Agent skill

Google Workspace

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when server-side code reads or writes Gmail, Drive, Calendar, or Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs…

MITAuto-check passedBackend & APIs

Install Google Workspace

skills CLI
$ npx skills add ericrisco/rsc-harness --skill google-workspace -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness google-workspace --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/google-workspace .claude/skills/google-workspace && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
google-workspace
GitHub stars
156
Token cost
~3.2k tokens
SKILL.md length
1,153 words
Files
6 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when server-side code reads or writes Gmail, Drive, Calendar, or Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs…

  • Works in 4 steps: Enable the APIs you will call in the… → Create the service account in IAM &… → Decide scopes (next section) — the exact… → …
  • Server-side code reads
  • SKILL.md covers Pick your auth mode, Setup checklist, Scopes: least privilege and Build the authed client, plus 4 more sections
  • Runs Shell scripts from its folder; reaches googleapis.com; needs SA_PRIVATE_KEY

What it does

Google Workspace is an agent skill from ericrisco/rsc-harness. Use when server-side code reads or writes Gmail, Drive, Calendar, or Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs domain-wide delegation vs keyless), scoping to least privilege, building the authed Node/Python client, staying under per-user quota, and debugging unauthorizedclient / 403 / 429. NOT SMTP providers or deliverability (that is email-connector), NOT slot-finding and booking UX (that is calendar-scheduling).

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/api-recipes.md`).

It sits in Backend & APIs, covering Transactional email, Email management and Cloud office suites. It works with Google Workspace, Gmail, Google Cloud and Python. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Server-side code reads
  • Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs domain-wide delegation vs keyless)
  • Scoping to least privilege
  • Building the authed Node/Python client

Example prompts

  • “/google-workspace”

Requirements

  • Python 3
  • A Bash shell
  • A credential in SA_PRIVATE_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Enable the APIs you will call in the Cloud console (Gmail, Drive,
  2. Create the service account in IAM & Admin → Service Accounts. For keyless
  3. Decide scopes (next section) — the exact scope strings you will request.
  4. Authorize DWD only if impersonating. In the Admin console →

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • googleapis.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SA_PRIVATE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Workspace loads about 3.2k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 125 tokens; SKILL.md has 1,153 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~125
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,153 words, ~3,220 tokens.

Download SKILL.mdSave it as .claude/skills/google-workspace/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
google-workspace
description
Use when server-side code reads or writes Gmail, Drive, Calendar, or Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs domain-wide delegation vs keyless), scoping to least privilege, building the authed Node/Python client, staying under per-user quota, and debugging unauthorized_client / 403 / 429. NOT SMTP providers or deliverability (that is `email-connector`), NOT slot-finding and booking UX (that is `calendar-scheduling`).
tags
google-workspace, gmail-api, drive-api, calendar-api, sheets-api, service-account, domain-wide-delegation, oauth-scopes
recommends
email-connector, calendar-scheduling, spreadsheet-ops, document-processing, automation-flows, secure-coding, webhooks
origin
risco

Google Workspace — auth + calling Gmail/Drive/Calendar/Sheets

This skill owns one layer: authenticating to and calling the four Google Workspace REST APIs from server-side code. Everything here is service-account / machine auth — if a real user must click "Allow", that is interactive OAuth and out of scope.

Where the neighbouring layers live:

Not this skillGoes toThis skill's slice
SMTP/provider choice, transactional/marketing sendsemail-connectorGmail-the-API inside a Workspace mailbox
SPF/DKIM, inbox placementemail-deliverability—
Availability search, booking-link UX, timezone-as-a-featurecalendar-schedulingRaw Calendar event CRUD underneath
Sheet data modeling, formulas, pivotsspreadsheet-opsSheets API read/write transport
Doc/PDF parsing, extraction, OCRdocument-processingDrive as storage transport (upload/download/move/permissions)
Chaining several connectors into one flowautomation-flowsThe individual Google calls
Notion as the backend / generic REST wrappingnotion-connector, api-connector-builder—
Receiving Gmail/Drive push notificationswebhooks—

Pick your auth mode

Choose first — it dictates scopes, the Admin-console step, and the client build.

SituationModeWhy
App owns the data (its own Drive folder, its own calendar, a shared drive it was added to)Service account, no delegationThe SA is its own identity; no need to act as a human. Simplest, no Admin step.
Must act AS each Workspace user (send from ops@acme.com, read their inbox/calendar)Service account + domain-wide delegation + subjectGmail has no "shared mailbox via SA" — to touch a user's mail/calendar you impersonate them. Requires a Workspace admin to authorize the SA.
Code runs on GCP (Cloud Run, GKE, Functions) or CI with WIFKeyless: Application Default Credentials / Workload Identity FederationNo long-lived key file to leak or rotate. The runtime mints short-lived tokens. Always prefer this when the platform supports it.

Rule: never reach for domain-wide delegation if app-owned resources suffice. DWD lets the SA impersonate anyone in the org for the granted scopes — it is a large blast radius. Use it only when you genuinely must act as the user.

Setup checklist

Do these in order. references/auth-setup.md has the full Cloud + Admin click-path, the scope catalog, DWD authorization, keyless WIF/ADC, and a longer troubleshooting matrix.

  1. Enable the APIs you will call in the Cloud console (Gmail, Drive, Calendar, Sheets) for the project. A disabled API returns 403 regardless of scopes.
  2. Create the service account in IAM & Admin → Service Accounts. For keyless you stop here and attach the SA to the runtime; for a key you create a JSON key (and treat it like a password — see Security).
  3. Decide scopes (next section) — the exact scope strings you will request.
  4. Authorize DWD only if impersonating. In the Admin console → Security → Access and data control → API controls → Manage Domain Wide Delegation, add the SA's client ID (the numeric client_id, not the email) plus the exact comma-separated scope list. A scope requested in code but not authorized here is the #1 cause of unauthorized_client.

Scopes: least privilege

Request the narrowest scope that does the job. Broad scopes also force a stricter Google verification review and widen what a leaked key can touch.

text
# Bad — full read/write to ALL of the user's Drive
https://www.googleapis.com/auth/drive

# Good — only files this app created or was explicitly shared
https://www.googleapis.com/auth/drive.file
TaskScopeNote
Send mail onlygmail.sendCannot read the inbox — ideal for notifications.
Read mailgmail.readonlyRead, no modify/delete.
Modify labels/stategmail.modifyAvoid full mail.google.com unless you truly need delete + settings.
App-created Drive filesdrive.fileCannot see the user's other files — smallest footprint.
Read all Drivedrive.readonlyPrefer over full drive.
Calendar eventscalendar.eventsNarrower than full calendar.
Read/write SheetsspreadsheetsUse spreadsheets.readonly if you only read.

Build the authed client

Node uses googleapis (latest 173.x, maintenance mode — bugs/security only) with google-auth-library (10.6.2). Python uses google-auth + google-api-python-client. The impersonation line is the subject / with_subject.

javascript
// Node — service account, optionally impersonating a Workspace user.
import { google } from 'googleapis';

const auth = new google.auth.JWT({
  email: process.env.SA_CLIENT_EMAIL,
  key: process.env.SA_PRIVATE_KEY.replace(/\\n/g, '\n'), // from secret mgr, never a file in the repo
  scopes: ['https://www.googleapis.com/auth/gmail.send'],
  subject: 'ops@acme.com', // omit this line for app-owned (no-delegation) mode
});
const gmail = google.gmail({ version: 'v1', auth });
javascript
// Node — keyless on GCP (Cloud Run / GKE / CI with WIF). No key in code at all.
import { google } from 'googleapis';
const auth = new google.auth.GoogleAuth({
  scopes: ['https://www.googleapis.com/auth/spreadsheets.readonly'],
});
const sheets = google.sheets({ version: 'v4', auth });
python
# Python — service account from credentials, impersonating a user.
from google.oauth2 import service_account
from googleapiclient.discovery import build

SCOPES = ["https://www.googleapis.com/auth/gmail.send"]
creds = service_account.Credentials.from_service_account_info(
    sa_info, scopes=SCOPES         # sa_info loaded from secret mgr, not a tracked file
).with_subject("ops@acme.com")     # drop .with_subject(...) for app-owned mode
gmail = build("gmail", "v1", credentials=creds, cache_discovery=False)

Per-API recipes (short)

Copy-paste-ready minimums. Longer recipes (raw MIME with attachments, resumable uploads, batchUpdate, recurring/timezone-correct events) are in references/api-recipes.md.

javascript
// Gmail: send. Body must be base64url-encoded RFC 822 (note -_ , no padding).
const raw = Buffer.from(
  'To: a@acme.com\r\nSubject: Report\r\n\r\nHello.'
).toString('base64url');
await gmail.users.messages.send({ userId: 'me', requestBody: { raw } });
javascript
// Drive: create a file, then grant read to one person (least-privilege share).
const file = await drive.files.create({
  requestBody: { name: 'report.pdf' },
  media: { mimeType: 'application/pdf', body: stream },
  fields: 'id', // partial response — ask only for what you use
});
await drive.permissions.create({
  fileId: file.data.id,
  requestBody: { role: 'reader', type: 'user', emailAddress: 'a@acme.com' },
});
python
# Calendar: insert an event (always send explicit IANA timeZone).
event = {
    "summary": "Sync",
    "start": {"dateTime": "2026-06-10T10:00:00", "timeZone": "Europe/Andorra"},
    "end":   {"dateTime": "2026-06-10T10:30:00", "timeZone": "Europe/Andorra"},
}
cal.events().insert(calendarId="primary", body=event).execute()
python
# Sheets: write a range. Use values.batchUpdate to write many ranges in one call.
sheets.spreadsheets().values().update(
    spreadsheetId=SID, range="Sheet1!A2",
    valueInputOption="USER_ENTERED",
    body={"values": [["2026-06-02", 1290]]},
).execute()

Stay under quota

The per-user ceiling is the one that bites a cron looping over a mailbox.

  • Gmail: 1.2M units/min per project, 6,000 units/min per user, 80M units/day. Costs: messages.send 100, messages.get 20, messages.list 5, messages.modify 5, drafts.create 10. Hard cap 500 recipients/message.
  • Drive: 1M units/min per project, 325,000 units/min per user, 1 TB/day egress.
  • Sheets: read and write each 300/min per project, 60/min per user; 429 on overage; 180s request timeout; keep payloads under ~2 MB.
  • Policy shift: as of 2026-05-01 Google updated Workspace quota policy — projects active Nov 2025–Apr 2026 keep legacy quotas, new projects get the new model, and overage will start incurring Cloud billing charges later in 2026. Treat quota as a cost line, not a free ceiling.

Three habits keep you under it:

  1. fields partial responses — ask only for the fields you read; smaller responses, lower cost, faster.
  2. Batch — Sheets values.batchUpdate, Gmail batch requests, Drive batch — one call instead of N cuts per-user request count directly.
  3. Exponential backoff with jitter on 403 rateLimitExceeded and 429 — retrying immediately just burns more quota.
python
# Backoff: min((2^n) + random_ms, max_backoff). Cap 32–64s. Jitter avoids
# thundering-herd retries syncing up.
import random, time
from googleapiclient.errors import HttpError

def with_backoff(call, max_retries=6, max_backoff=64):
    for n in range(max_retries):
        try:
            return call()
        except HttpError as e:
            if e.resp.status not in (403, 429) or n == max_retries - 1:
                raise
            time.sleep(min((2 ** n) + random.random(), max_backoff))
Show full SKILL.md (373 more words)Show less

Security rules

  • Never commit the SA key JSON. It is a long-lived bearer credential — a committed service_account.json is game over. Add *.json SA patterns to .gitignore; the verify.sh here flags tracked keys.
  • Prefer keyless. A leaked key is the single most common Workspace credential compromise. On GCP/CI use ADC or Workload Identity Federation so there is no file to leak. If you must use a key, store it in a secret manager (env-injected, not a file beside the code) and rotate it.
  • Least scope. A leaked drive.file key sees app files; a leaked full drive key sees everything. The scope IS the blast radius.
  • Map the error before you change anything:
ErrorLikely causeFix
unauthorized_clientSA client ID / scope not authorized for DWDAdd the client ID + exact scopes in Admin console Manage DWD
403 insufficient permissionsScope too narrow, or API not enabledWiden to the right scope (still least), enable the API
403 rateLimitExceeded / 429Per-user or per-project quota hitExponential backoff + jitter; batch; spread load
400 failedPrecondition on impersonationsubject set but DWD not configuredEither remove subject (app-owned) or finish DWD setup
invalid_grantClock skew or stale/rotated keySync clock; re-issue the key

Anti-patterns

Anti-patternWhy it breaksDo instead
Committing service_account.json to the repoLong-lived key in git history = full compromise; can't un-leakKeyless ADC/WIF, or key in a secret manager + .gitignore
Requesting auth/drive / mail.google.com "to be safe"Max blast radius, stricter Google review, more to leakNarrowest scope: drive.file, gmail.send, spreadsheets.readonly
Using DWD subject for app-owned dataImpersonating users when the SA could own the resource — needless blast radius + an Admin dependencyDrop subject; let the SA own the folder/calendar/shared drive
Looping messages.send/values.update per row with no backoffTrips the 6k/min (Gmail) or 60/min (Sheets) per-user cap → 429 stormBatch (values.batchUpdate) + exponential backoff with jitter
Reading whole resources without fieldsBigger payloads, higher quota cost, slowerRequest only the fields you use (fields: 'id')
Hardcoding the private key inline in sourceCan't rotate, leaks via logs/screenshots/historyInject from env/secret manager; \n-unescape at load
Pasting raw text into Gmail rawAPI needs base64url RFC 822, not plain text → 400Build a MIME message, base64url-encode it

Before this connector ships, run the secret-handling and key-rotation pass in ../secure-coding/SKILL.md.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/google-workspace of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/api-recipes.md
  • references/auth-setup.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Google Workspace next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Workspace compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Workspace this skillericrisco/rsc-harness156—~3.2kAutomated safety check: PassMIT
Google WorkspaceRedWoodOG/Hermes-Desktop177—~2.1kAutomated safety check: PassMIT
GCP Workspace Pivotwgpsec/AboutSecurity1.8k—~2.9kAutomated safety check: PassNone
Community Google WorkspaceArgentAIOS/argentos-core126—~2.8kAutomated safety check: PassMIT
Google WorkspaceTommy-yw/RunbookHermes5461 repos~2.7kAutomated safety check: PassMIT
Google Workspacetaracodlabs/aiden849—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Google Workspace

    RedWoodOG/Hermes-Desktop

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration via Python.

    177 GitHub stars~2.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • GCP Workspace Pivot

    wgpsec/AboutSecurity

    GCP 到 Google Workspace 的穿越攻击方法论。当已获取 GCP Service Account 或 Project 权限并发现目标组织使用 Google Workspace、需要从云平台穿越到企业邮件/文档/管理控制台、或发现 Domain-Wide Delegation 配置时使用。覆盖 Domain-Wide Delegation 滥用、OAuth…

    1.8k GitHub stars~2.9k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Community Google Workspace

    ArgentAIOS/argentos-core

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration for community skills.

    126 GitHub stars~2.8k tokensUpdated 3 mo ago
    Documents & OfficeAuto-check passed
  • Google Workspace

    Tommy-yw/RunbookHermes

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration for Hermes.

    546 GitHub starsUsed in 1 repo~2.7k tokens
    Documents & OfficeAuto-check passed
  • Google Workspace

    taracodlabs/aiden

    Gmail, Calendar, Drive, Sheets, Docs via Google API (SA / OAuth)

    849 GitHub stars~1.1k tokensUpdated 24 days ago
    Documents & OfficeAuto-check passed
  • Google Workspace

    AlexAI-MCP/hermes-CCC

    Automate Google Workspace — Gmail, Drive, Sheets, Docs, Calendar via Google API Python client or gcloud CLI.

    135 GitHub stars~1.2k tokensUpdated 6 mo ago
    Documents & OfficeAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Questions about Google Workspace

What does Google Workspace do?

A skill your agent uses when server-side code reads or writes Gmail, Drive, Calendar, or Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs…. Google Workspace is an agent skill from ericrisco/rsc-harness. Use when server-side code reads or writes Gmail, Drive, Calendar, or Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs domain-wide delegation vs keyless), scoping to least privilege, building the authed Node/Python client, staying under per-user quota, and debugging unauthorizedclient / 403 / 429.

When should I use Google Workspace?

Google Workspace fits situations like: server-side code reads; sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs domain-wide delegation vs keyless); scoping to least privilege; building the authed Node/Python client.

How do I install Google Workspace in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill google-workspace -a claude-code`. Or copy the skill folder (skills/google-workspace in ericrisco/rsc-harness) into .claude/skills/google-workspace in your project. Claude Code loads it when a task matches its description.

How do I install Google Workspace in Codex?

Run `npx skills add ericrisco/rsc-harness --skill google-workspace -a codex`. Or copy the skill folder (skills/google-workspace in ericrisco/rsc-harness) into .agents/skills/google-workspace in your project. Codex loads it when a task matches its description.

Can I use Google Workspace in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill google-workspace -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-workspace, .gemini/skills/google-workspace, .github/skills/google-workspace and .opencode/skills/google-workspace in your project.

What does Google Workspace need to run?

Going by SKILL.md and its folder, Google Workspace needs a shell for the scripts in its folder and credentials named SA_PRIVATE_KEY. Our summary lists: Python 3; A Bash shell; A credential in SA_PRIVATE_KEY.

Does Google Workspace access the network?

SKILL.md names 1 domain. In commands or code: googleapis.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Google Workspace safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Google Workspace use?

Google Workspace is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Workspace use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Google Workspace?

Skills that share tags, products or a category with Google Workspace: Google Workspace (RedWoodOG/Hermes-Desktop, 177 stars), GCP Workspace Pivot (wgpsec/AboutSecurity, 1.8k stars), Community Google Workspace (ArgentAIOS/argentos-core, 126 stars) and Google Workspace (Tommy-yw/RunbookHermes, 546 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Workspace?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.