\": \"MEMBER\"\n  }'\n```\n\n### List groups\n\n```bash\nclawlink_call_tool --tool \"google_admin_list_all_groups\" \\\n  --params '{}'\n```\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm Google Admin is connected.\n2. Call `clawlink_list_tools --integration google-admin` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `google-admin`.\n5. If no Google Admin tools appear, direct the user to https://claw-link.dev/dashboard?add=google-admin.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                      │\n│                                                             │\n│  Example: List users → Get user → Show details              │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                    │\n│  list → get → describe → preview → confirm → call           │\n│                                                             │\n│  Example: Describe tool → Preview user creation             │\n│           → User approves → Execute create                  │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Notes\n\n- This skill requires Google Workspace admin privileges. Personal Gmail accounts do not have Admin SDK access.\n- User and group email addresses must belong to the verified Google Workspace domain.\n- Some admin operations (like deleting users or moving OUs) may be restricted by admin policies.\n- The `customer` parameter for user queries can be `my_customer` or the specific customer ID.\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration google-admin`. |\n| Missing connection | Google Admin is not connected. Direct the user to https://claw-link.dev/dashboard?add=google-admin. |\n| `404 Not Found` | User, group, or resource does not exist in the domain. |\n| `403 Forbidden` | The connected account is not a Workspace admin or lacks permission for this operation. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Invalid Tool Call\n\n1. Ensure the integration slug is exactly `google-admin`.\n2. Use `clawlink_describe_tool` to verify parameter names and types before calling.\n3. For write operations, always call `clawlink_preview_tool` first.\n\n## Resources\n\n- [Google Admin SDK Documentation](https://developers.google.com/admin-sdk)\n- [Directory API Reference](https://developers.google.com/admin-sdk/directory/reference/rest)\n- [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=google-admin-workspace)\n- [ClawLink Docs](https://docs.claw-link.dev/openclaw)\n- [ClawLink Verification](https://claw-link.dev/verify)\n\n## Related Skills\n\n- [Google Calendar](https://clawhub.ai/hith3sh/google-calendar-scheduling) — For calendar management\n- [Gmail](https://clawhub.ai/hith3sh/gmail-email) — For email management\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=google-admin-workspace)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"google-admin-workspace\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1780988936007\n}\n\nFile v1.0.5:skill-card.md\n\n## Description:\n\nManage Google Workspace users, groups, domains, devices, and admin directory data through Google Admin SDK API workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[hith3sh](https://clawhub.ai/user/hith3sh)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nWorkspace administrators and IT operators use this skill to inspect and manage Google Workspace directory resources, including users, groups, organization units, domains, and devices. The skill supports read workflows and confirmed write workflows through a connected Google Workspace admin account.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: A third-party plugin and hosted service can use administrator OAuth access for high-impact Google Workspace directory changes.\n\nMitigation: Review before production installation, use a dedicated least-privilege admin account, verify the ClawLink plugin and service provenance, and confirm requested OAuth scopes during connection.\n\nRisk: Administrative write or destructive actions could affect users, groups, organization units, or devices.\n\nMitigation: Preview and explicitly confirm the target resource and intended effect before create, update, delete, group-membership, 2-step-verification, or organization-unit move operations.\n\nRisk: Compromised or overbroad access may be difficult to notice without monitoring.\n\nMitigation: Monitor Google Workspace audit logs after deployment and revoke the connected OAuth token if activity looks wrong.\n\nRisk: Sensitive credentials or passwords could be exposed through chat or command-line examples.\n\nMitigation: Avoid putting real passwords directly into chat or command-line examples; prefer secure account provisioning and rotation processes.\n\n## Reference(s):\n\n- [Google Admin SDK Documentation](https://developers.google.com/admin-sdk)\n- [Directory API Reference](https://developers.google.com/admin-sdk/directory/reference/rest)\n- [ClawLink Docs](https://docs.claw-link.dev/openclaw)\n- [ClawLink Verification](https://claw-link.dev/verify)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, API calls, guidance]\n\n**Output Format:** [Markdown with inline shell commands and JSON tool parameters]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes confirmation-oriented guidance for write and destructive Google Workspace admin operations.]\n\n## Skill Version(s):\n\n1.0.5 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.4: 3 files, 5633 bytes\n\nFiles: skill-card.md (2527b), SKILL.md (13312b), _meta.json (141b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: google-admin-workspace\ndescription: Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and inspect users, create or update user accounts, manage groups and memberships, review organization units and directory metadata, or manage devices and admin resources in Google Workspace.\n---\n\n# Google Admin\n\n![Google Admin](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/google-admin.png)\n\nAccess Google Workspace Admin SDK via the Google Admin API with OAuth authentication. Manage users, groups, domains, devices, and directory data.\n\nThis skill uses [ClawLink](https://claw-link.dev) for hosted connection flows and credentials so you do not need to configure Google Admin API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect Google Admin |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n| Run the install command in OpenClaw | Sign in and approve the device | Open the dashboard and connect Google Admin |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│ Google Admin SDK │\n│   (User Chat)   │     │   (OAuth)    │     │   (REST)         │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin    │                       │\n         │  2. Pair Device       │                       │\n         │  3. Connect Google Admin                       │\n         │                       │  4. Secure Token      │\n         │                       │  5. Proxy Requests    │\n         │                       │                       │\n         ▼                       ▼                       ▼\n   ┌──────────┐           ┌──────────┐           ┌──────────┐\n   │  SKILL   │           │ Dashboard│           │ Google   │\n   │  File    │           │ Auth     │           │ Workspace│\n   └──────────┘           └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for Google Admin again.\"\n\n## Quick Start\n\n```bash\n# List all users in the domain\nclawlink_call_tool --tool \"google_admin_list_all_users\" --params '{}'\n\n# Get a specific user\nclawlink_call_tool --tool \"google_admin_get_a_user\" --params '{\"user_key\": \"user@example.com\"}'\n\n# List groups\nclawlink_call_tool --tool \"google_admin_list_all_groups\" --params '{}'\n```\n\n## Authentication\n\nAll Google Admin tool calls are authenticated automatically by ClawLink using the user's connected Google Workspace admin account.\n\n**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Google Admin API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=google-admin and connect Google Admin.\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `google-admin` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration google-admin\n```\n\n**Response:** Returns the live tool catalog for Google Admin.\n\n### Reconnect\n\nIf Google Admin tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=google-admin\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration google-admin`\n\n## Security & Permissions\n\n- Access is scoped to the Google Workspace domain and resources the connected admin account can manage.\n- **All write operations require explicit user confirmation.** Before executing any create, update, or delete call, confirm the target resource and intended effect with the user.\n- Destructive actions (deleting users, removing groups) are marked as high-impact and must be confirmed.\n- This skill requires Google Workspace admin privileges. Personal Gmail accounts do not have access to the Admin SDK.\n\n## Tool Reference\n\n### Users\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_users` | List all users in the domain | Read |\n| `google_admin_get_a_user` | Get user details by email or ID | Read |\n| `google_admin_create_user` | Create a new user account | Write |\n| `google_admin_update_user` | Update user fields (name, departments, etc.) | Write |\n| `google_admin_delete_user` | Delete a user account | Write |\n| `google_admin_add_user_alias` | Add an email alias to a user | Write |\n| `google_admin_turn_off_2_step_verification` | Disable 2SV for a user (admin only) | Write |\n\n### Groups\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_groups` | List all groups in the domain | Read |\n| `google_admin_get_group` | Get group details | Read |\n| `google_admin_create_group` | Create a new group | Write |\n| `google_admin_delete_group` | Delete a group | Write |\n| `google_admin_add_user_to_group` | Add a user to a group | Write |\n| `google_admin_remove_user_from_group` | Remove a user from a group | Write |\n\n### Organization Units\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_organization_units` | List all organization units | Read |\n| `google_admin_get_organization_unit` | Get OU details | Read |\n| `google_admin_move_users_and_printers_to_ou` | Move users or printers to an OU | Write |\n\n### Devices\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_devices` | List all devices in the domain | Read |\n| `google_admin_get_device` | Get device details | Read |\n| `google_admin_update_device` | Update device status or attributes | Write |\n\n### Domain Management\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_get_domain_info` | Get domain information | Read |\n| `google_admin_list_domains` | List all domains in the account | Read |\n\n## Code Examples\n\n### List all users\n\n```bash\nclawlink_call_tool --tool \"google_admin_list_all_users\" \\\n  --params '{\n    \"customer\": \"my_customer\",\n    \"max_results\": 100\n  }'\n```\n\n### Create a new user\n\n```bash\nclawlink_call_tool --tool \"google_admin_create_user\" \\\n  --params '{\n    \"primary_email\": \"newuser@example.com\",\n    \"name\": {\n      \"given_name\": \"New\",\n      \"family_name\": \"User\"\n    },\n    \"password\": \"secure-password-here\"\n  }'\n```\n\n### Add user to group\n\n```bash\nclawlink_call_tool --tool \"google_admin_add_user_to_group\" \\\n  --params '{\n    \"group_email\": \"engineering@example.com\",\n    \"user_email\": \"newuser@example.com\",\n    \"role\": \"MEMBER\"\n  }'\n```\n\n### List groups\n\n```bash\nclawlink_call_tool --tool \"google_admin_list_all_groups\" \\\n  --params '{}'\n```\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm Google Admin is connected.\n2. Call `clawlink_list_tools --integration google-admin` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `google-admin`.\n5. If no Google Admin tools appear, direct the user to https://claw-link.dev/dashboard?add=google-admin.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                      │\n│                                                             │\n│  Example: List users → Get user → Show details              │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                    │\n│  list → get → describe → preview → confirm → call           │\n│                                                             │\n│  Example: Describe tool → Preview user creation             │\n│           → User approves → Execute create                  │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Notes\n\n- This skill requires Google Workspace admin privileges. Personal Gmail accounts do not have Admin SDK access.\n- User and group email addresses must belong to the verified Google Workspace domain.\n- Some admin operations (like deleting users or moving OUs) may be restricted by admin policies.\n- The `customer` parameter for user queries can be `my_customer` or the specific customer ID.\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration google-admin`. |\n| Missing connection | Google Admin is not connected. Direct the user to https://claw-link.dev/dashboard?add=google-admin. |\n| `404 Not Found` | User, group, or resource does not exist in the domain. |\n| `403 Forbidden` | The connected account is not a Workspace admin or lacks permission for this operation. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Invalid Tool Call\n\n1. Ensure the integration slug is exactly `google-admin`.\n2. Use `clawlink_describe_tool` to verify parameter names and types before calling.\n3. For write operations, always call `clawlink_preview_tool` first.\n\n## Resources\n\n- [Google Admin SDK Documentation](https://developers.google.com/admin-sdk)\n- [Directory API Reference](https://developers.google.com/admin-sdk/directory/reference/rest)\n- [ClawLink](https://claw-link.dev)\n- [ClawLink Docs](https://docs.claw-link.dev/openclaw)\n- [ClawLink Verification](https://claw-link.dev/verify)\n\n## Related Skills\n\n- [Google Calendar](https://clawhub.ai/hith3sh/google-calendar-scheduling) — For calendar management\n- [Gmail](https://clawhub.ai/hith3sh/gmail-email) — For email management\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"google-admin-workspace\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1780980762260\n}\n\nFile v1.0.4:skill-card.md\n\n## Description: <br>\nManage Google Workspace users, groups, domains, devices, and admin directory data through the Google Admin SDK API. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nWorkspace administrators and delegated operators use this skill to inspect and manage Google Workspace directory resources, including users, groups, organization units, domains, and devices. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill uses Google Workspace admin OAuth access and can affect sensitive directory resources. <br>\nMitigation: Install only when the publisher and ClawLink connection are trusted, and use an admin account whose permissions match the intended tasks. <br>\nRisk: Write operations can create, update, delete, move, or disable protections on Workspace resources. <br>\nMitigation: Review every write preview carefully and confirm the exact target resource and intended effect before execution. <br>\nRisk: The connected account may lack required Workspace admin privileges or be outside the managed domain. <br>\nMitigation: Verify the Google Admin connection and live tool catalog before use, and handle permission failures as access-control issues rather than missing capabilities. <br>\n\n\n## Reference(s): <br>\n- [Google Admin on ClawHub](https://clawhub.ai/hith3sh/google-admin-workspace) <br>\n- [Google Admin SDK Documentation](https://developers.google.com/admin-sdk) <br>\n- [Directory API Reference](https://developers.google.com/admin-sdk/directory/reference/rest) <br>\n- [ClawLink OpenClaw Docs](https://docs.claw-link.dev/openclaw) <br>\n- [ClawLink Verification](https://claw-link.dev/verify) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with shell commands and JSON tool-call parameters] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires a connected Google Workspace admin account through ClawLink.] <br>\n\n## Skill Version(s): <br>\n1.0.4 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.1: 3 files, 5666 bytes\n\nFiles: skill-card.md (2770b), SKILL.md (13312b), _meta.json (141b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: google-admin-workspace\ndescription: Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and inspect users, create or update user accounts, manage groups and memberships, review organization units and directory metadata, or manage devices and admin resources in Google Workspace.\n---\n\n# Google Admin\n\n![Google Admin](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/google-admin.png)\n\nAccess Google Workspace Admin SDK via the Google Admin API with OAuth authentication. Manage users, groups, domains, devices, and directory data.\n\nThis skill uses [ClawLink](https://claw-link.dev) for hosted connection flows and credentials so you do not need to configure Google Admin API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect Google Admin |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n| Run the install command in OpenClaw | Sign in and approve the device | Open the dashboard and connect Google Admin |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│ Google Admin SDK │\n│   (User Chat)   │     │   (OAuth)    │     │   (REST)         │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin    │                       │\n         │  2. Pair Device       │                       │\n         │  3. Connect Google Admin                       │\n         │                       │  4. Secure Token      │\n         │                       │  5. Proxy Requests    │\n         │                       │                       │\n         ▼                       ▼                       ▼\n   ┌──────────┐           ┌──────────┐           ┌──────────┐\n   │  SKILL   │           │ Dashboard│           │ Google   │\n   │  File    │           │ Auth     │           │ Workspace│\n   └──────────┘           └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for Google Admin again.\"\n\n## Quick Start\n\n```bash\n# List all users in the domain\nclawlink_call_tool --tool \"google_admin_list_all_users\" --params '{}'\n\n# Get a specific user\nclawlink_call_tool --tool \"google_admin_get_a_user\" --params '{\"user_key\": \"user@example.com\"}'\n\n# List groups\nclawlink_call_tool --tool \"google_admin_list_all_groups\" --params '{}'\n```\n\n## Authentication\n\nAll Google Admin tool calls are authenticated automatically by ClawLink using the user's connected Google Workspace admin account.\n\n**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Google Admin API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=google-admin and connect Google Admin.\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `google-admin` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration google-admin\n```\n\n**Response:** Returns the live tool catalog for Google Admin.\n\n### Reconnect\n\nIf Google Admin tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=google-admin\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration google-admin`\n\n## Security & Permissions\n\n- Access is scoped to the Google Workspace domain and resources the connected admin account can manage.\n- **All write operations require explicit user confirmation.** Before executing any create, update, or delete call, confirm the target resource and intended effect with the user.\n- Destructive actions (deleting users, removing groups) are marked as high-impact and must be confirmed.\n- This skill requires Google Workspace admin privileges. Personal Gmail accounts do not have access to the Admin SDK.\n\n## Tool Reference\n\n### Users\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_users` | List all users in the domain | Read |\n| `google_admin_get_a_user` | Get user details by email or ID | Read |\n| `google_admin_create_user` | Create a new user account | Write |\n| `google_admin_update_user` | Update user fields (name, departments, etc.) | Write |\n| `google_admin_delete_user` | Delete a user account | Write |\n| `google_admin_add_user_alias` | Add an email alias to a user | Write |\n| `google_admin_turn_off_2_step_verification` | Disable 2SV for a user (admin only) | Write |\n\n### Groups\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_groups` | List all groups in the domain | Read |\n| `google_admin_get_group` | Get group details | Read |\n| `google_admin_create_group` | Create a new group | Write |\n| `google_admin_delete_group` | Delete a group | Write |\n| `google_admin_add_user_to_group` | Add a user to a group | Write |\n| `google_admin_remove_user_from_group` | Remove a user from a group | Write |\n\n### Organization Units\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_organization_units` | List all organization units | Read |\n| `google_admin_get_organization_unit` | Get OU details | Read |\n| `google_admin_move_users_and_printers_to_ou` | Move users or printers to an OU | Write |\n\n### Devices\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_devices` | List all devices in the domain | Read |\n| `google_admin_get_device` | Get device details | Read |\n| `google_admin_update_device` | Update device status or attributes | Write |\n\n### Domain Management\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_get_domain_info` | Get domain information | Read |\n| `google_admin_list_domains` | List all domains in the account | Read |\n\n## Code Examples\n\n### List all users\n\n```bash\nclawlink_call_tool --tool \"google_admin_list_all_users\" \\\n  --params '{\n    \"customer\": \"my_customer\",\n    \"max_results\": 100\n  }'\n```\n\n### Create a new user\n\n```bash\nclawlink_call_tool --tool \"google_admin_create_user\" \\\n  --params '{\n    \"primary_email\": \"newuser@example.com\",\n    \"name\": {\n      \"given_name\": \"New\",\n      \"family_name\": \"User\"\n    },\n    \"password\": \"secure-password-here\"\n  }'\n```\n\n### Add user to group\n\n```bash\nclawlink_call_tool --tool \"google_admin_add_user_to_group\" \\\n  --params '{\n    \"group_email\": \"engineering@example.com\",\n    \"user_email\": \"newuser@example.com\",\n    \"role\": \"MEMBER\"\n  }'\n```\n\n### List groups\n\n```bash\nclawlink_call_tool --tool \"google_admin_list_all_groups\" \\\n  --params '{}'\n```\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm Google Admin is connected.\n2. Call `clawlink_list_tools --integration google-admin` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `google-admin`.\n5. If no Google Admin tools appear, direct the user to https://claw-link.dev/dashboard?add=google-admin.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                      │\n│                                                             │\n│  Example: List users → Get user → Show details              │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                    │\n│  list → get → describe → preview → confirm → call           │\n│                                                             │\n│  Example: Describe tool → Preview user creation             │\n│           → User approves → Execute create                  │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Notes\n\n- This skill requires Google Workspace admin privileges. Personal Gmail accounts do not have Admin SDK access.\n- User and group email addresses must belong to the verified Google Workspace domain.\n- Some admin operations (like deleting users or moving OUs) may be restricted by admin policies.\n- The `customer` parameter for user queries can be `my_customer` or the specific customer ID.\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration google-admin`. |\n| Missing connection | Google Admin is not connected. Direct the user to https://claw-link.dev/dashboard?add=google-admin. |\n| `404 Not Found` | User, group, or resource does not exist in the domain. |\n| `403 Forbidden` | The connected account is not a Workspace admin or lacks permission for this operation. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Invalid Tool Call\n\n1. Ensure the integration slug is exactly `google-admin`.\n2. Use `clawlink_describe_tool` to verify parameter names and types before calling.\n3. For write operations, always call `clawlink_preview_tool` first.\n\n## Resources\n\n- [Google Admin SDK Documentation](https://developers.google.com/admin-sdk)\n- [Directory API Reference](https://developers.google.com/admin-sdk/directory/reference/rest)\n- [ClawLink](https://claw-link.dev)\n- [ClawLink Docs](https://docs.claw-link.dev/openclaw)\n- [ClawLink Verification](https://claw-link.dev/verify)\n\n## Related Skills\n\n- [Google Calendar](https://clawhub.ai/hith3sh/google-calendar-scheduling) — For calendar management\n- [Gmail](https://clawhub.ai/hith3sh/gmail-email) — For email management\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"google-admin-workspace\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1780936591554\n}\n\nFile v1.0.1:skill-card.md\n\n## Description: <br>\nManage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nWorkspace administrators and developers use this skill to inspect and manage Google Workspace users, groups, domains, devices, organization units, and directory metadata through Google Admin SDK tooling. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can operate on sensitive Google Workspace directory resources through an admin account. <br>\nMitigation: Install only when a Google Workspace admin account should be connected through ClawLink, review OAuth permissions carefully, and scope use to resources the connected administrator is authorized to manage. <br>\nRisk: Write or destructive actions can create accounts, update users or devices, change memberships, move organization units, disable 2-step verification, or delete users and groups. <br>\nMitigation: Require previews and explicit user confirmation before executing create, update, delete, membership, organization unit, or 2-step verification changes. <br>\nRisk: Tool availability can vary by live ClawLink catalog and connected Google Workspace permissions. <br>\nMitigation: Verify the connection and live tool catalog before use, and report real tool errors instead of assuming unsupported capabilities. <br>\n\n\n## Reference(s): <br>\n- [Google Admin skill on ClawHub](https://clawhub.ai/hith3sh/google-admin-workspace) <br>\n- [Publisher profile](https://clawhub.ai/user/hith3sh) <br>\n- [Google Admin SDK documentation](https://developers.google.com/admin-sdk) <br>\n- [Google Admin SDK Directory API reference](https://developers.google.com/admin-sdk/directory/reference/rest) <br>\n- [ClawLink documentation](https://docs.claw-link.dev/openclaw) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, shell commands, configuration, API calls] <br>\n**Output Format:** [Markdown with inline shell commands and JSON tool parameters] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires ClawLink OAuth connection to a Google Workspace admin account; write and destructive actions require explicit confirmation.] <br>\n\n## Skill Version(s): <br>\n1.0.1 (source: server-resolved release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.1.1: 3 files, 5475 bytes\n\nFiles: skill-card.md (2259b), SKILL.md (13191b), _meta.json (141b)\n\nFile v0.1.1:SKILL.md\n\n---\nname: google-admin-workspace\ndescription: Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and inspect users, create or update user accounts, manage groups and memberships, review organization units and directory metadata, or manage devices and admin resources in Google Workspace.\n---\n\n# Google Admin\n\nAccess Google Workspace Admin SDK via the Google Admin API with OAuth authentication. Manage users, groups, domains, devices, and directory data.\n\nThis skill uses [ClawLink](https://claw-link.dev) for hosted connection flows and credentials so you do not need to configure Google Admin API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect Google Admin |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n| Run the install command in OpenClaw | Sign in and approve the device | Open the dashboard and connect Google Admin |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│ Google Admin SDK │\n│   (User Chat)   │     │   (OAuth)    │     │   (REST)         │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin    │                       │\n         │  2. Pair Device       │                       │\n         │  3. Connect Google Admin                       │\n         │                       │  4. Secure Token      │\n         │                       │  5. Proxy Requests    │\n         │                       │                       │\n         ▼                       ▼                       ▼\n   ┌──────────┐           ┌──────────┐           ┌──────────┐\n   │  SKILL   │           │ Dashboard│           │ Google   │\n   │  File    │           │ Auth     │           │ Workspace│\n   └──────────┘           └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for Google Admin again.\"\n\n## Quick Start\n\n```bash\n# List all users in the domain\nclawlink_call_tool --tool \"google_admin_list_all_users\" --params '{}'\n\n# Get a specific user\nclawlink_call_tool --tool \"google_admin_get_a_user\" --params '{\"user_key\": \"user@example.com\"}'\n\n# List groups\nclawlink_call_tool --tool \"google_admin_list_all_groups\" --params '{}'\n```\n\n## Authentication\n\nAll Google Admin tool calls are authenticated automatically by ClawLink using the user's connected Google Workspace admin account.\n\n**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Google Admin API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=google-admin and connect Google Admin.\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `google-admin` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration google-admin\n```\n\n**Response:** Returns the live tool catalog for Google Admin.\n\n### Reconnect\n\nIf Google Admin tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=google-admin\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration google-admin`\n\n## Security & Permissions\n\n- Access is scoped to the Google Workspace domain and resources the connected admin account can manage.\n- **All write operations require explicit user confirmation.** Before executing any create, update, or delete call, confirm the target resource and intended effect with the user.\n- Destructive actions (deleting users, removing groups) are marked as high-impact and must be confirmed.\n- This skill requires Google Workspace admin privileges. Personal Gmail accounts do not have access to the Admin SDK.\n\n## Tool Reference\n\n### Users\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_users` | List all users in the domain | Read |\n| `google_admin_get_a_user` | Get user details by email or ID | Read |\n| `google_admin_create_user` | Create a new user account | Write |\n| `google_admin_update_user` | Update user fields (name, departments, etc.) | Write |\n| `google_admin_delete_user` | Delete a user account | Write |\n| `google_admin_add_user_alias` | Add an email alias to a user | Write |\n| `google_admin_turn_off_2_step_verification` | Disable 2SV for a user (admin only) | Write |\n\n### Groups\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_groups` | List all groups in the domain | Read |\n| `google_admin_get_group` | Get group details | Read |\n| `google_admin_create_group` | Create a new group | Write |\n| `google_admin_delete_group` | Delete a group | Write |\n| `google_admin_add_user_to_group` | Add a user to a group | Write |\n| `google_admin_remove_user_from_group` | Remove a user from a group | Write |\n\n### Organization Units\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_organization_units` | List all organization units | Read |\n| `google_admin_get_organization_unit` | Get OU details | Read |\n| `google_admin_move_users_and_printers_to_ou` | Move users or printers to an OU | Write |\n\n### Devices\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_list_all_devices` | List all devices in the domain | Read |\n| `google_admin_get_device` | Get device details | Read |\n| `google_admin_update_device` | Update device status or attributes | Write |\n\n### Domain Management\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `google_admin_get_domain_info` | Get domain information | Read |\n| `google_admin_list_domains` | List all domains in the account | Read |\n\n## Code Examples\n\n### List all users\n\n```bash\nclawlink_call_tool --tool \"google_admin_list_all_users\" \\\n  --params '{\n    \"customer\": \"my_customer\",\n    \"max_results\": 100\n  }'\n```\n\n### Create a new user\n\n```bash\nclawlink_call_tool --tool \"google_admin_create_user\" \\\n  --params '{\n    \"primary_email\": \"newuser@example.com\",\n    \"name\": {\n      \"given_name\": \"New\",\n      \"family_name\": \"User\"\n    },\n    \"password\": \"secure-password-here\"\n  }'\n```\n\n### Add user to group\n\n```bash\nclawlink_call_tool --tool \"google_admin_add_user_to_group\" \\\n  --params '{\n    \"group_email\": \"engineering@example.com\",\n    \"user_email\": \"newuser@example.com\",\n    \"role\": \"MEMBER\"\n  }'\n```\n\n### List groups\n\n```bash\nclawlink_call_tool --tool \"google_admin_list_all_groups\" \\\n  --params '{}'\n```\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm Google Admin is connected.\n2. Call `clawlink_list_tools --integration google-admin` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `google-admin`.\n5. If no Google Admin tools appear, direct the user to https://claw-link.dev/dashboard?add=google-admin.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                      │\n│                                                             │\n│  Example: List users → Get user → Show details              │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                    │\n│  list → get → describe → preview → confirm → call           │\n│                                                             │\n│  Example: Describe tool → Preview user creation             │\n│           → User approves → Execute create                  │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Notes\n\n- This skill requires Google Workspace admin privileges. Personal Gmail accounts do not have Admin SDK access.\n- User and group email addresses must belong to the verified Google Workspace domain.\n- Some admin operations (like deleting users or moving OUs) may be restricted by admin policies.\n- The `customer` parameter for user queries can be `my_customer` or the specific customer ID.\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration google-admin`. |\n| Missing connection | Google Admin is not connected. Direct the user to https://claw-link.dev/dashboard?add=google-admin. |\n| `404 Not Found` | User, group, or resource does not exist in the domain. |\n| `403 Forbidden` | The connected account is not a Workspace admin or lacks permission for this operation. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Invalid Tool Call\n\n1. Ensure the integration slug is exactly `google-admin`.\n2. Use `clawlink_describe_tool` to verify parameter names and types before calling.\n3. For write operations, always call `clawlink_preview_tool` first.\n\n## Resources\n\n- [Google Admin SDK Documentation](https://developers.google.com/admin-sdk)\n- [Directory API Reference](https://developers.google.com/admin-sdk/directory/reference/rest)\n- [ClawLink](https://claw-link.dev)\n- [ClawLink Docs](https://docs.claw-link.dev/openclaw)\n- [ClawLink Verification](https://claw-link.dev/verify)\n\n## Related Skills\n\n- [Google Calendar](https://clawhub.ai/hith3sh/google-calendar-scheduling) — For calendar management\n- [Gmail](https://clawhub.ai/hith3sh/gmail-email) — For email management\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v0.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"google-admin-workspace\",\n  \"version\": \"0.1.1\",\n  \"publishedAt\": 1780838981879\n}\n\nFile v0.1.1:skill-card.md\n\n## Description: <br>\nManage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nWorkspace administrators and agents assisting them use this skill to inspect and manage users, groups, domains, organization units, devices, and directory metadata through ClawLink and the Google Admin SDK. It supports read operations and confirmed write actions for account, group, device, 2-step verification, and deletion changes. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can perform high-impact Google Workspace administration actions after confirmation, including account, group, device, 2-step verification, and deletion changes. <br>\nMitigation: Review Google OAuth consent carefully, use a least-privileged admin account where possible, and confirm write previews before allowing changes. <br>\n\n\n## Reference(s): <br>\n- [Google Admin SDK Documentation](https://developers.google.com/admin-sdk) <br>\n- [Directory API Reference](https://developers.google.com/admin-sdk/directory/reference/rest) <br>\n- [ClawLink](https://claw-link.dev) <br>\n- [ClawLink Docs](https://docs.claw-link.dev/openclaw) <br>\n- [ClawHub Skill Page](https://clawhub.ai/hith3sh/google-admin-workspace) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with shell command examples and JSON tool parameters] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires an OAuth-connected Google Workspace admin account through ClawLink; write and destructive operations require explicit confirmation.] <br>\n\n## Skill Version(s): <br>\n0.1.1 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.1.0: 3 files, 3519 bytes\n\nFiles: skill-card.md (2490b), SKILL.md (5076b), _meta.json (141b)\n\nFile v0.1.0:SKILL.md\n\n---\nname: google-admin-workspace\ndescription: Manage Google Workspace users, groups, domains, devices, and admin directory data - powered by ClawLink.\n---\n\n# Google Admin\n\nWork with Google Admin from chat - manage Workspace users, groups, domains, devices, and directory data.\n\nPowered by [ClawLink](https://claw-link.dev), an integration hub for OpenClaw that handles hosted connection flows and credentials so you don't need to configure Google Admin API access yourself.\n\n## Quick start\n\n1. Install the verified ClawLink plugin: `openclaw plugins install clawhub:clawlink-plugin`\n2. Start a fresh OpenClaw chat if the plugin was just installed and ClawLink tools are not visible yet\n3. If ClawLink is not configured, call `clawlink_begin_pairing`\n4. Tell the user to open the returned pairing URL, sign in to ClawLink if needed, and approve the device\n5. After the user confirms approval, call `clawlink_get_pairing_status`\n6. Tell the user to connect Google Admin at [claw-link.dev/dashboard?add=google-admin](https://claw-link.dev/dashboard?add=google-admin)\n7. When the user confirms Google Admin is connected, call `clawlink_list_integrations` and then `clawlink_list_tools` with the `google-admin` integration slug\n\n## Setup details\n\n### Installing the plugin\n\nIf the ClawLink plugin is not installed yet, tell the user to run:\n\n```\nopenclaw plugins install clawhub:clawlink-plugin\n```\n\nIf the current chat started before the plugin was installed and ClawLink tools are still unavailable, tell the user to start a fresh chat so OpenClaw reloads the plugin tool catalog.\n\n### Pairing ClawLink\n\nIf ClawLink reports that the plugin is not configured, the plugin has not been paired with the user's ClawLink account yet.\n\n1. Call `clawlink_begin_pairing`.\n2. Tell the user to open the returned pairing URL in their browser.\n3. The user signs in to ClawLink if needed and approves the OpenClaw device.\n4. After the user confirms approval, call `clawlink_get_pairing_status` to finish local setup.\n\nThe resulting device credential is stored locally in OpenClaw's plugin config and is only sent to `claw-link.dev`. The user should not paste raw credentials into chat.\n\n### Connecting Google Admin\n\nTell the user to open https://claw-link.dev/dashboard?add=google-admin and connect Google Admin there. The page opens the add-connection panel filtered to Google Admin. ClawLink's hosted page runs the provider connection flow. When they confirm it is done, call `clawlink_list_integrations` to verify, then call `clawlink_list_tools` with integration `google-admin`.\n\n## Using Google Admin tools\n\nClawLink provides tools dynamically based on what the user has connected. You do not need to know tool names or schemas in advance.\n\n### Discovery\n\n1. Call `clawlink_list_integrations` to confirm Google Admin is connected.\n2. Call `clawlink_list_tools` with integration `google-admin`.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `google-admin`.\n5. If no Google Admin tools appear, direct the user to https://claw-link.dev/dashboard?add=google-admin.\n\n### Execution\n\n1. Call `clawlink_describe_tool` before using an unfamiliar tool, before any write, or when the request is ambiguous.\n2. Use the returned schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups`.\n3. Prefer read, list, search, and get operations before writes.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first, then confirm with the user.\n5. Execute with `clawlink_call_tool`.\n6. If it fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## What you can do\n\nTypical Google Admin tasks (actual availability depends on the user's connected account, permissions, scopes, and current ClawLink tool catalog):\n\n- List and inspect users, groups, and domains\n- Review organization units and directory metadata\n- Create or update users and groups after confirmation\n- Manage devices and admin resources when available\n- Check Workspace account state before admin actions\n\n## Rules\n\n- Always use ClawLink tools for Google Admin. Do not ask the user for separate Google Admin credentials.\n- Do not claim a capability is missing without checking the live ClawLink catalog in the current turn.\n- Do not invent slash commands or ask the user to paste raw credentials.\n- Ask for confirmation before destructive, external-facing, or bulk write actions.\n- If Google Admin is not connected, direct the user to https://claw-link.dev/dashboard?add=google-admin.\n- Never echo or repeat the user's ClawLink credential.\n\n## Resources\n\n- ClawLink: https://claw-link.dev\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n- ClawLink Source: https://github.com/hith3sh/clawlink\n- Google Admin API: https://developers.google.com/admin-sdk\n\nFile v0.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"google-admin-workspace\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1778953781068\n}\n\nFile v0.1.0:skill-card.md\n\n## Description: <br>\nManage Google Workspace users, groups, domains, devices, and admin directory data - powered by ClawLink. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nWorkspace administrators and support teams use this skill to manage Google Workspace directory resources from chat through ClawLink. It supports setup, tool discovery, reads, and confirmed administrative changes for users, groups, domains, devices, and related directory data. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The release security summary notes that artifact contents were not available for full manual verification. <br>\nMitigation: Review the bundled skill file, requested external-service connections, and any commands before enabling the skill. <br>\nRisk: The skill can guide external-facing or administrative Google Workspace changes through connected tools. <br>\nMitigation: Use live tool schema discovery, preview write operations where available, and require user confirmation before destructive, bulk, or external-facing changes. <br>\nRisk: The skill relies on ClawLink-hosted authentication and dynamic tool catalogs. <br>\nMitigation: Verify the Google Admin connection in ClawLink and treat the current ClawLink tool catalog as the source of truth before claiming or using capabilities. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/hith3sh/google-admin-workspace) <br>\n- [ClawLink](https://claw-link.dev) <br>\n- [ClawLink OpenClaw Docs](https://docs.claw-link.dev/openclaw) <br>\n- [Google Admin SDK](https://developers.google.com/admin-sdk) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, shell commands, configuration, text] <br>\n**Output Format:** [Markdown with inline shell commands and tool-calling guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May direct the agent to discover live ClawLink tool schemas and request confirmation before write operations.] <br>\n\n## Skill Version(s): <br>\n0.1.0 (source: release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: Google Admin Owner: hith3sh Summary: Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and in... Tags: latest:1.0.5 Version history: v1.0.5 | 2026-06-09T07:08:56.007Z | user Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic ","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│ Google Admin SDK │\n│   (User Chat)   │     │   (OAuth)    │     │   (REST)         │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin    │                       │\n         │  2. Pair Device       │                       │\n         │  3. Connect Google Admin                       │\n         │                       │  4. Secure Token      │\n         │                       │  5. Proxy Requests    │\n         │                       │                       │\n         ▼                       ▼                       ▼\n   ┌──────────┐           ┌──────────┐           ┌──────────┐\n   │  SKILL   │           │ Dashboard│           │ Google   │\n   │  File    │           │ Auth     │           │ Workspace│\n   └──────────┘           └──────────┘           └──────────┘"},{"language":"bash","snippet":"openclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart"},{"language":"bash","snippet":"# List all users in the domain\nclawlink_call_tool --tool \"google_admin_list_all_users\" --params '{}'\n\n# Get a specific user\nclawlink_call_tool --tool \"google_admin_get_a_user\" --params '{\"user_key\": \"user@example.com\"}'\n\n# List groups\nclawlink_call_tool --tool \"google_admin_list_all_groups\" --params '{}'"},{"language":"bash","snippet":"clawlink_list_integrations"},{"language":"bash","snippet":"clawlink_list_tools --integration google-admin"},{"language":"bash","snippet":"clawlink_call_tool --tool \"google_admin_list_all_users\" \\\n  --params '{\n    \"customer\": \"my_customer\",\n    \"max_results\": 100\n  }'"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: google-admin-workspace\ndescription: Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and inspect users, create or update user accounts, manage groups and memberships, review organization units and directory metadata, or manage devices and admin resources in Google Workspace.\n---\n\n# Google Admin\n\n![Google Admin](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/google-admin.png)\n\nAccess Google Workspace Admin SDK via the Google Admin API with OAuth authentication. Manage users, groups, domains, devices, and directory data.\n\nThis skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=google-admin-workspace) for hosted connection flows and credentials so you do not need to configure Google Admin API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect Google Admin |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n| Run the install command in OpenClaw | Sign in and approve the device | Open the dashboard and connect Google Admin |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│ Google Admin SDK │\n│   (User Chat)   │     │   (OAuth)    │     │   (REST)         │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin    │                       │\n         │  2. Pair Device       │                       │\n         │  3. Connect Google Admin                       │\n         │                       │  4. Secure Token      │\n         │                       │  5. Proxy Requests    │\n         │                       │                       │\n         ▼                       ▼                       ▼\n   ┌──────────┐           ┌──────────┐           ┌──────────┐\n   │  SKILL   │           │ Dashboard│           │ Google   │\n   │  File    │           │ Auth     │           │ Workspace│\n   └──────────┘           └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for Google Admin again.\"\n\n## Quick Start\n\n```bash\n# List all users in the domain\nclawlink_call_tool --tool \"google_admin_list_al"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"google-admin-workspace\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1780988936007\n}"},{"path":"skill-card.md","content":"## Description:\n\nManage Google Workspace users, groups, domains, devices, and admin directory data through Google Admin SDK API workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[hith3sh](https://clawhub.ai/user/hith3sh)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nWorkspace administrators and IT operators use this skill to inspect and manage Google Workspace directory resources, including users, groups, organization units, domains, and devices. The skill supports read workflows and confirmed write workflows through a connected Google Workspace admin account.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: A third-party plugin and hosted service can use administrator OAuth access for high-impact Google Workspace directory changes.\n\nMitigation: Review before production installation, use a dedicated least-privilege admin account, verify the ClawLink plugin and service provenance, and confirm requested OAuth scopes during connection.\n\nRisk: Administrative write or destructive actions could affect users, groups, organization units, or devices.\n\nMitigation: Preview and explicitly confirm the target resource and intended effect before create, update, delete, group-membership, 2-step-verification, or organization-unit move operations.\n\nRisk: Compromised or overbroad access may be difficult to notice without monitoring.\n\nMitigation: Monitor Google Workspace audit logs after deployment and revoke the connected OAuth token if activity looks wrong.\n\nRisk: Sensitive credentials or passwords could be exposed through chat or command-line examples.\n\nMitigation: Avoid putting real passwords directly into chat or command-line examples; prefer secure account provisioning and rotation processes.\n\n## Reference(s):\n\n- [Google Admin SDK Documentation](https://developers.google.com/admin-sdk)\n- [Directory API Reference](https://developers.google.com/admin-sdk/directory/reference/rest)\n- [ClawLink Docs](https://docs.claw-link.dev/openclaw)\n- [ClawLink Verification](https://claw-link.dev/verify)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, API calls, guidance]\n\n**Output Format:** [Markdown with inline shell commands and JSON tool parameters]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes confirmation-oriented guidance for write and destructive Google Workspace admin operations.]\n\n## Skill Version(s):\n\n1.0.5 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and in... Skill: Google Admin Owner: hith3sh Summary: Manage Google Workspace users, groups, domains, devices, and admin directory data via the Google Admin SDK API. Use this skill when users want to list and in... Tags: latest:1.0.5 Version history: v1.0.5 | 2026-06-09T07:08:56.007Z | user Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1081,"uniquenessScore":49,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T11:54:16.889Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T11:54:16.889Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T19:15:56.250Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}