Agent skill

Auth Preflight

by ai-analyst-lab in ai-analyst-lab/ai-analyst

Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive).

MITAuto-check passedDocuments & Office

Install Auth Preflight

skills CLI
$ npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ai-analyst-lab/ai-analyst auth-preflight --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/auth-preflight .claude/skills/auth-preflight && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auth-preflight
GitHub stars
304
Token cost
~3.1k tokens
SKILL.md length
1,177 words
Files
1
Skills in repo
43
Repo updated
First seen
Licence
MIT

At a glance

Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive).

  • Works in 6 steps: Detect MCP Configuration → Check Stored Credentials → Test with Lightweight API Call → …
  • Users mention Google Doc
  • SKILL.md covers Purpose, When to Apply, Preflight Workflow and Known Issues & Solutions, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Auth Preflight is an agent skill from ai-analyst-lab/ai-analyst. Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive). This skill prevents auth failures mid-workflow by testing credentials upfront. Use this skill automatically at session start when the task involves Google Docs, Google Slides, Drive uploads, or any MCP Google Workspace tool. Also trigger when users mention "Google Doc", "Google Slides", "upload to Drive", "export to Google", "share on Drive", or any Google-related output format. Apply before…

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Cloud office suites. It works with Model Context Protocol, Google Docs, Google Slides and Google Workspace. The repository describes itself as: AI Product Analyst — Claude Code-powered data analysis toolkit. The licence is MIT.

When your agent uses it

  • Users mention Google Doc
  • Upload to Drive
  • Export to Google
  • Any Google-related output format

Example prompts

  • “Google Doc”
  • “Google Slides”
  • “upload to Drive”
  • “/auth-preflight”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Detect MCP Configuration
  2. Check Stored Credentials
  3. Test with Lightweight API Call
  4. Re-authenticate
  5. Verify After Re-auth
  6. Cleanup Test Resources (Optional)

What it can do on your machine

Read from SKILL.md and the folder at commit 52c0744. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auth Preflight loads about 3.1k tokens when it runs. Until then it costs about 243 tokens; SKILL.md has 1,177 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~243
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ai-analyst-lab/ai-analyst at commit 52c0744, republished under its MIT licence (© ai-analyst-lab). 1,177 words, ~3,099 tokens.

Download SKILL.mdSave it as .claude/skills/auth-preflight/SKILL.md (or your agent's skills folder).
name
auth-preflight
description
Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive). This skill prevents auth failures mid-workflow by testing credentials upfront. Use this skill automatically at session start when the task involves Google Docs, Google Slides, Drive uploads, or any MCP Google Workspace tool. Also trigger when users mention "Google Doc", "Google Slides", "upload to Drive", "export to Google", "share on Drive", or any Google-related output format. Apply before running any Google Workspace agents (google-slides-creator, google-slides-reviewer) or calling any mcp__google-* tool. This skill detects the actual MCP configuration, checks stored credentials in all known locations, tests tokens with a lightweight API call using create operations instead of reads, handles re-authentication if needed, and reports auth status clearly so downstream work can proceed safely or fail fast with actionable guidance.

Skill: Auth Preflight

Purpose

Verify Google Workspace MCP authentication BEFORE beginning any Google-dependent work. Catches auth issues in <30 seconds instead of discovering them after 5-10 minutes of chart generation, narrative writing, or deck building.

Core principle: Fail fast with clear guidance, not slow with cryptic errors mid-workflow.

When to Apply

Trigger this skill immediately when:

  • The task involves Google Docs, Slides, or Drive
  • Any mcp__google-* tool will be called
  • The user mentions "Google Doc", "Google Slides", "upload to Drive", "create a deck", "export to Google", "share on Drive"
  • Before running google-slides-creator, google-slides-reviewer, gdoc-builder, or any Google-dependent agent

Critical timing: Run auth preflight as your FIRST action, before exploring data, generating charts, parsing narratives, or any other substantive work.


Preflight Workflow

Step 1: Detect MCP Configuration

Read .mcp.json to discover which Google MCP server(s) are configured:

bash
cat .mcp.json | grep -A3 google

Look for entries like:

  • google-docs → Google Docs + Drive MCP server (most common)
  • google-workspace → Full workspace MCP (Docs, Slides, Drive)
  • google-slides → Slides-specific MCP server

Extract:

  • Server name (JSON key, e.g., "google-docs")
  • Command path (where the executable lives)
  • Args (to identify server type)

Why this matters: Different MCP implementations store credentials in different locations. Detecting configuration first ensures you check the right paths.

If no Google MCP found: Report:

Auth: FAILED — No Google MCP server configured in .mcp.json
To use Google Docs/Slides, add a Google MCP server to .mcp.json
Step 2: Check Stored Credentials

Based on MCP type from Step 1, check credentials in ALL possible locations (some setups use non-standard paths):

Priority 1: MCP-specific locations
bash
# For google-docs MCP
ls ~/.claude/mcp-servers/google-docs-mcp-server/

# For google-workspace MCP
ls ~/.google_workspace_mcp/credentials/

# For google-slides MCP
ls ~/.claude/mcp-servers/google-slides-mcp-server/
Priority 2: Alternative locations (check if Priority 1 empty)
bash
# Some custom MCP installs use these
ls ~/.config/google-docs-mcp-server/
ls ~/.google_mcp/credentials/

Look for:

  • token.json (current access/refresh token)
  • credentials.json (OAuth client credentials)
  • For workspace-mcp: {email}.json files

If no credentials found anywhere:

  • Auth has never been completed
  • Skip to Step 4 (Re-authenticate)

If credentials found:

  • For workspace-mcp: Extract email from filename (e.g., user@gmail.com.json → use exactly user@gmail.com in all API calls)
  • For other servers: Note the token.json location for diagnostics
  • Check token expiry if readable: cat {token_path} | grep expiry
  • Proceed to Step 3
Step 3: Test with Lightweight API Call

Make a simple API call to verify the token works. Always use CREATE operations, not READ operations to avoid permission errors on specific documents.

Best practice: Use create operations

Why create, not read? Reading a specific document can fail with 403 "Permission denied" even when auth is valid (if that doc isn't shared with the user). Creating a new document only requires valid auth, not document-specific permissions.

Test calls by MCP type:

If google-docs MCP:

mcp__google-docs__create_document(title="Auth Preflight Test - Delete Me")
  • Success → Extract document_id, report "Auth: OK (google-docs)", optionally clean up test doc
  • Auth error (401/403) → Proceed to Step 4
  • Tool not found → Report ".mcp.json has google-docs but tools not available - restart Claude Code"

If google-workspace MCP:

mcp__google-workspace__create_doc(
    user_google_email="{email_from_credentials_filename}",
    title="Auth Preflight Test"
)

Critical: Use the EXACT email string from the credential filename. Gmail treats dots as equivalent (a.b@gmail.com = ab@gmail.com) but MCP stores tokens by exact string match.

If google-slides MCP:

mcp__google-slides__create_presentation(title="Auth Preflight Test")

Interpreting results:

ResultMeaningAction
Success (doc/presentation created)Auth is validReport "Auth: OK", clean up test resource, proceed
401 UnauthorizedToken expired/invalidProceed to Step 4 (re-auth)
403 Forbidden (when creating)Quota exceeded or API disabledReport API configuration issue
"Tool not found"MCP not loadedRecommend restarting Claude Code
"Address already in use"OAuth server already runningTry actual API call (ignore this error)

If successful:

Auth: OK ({server_type})
Token verified via create_document at {timestamp}
Ready to proceed with Google API operations

If auth error: Proceed to Step 4.

Step 4: Re-authenticate

If credentials missing or token invalid, guide user through re-authentication.

Invoke appropriate auth tool:

For google-docs MCP:

mcp__google-docs__authorize_google_docs()

For google-workspace MCP:

mcp__google-workspace__authorize()

For google-slides MCP:

mcp__google-slides__authorize()
Present these instructions:

When authorization URL appears:

  1. Copy-paste the URL into your browser

    • Do NOT cmd-click or ctrl-click the URL in the terminal
    • Terminal click handlers can append garbage characters that break the URL
    • Manually select, copy (Cmd+C), and paste into browser
  2. Select your Google account when prompted

  3. If you see "Access blocked: This app isn't verified":

    • Go to console.cloud.google.com → APIs & Services → OAuth consent screen
    • Scroll to "Test users" section → Click "Add Users"
    • Add your email address
    • Return to the auth URL and try again
    • The app will now recognize you as an authorized test user
  4. If authorization fails with "Address already in use":

    • This means the MCP server is already running (normal state)
    • The issue is that no auth URL is being displayed
    • Solution: Restart Claude Code completely
    • The MCP server will restart and display the auth URL on startup
  5. After you see "Authentication successful" in browser, tell me "done" and I'll verify

Show full SKILL.md (463 more words)Show less
Step 5: Verify After Re-auth

After user confirms auth completed, repeat Step 3 (create test document/presentation).

If successful:

Auth: OK ({server_type})
Re-authentication successful
Proceeding with {original_task}

If still failing: Check diagnostics:

bash
# Verify new credentials appeared
ls ~/.claude/mcp-servers/google-docs-mcp-server/

# Check if token was actually written
ls -lh ~/.claude/mcp-servers/google-docs-mcp-server/token.json

# If token is 0 bytes or very old (unchanged timestamp), auth didn't complete

If credentials still missing/invalid:

Auth: FAILED — Re-authentication did not create valid credentials

Diagnostic findings:
- Credential location: {path_checked}
- Token file: {exists/missing}
- Token size: {bytes} (should be >200 bytes)
- Last modified: {timestamp}

Recommended action:
1. Restart Claude Code (closes all MCP servers cleanly)
2. Check for auth URL in Claude Code startup logs
3. Complete OAuth flow in browser
4. Verify you added your email as a test user in Google Cloud Console
5. If still failing, check Google Cloud Console → APIs & Services → Enabled APIs
   - Required: Google Docs API, Google Drive API (and Google Slides API if needed)
Step 6: Cleanup Test Resources (Optional)

If you created a test document/presentation in Step 3 and it's still accessible, optionally clean it up:

# For test documents
mcp__google-docs__delete_document(document_id="{test_doc_id}")
# (if delete tool exists)

# Or just leave it - user can delete manually from Drive

This is non-critical; the test resource causes no harm.


Known Issues & Solutions

IssueSymptomRoot CauseFix
Email mismatch (workspace-mcp)Auth succeeds but all API calls fail with "Invalid grant"Email parameter doesn't match credential filename exactlyExtract email from credential filename, use exact string (including/excluding dots)
Token expired"Authentication needed" on every callToken hasn't been refreshed, or refresh token invalidRe-auth via Step 4
App not verified"Access blocked" screen after selecting Google accountUser not added as test user for OAuth appAdd user's email in Google Cloud Console → OAuth consent screen → Test users
URL corruptionAuth URL gives 400 errorTerminal cmd-click appended control charactersCopy-paste URL manually, don't click
MCP server not found"Tool not found" errors on all MCP callsServer didn't start with Claude Code sessionRestart Claude Code (MCP servers auto-start)
Port conflict"Address already in use" during authorize()OAuth callback server already bound to portRestart Claude Code to reset server state
Stale token in memoryCredentials valid on disk but API calls failMCP server has cached invalid tokenRestart Claude Code to reload credentials from disk
Credentials in wrong locationToken.json exists but skill can't find itCustom MCP installation pathCheck .mcp.json command/args to infer storage location

General troubleshooting principle: When in doubt, restart Claude Code. This cleanly reloads all MCP servers with fresh credentials from disk.


Implementation Patterns by MCP Type

Pattern A: google-workspace MCP (workspace-mcp package)
  • Credentials: ~/.google_workspace_mcp/credentials/{email}.json
  • Email required: Yes — passed to every API call as user_google_email parameter
  • Email format: EXACT string from filename (e.g., john.doe@gmail.com ≠ johndoe@gmail.com)
  • Test call: create_doc() with email + title
  • Re-auth: mcp__google-workspace__authorize()
Pattern B: google-docs MCP (custom Python server)
  • Credentials: ~/.claude/mcp-servers/google-docs-mcp-server/token.json
  • Email required: No — token is user-agnostic
  • Test call: create_document(title="...") — no email param
  • Re-auth: mcp__google-docs__authorize_google_docs()
  • Token contents: JSON with token, refresh_token, expiry, scopes
Pattern C: google-slides MCP
  • Credentials: ~/.claude/mcp-servers/google-slides-mcp-server/token.json
  • Email required: No
  • Test call: create_presentation(title="...")
  • Re-auth: mcp__google-slides__authorize()

Adaptation rule: Always detect actual config from .mcp.json and ls results rather than assuming a specific pattern. Support all three patterns in the same skill.


Rules

  1. Always use CREATE for test calls, never READ. Creating a resource only requires valid auth. Reading requires auth + permissions on that specific resource.

  2. Extract email from credential filename for workspace-mcp. Don't ask the user for their email. The exact string in the filename is what must be passed to API calls.

  3. One auth attempt, then clear explanation. If re-auth fails, provide diagnostics and actionable next steps. Don't retry repeatedly.

© ai-analyst-lab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/auth-preflight of ai-analyst-lab/ai-analyst.

Open the folder on GitHubat commit 52c0744

Compare with similar skills

Auth Preflight next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auth Preflight compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auth Preflight this skillai-analyst-lab/ai-analyst304—~3.1kAutomated safety check: PassMIT
Managing Google Workspacetaylorwilsdon/google_workspace_mcp3.3k—~2.9kAutomated safety check: PassMIT
Google Workspaceespennilsen/pi122—~3.4kAutomated safety check: PassMIT
Google Docssanjay3290/ai-skills431—~636Automated safety check: PassApache-2.0
Gwskv0906/pm-kit138—~1.6kAutomated safety check: PassMIT
Google Docs, Sheets and Slides Editingasgeirtj/system_prompts_leaks69k—~3.5kAutomated safety check: WarnCC0-1.0

Similar skills

  • Managing Google Workspace

    taylorwilsdon/google_workspace_mcp

    Manages Google Workspace operations across 12 services (Gmail, Drive, Calendar, Docs, Sheets, Slides, Forms, Tasks, Contacts, Chat, Apps Script, Custom Search).

    3.3k GitHub stars~2.9k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Google Workspace

    espennilsen/pi

    Manage Google Workspace via the gws CLI — Drive, Gmail, Sheets, Docs, Slides, People, Chat, Meet, Forms, and cross-service workflows.

    122 GitHub stars~3.4k tokensUpdated 17 days ago
    Documents & OfficeAuto-check passed
  • Google Docs

    sanjay3290/ai-skills

    Interact with Google Docs - create documents, search by title, read content, and edit text.

    431 GitHub stars~636 tokensUpdated 28 days ago
    Documents & OfficeAuto-check passed
  • Gws

    kv0906/pm-kit

    This skill should be used when the user asks to "set up gws", "install Google Workspace CLI", "connect Gmail to Claude", "manage Google Drive from terminal", "send email from CLI", "check my…

    138 GitHub stars~1.6k tokensUpdated 3 mo ago
    Documents & OfficeAuto-check passed
  • Google Docs, Sheets and Slides Editing

    asgeirtj/system_prompts_leaks

    Guidance for creating and editing Google Docs, Sheets and Slides through connectors, with per-app API rules and helper scripts for positions, ranges and slide layout.

    69k GitHub stars~3.5k tokensUpdated yesterday
    Documents & OfficeAuto-check: warnings
  • Google Workspace

    mitsuhiko/agent-stuff

    Access Google Workspace APIs (Drive, Docs, Calendar, Gmail, Sheets, Slides, Chat, People) via local helper scripts without MCP.

    3.2k GitHub stars~919 tokensUpdated 11 days ago
    Documents & OfficeAuto-check passed

More from ai-analyst-lab/ai-analyst

All 43 skills in this repo
  • Always Compare

    ai-analyst-lab/ai-analyst

    Never present a metric or number in isolation; anchor every number to a comparison (prior period, benchmark, or another segment) or state that none is available.

    304 GitHub stars~1.4k tokensUpdated 8 days ago
    Auto-check passed
  • Archaeology

    ai-analyst-lab/ai-analyst

    Retrieve proven SQL patterns, table cheatsheets, and join patterns from .knowledge/query-archaeology/ so past work gets reused.

    304 GitHub stars~1.3k tokensUpdated 8 days ago
    Auto-check passed
  • Archive Analysis

    ai-analyst-lab/ai-analyst

    Save completed analyses to the knowledge system's analysis archive for future reference.

    304 GitHub stars~2.7k tokensUpdated 8 days ago
    Auto-check passed
  • Causal

    ai-analyst-lab/ai-analyst

    Causal inference toolkit for when experiments are not possible: estimate treatment effects from observational data with assumption checks and mandatory caveats.

    304 GitHub stars~1.8k tokensUpdated 8 days ago
    Auto-check passed
  • Chart To Drive

    ai-analyst-lab/ai-analyst

    Standardized workflow for uploading local chart PNGs to Google Drive and making them available for insertion into Google Docs and Slides.

    304 GitHub stars~1.4k tokensUpdated 8 days ago
    Auto-check passed
  • Codex Review

    ai-analyst-lab/ai-analyst

    Independently validate the current analysis with a second model (OpenAI Codex).

    304 GitHub stars~3k tokensUpdated 8 days ago
    Auto-check passed

Questions about Auth Preflight

What does Auth Preflight do?

Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive). Auth Preflight is an agent skill from ai-analyst-lab/ai-analyst. Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive).

When should I use Auth Preflight?

Auth Preflight fits situations like: users mention Google Doc; upload to Drive; export to Google; any Google-related output format.

How do I install Auth Preflight in Claude Code?

Run `npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a claude-code`. Or copy the skill folder (.claude/skills/auth-preflight in ai-analyst-lab/ai-analyst) into .claude/skills/auth-preflight in your project. Claude Code loads it when a task matches its description.

How do I install Auth Preflight in Codex?

Run `npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a codex`. Or copy the skill folder (.claude/skills/auth-preflight in ai-analyst-lab/ai-analyst) into .agents/skills/auth-preflight in your project. Codex loads it when a task matches its description.

Can I use Auth Preflight in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ai-analyst-lab/ai-analyst --skill auth-preflight -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auth-preflight, .gemini/skills/auth-preflight, .github/skills/auth-preflight and .opencode/skills/auth-preflight in your project.

What does Auth Preflight need to run?

SKILL.md names no scripts, command-line tools or credentials: Auth Preflight is instructions for the agent only. Our summary lists: Python 3.

Does Auth Preflight access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Auth Preflight safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auth Preflight use?

Auth Preflight is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auth Preflight use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auth Preflight?

Skills that share tags, products or a category with Auth Preflight: Managing Google Workspace (taylorwilsdon/google_workspace_mcp, 3.3k stars), Google Workspace (espennilsen/pi, 122 stars), Google Docs (sanjay3290/ai-skills, 431 stars) and Gws (kv0906/pm-kit, 138 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auth Preflight?

ai-analyst-lab (a GitHub organization) maintains it in ai-analyst-lab/ai-analyst, which has 304 GitHub stars. The repository holds 43 skills in this directory. The repository was last updated on September 30, 2026.

Source: ai-analyst-lab/ai-analyst on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.