Agent skill

Google Docs Audit Reports

by forefy in forefy/.context

Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.

MITAuto-check passedDocuments & Office

Install Google Docs Audit Reports

skills CLI
$ npx skills add forefy/.context --skill gdocs-audit-report -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forefy/.context gdocs-audit-report --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunter-utils/gdocs-audit-report .claude/skills/gdocs-audit-report && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gdocs-audit-report
GitHub stars
152
Token cost
~951 tokens
SKILL.md length
391 words
Files
5 (incl. scripts, references)
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.

  • Works in 10 steps: Index drift → Text bg ≠ paragraph bg → headingId already has h. prefix → …
  • Generating a security audit report in Google Docs from a list of findings
  • SKILL.md covers Overview, Workflow, Critical Gotchas (read these… and Formatting Standards, plus 2 more sections
  • Runs Python scripts from its folder

What it does

The skill collects patterns and gotchas for writing and maintaining security audit reports in Google Docs with the Docs API, authenticated with a service account. A helper, scripts/gdocs_auth.py, provides the token function, and the agent is told to read references/api-patterns.md and references/formatting-standards.md before writing any script.

Its core workflow is to authenticate, fetch a fresh document snapshot before every batch of edits, build all operations sorted from the highest index to the lowest, and apply them. Listed gotchas include index drift after inserts or deletes, text backgrounds that leave gaps compared with paragraph shading for code blocks, heading anchor URLs where the heading ID already carries a prefix, code styling that needs a second pass, and sorting code terms longest first.

Further notes cover the order for removing backticks, converting bullets, linking cross-references to finding IDs while skipping only already-linked runs, replacing table cell content, and using replaceAllText to renumber finding IDs. A reference explains how to create a Google service account.

When your agent uses it

  • Generating a security audit report in Google Docs from a list of findings
  • Fixing a report whose code blocks have white gaps or broken styling
  • Renumbering finding IDs and keeping cross-reference links working

Example prompts

  • “Create the audit report in our Google Doc with a findings table and severity colors.”
  • “The code blocks in this audit doc have white gaps between lines. Fix the styling.”
  • “Renumber the findings in the report and update every cross-reference link.”

Requirements

  • A Google service account with access to the target document
  • Python for scripts/gdocs_auth.py
  • Network access to the Google Docs API
  • Compatibility (from SKILL.md): Requires Google Docs API (service-account creds)

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Index drift
  2. Text bg ≠ paragraph bg
  3. headingId already has h. prefix
  4. Code styling needs multiple passes
  5. Sort code terms longest-first
  6. Backtick removal order (per segment, high→low)
  7. Bullet conversion
  8. Cross-reference links: skip only already-linked runs
  9. Table cell content replace
  10. replaceAllText for bulk renames

What it can do on your machine

Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Google Docs API (service-account creds)

    From compatibility in the SKILL.md frontmatter.

Context cost

Google Docs Audit Reports loads about 951 tokens when it runs, and up to ~3.2k if it reads all its reference files. Until then it costs about 41 tokens; SKILL.md has 391 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~951
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 391 words, ~951 tokens.

Download SKILL.mdSave it as .claude/skills/gdocs-audit-report/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
gdocs-audit-report
description
Write and format security-audit reports in Google Docs via the Docs API - findings, tables, and severity styling. Use to build or fix a report.
compatibility
Requires Google Docs API (service-account creds)

Google Docs Security Audit Report

Overview

This skill provides patterns, constants, and gotcha-avoidance for building and maintaining security audit reports in Google Docs using the Docs API (service account auth). It encodes hard-won lessons around index drift, code styling multi-pass, paragraph vs text backgrounds, heading anchor URLs, and cross-reference linking.

Always read references/api-patterns.md and references/formatting-standards.md before writing any script.

Workflow

1. Auth          → make_token() from scripts/gdocs_auth.py
2. get_doc()     → fresh snapshot before EVERY batch of edits
3. Build ops     → sort ALL ops highest-index-first
4. do_batch()    → send in chunks of ≤50
5. Verify        → get_doc() again and spot-check changed ranges

Critical Gotchas (read these first)

1. Index drift

Any insert/delete shifts every index above it. Always sort ops high→low. Always get_doc() fresh.

2. Text bg ≠ paragraph bg

updateTextStyle.backgroundColor only covers character width - leaves white gaps between lines in code blocks. Use updateParagraphStyle.shading.backgroundColor + spaceAbove/Below: 0 for full-width code block backgrounds.

3. headingId already has h. prefix

Anchor URL = #heading={headingId} - not #heading=h.{headingId}.

4. Code styling needs multiple passes

After updateTextStyle splits a run, new unstyled sub-runs appear. Always do a second full-doc re-scan after the first styling pass.

5. Sort code terms longest-first

Prevents maxRelayFeeBPS matching before assetConfig.maxRelayFeeBPS and leaving a partial un-styled prefix.

6. Backtick removal order (per segment, high→low)

Delete closing backtick → style inner → delete opening backtick - all in one batch.

7. Bullet conversion

createParagraphBullets does not change indices. Then deleteContentRange the - prefix high→low in a second batch.

Scan ALL runs for X-NN regex - only skip runs where textStyle.link is already set. Do NOT also filter by font (Courier runs can contain xrefs too).

Show full SKILL.md (160 more words)Show less
9. Table cell content replace

Delete to elements[-1].endIndex - 1 (keep the required trailing \n), then insert. Sort delete (higher) before insert (lower) in same batch.

10. replaceAllText for bulk renames

Use replaceAllText for ID renames (e.g. renumbering findings). Same-length replacements are index-safe. Do in one batch, longest/most-specific strings first.

Formatting Standards

See references/formatting-standards.md for:

  • Severity RGB colors (Critical, High, Medium, Low, Unmitigated)
  • Heading purple, code purple, code bg gray
  • Finding structure template
  • Summary table column definitions
  • Finding ID scheme (C-01, H-01, etc.)

API Patterns

See references/api-patterns.md for:

  • Auth boilerplate
  • All common op templates (style, delete, insert, hyperlink, bullets, paragraph shading)
  • Heading anchor URL construction
  • Cross-reference linking pattern
  • Inline code multi-pass approach

Resources

  • scripts/gdocs_auth.py - reusable auth + get_doc + do_batch helpers
  • references/api-patterns.md - op templates and patterns
  • references/formatting-standards.md - colors, typography, structure constants
  • references/how-to-create-google-service-account.md - one-time setup: instruct the user to create a service account, advise the user to restrict it to the AI-only Drive folder/file (via google share feature), and provide the JSON key path

© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/hunter-utils/gdocs-audit-report of forefy/.context.

  • SKILL.md
  • references/api-patterns.md
  • references/formatting-standards.md
  • references/how-to-create-google-service-account.md
  • scripts/gdocs_auth.py

Open the folder on GitHubat commit c8ff161

Compare with similar skills

Google Docs Audit Reports next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Docs Audit Reports compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Docs Audit Reports this skillforefy/.context152—~951Automated safety check: PassMIT
Google Workspace CLIalirezarezvani/claude-skills28k—~3kAutomated safety check: NotesMIT
Managing Google Workspacetaylorwilsdon/google_workspace_mcp3.3k—~2.9kAutomated safety check: PassMIT
Colleague DistillationZhixiangLuo/10xProductivity478—~2.1kAutomated safety check: NotesMIT
Gwskv0906/pm-kit138—~1.6kAutomated safety check: PassMIT
Gdoc To Markdowniurykrieger/claude-bedrock1051 repos~3.8kAutomated safety check: NotesMIT

Similar skills

  • Google Workspace CLI

    alirezarezvani/claude-skills

    Google Workspace administration via the gws CLI (github.com/googleworkspace/cli).

    28k GitHub stars~3k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check: notes
  • Managing Google Workspace

    taylorwilsdon/google_workspace_mcp

    Manages Google Workspace operations across 12 services (Gmail, Drive, Calendar, Docs, Sheets, Slides, Forms, Tasks, Contacts, Chat, Apps Script, Custom Search).

    3.3k GitHub stars~2.9k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Colleague Distillation

    ZhixiangLuo/10xProductivity

    Distill a colleague into a reusable AI skill (work + persona) using tool connections — Slack, Slack AI, Jira, GHE, Bitbucket, Confluence, SharePoint, Teams, Outlook, Notion, Linear, Google Docs, and…

    478 GitHub stars~2.1k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check: notes
  • Gws

    kv0906/pm-kit

    This skill should be used when the user asks to "set up gws", "install Google Workspace CLI", "connect Gmail to Claude", "manage Google Drive from terminal", "send email from CLI", "check my…

    138 GitHub stars~1.6k tokensUpdated 3 mo ago
    Documents & OfficeAuto-check passed
  • Gdoc To Markdown

    iurykrieger/claude-bedrock

    Internal fetcher module for Google Docs and Sheets. An agent skill from iurykrieger/claude-bedrock.

    105 GitHub starsUsed in 1 repo~3.8k tokens
    Documents & OfficeAuto-check: notes
  • Cache Notes

    benoror/obsidianos_work

    Fetch & embed AI transcripts as Obsidian callouts. An agent skill from benoror/obsidianos_work.

    165 GitHub stars~2.7k tokensUpdated 3 mo ago
    Documents & OfficeAuto-check passed

More from forefy/.context

All 20 skills in this repo
  • Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.

    152 GitHub stars~1.4k tokensUpdated 3 days ago
    Auto-check passed
  • Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.

    152 GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed
  • Audit Scope

    forefy/.context

    Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

    152 GitHub stars~2.3k tokensUpdated 3 days ago
    Auto-check passed
  • External Enumeration

    forefy/.context

    Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

    152 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    Auto-check passed
  • Infrastructure Audit

    forefy/.context

    Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.

    152 GitHub stars~3.7k tokensUpdated 3 days ago
    Auto-check: notes

Works with

Questions about Google Docs Audit Reports

What does Google Docs Audit Reports do?

Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links. The skill collects patterns and gotchas for writing and maintaining security audit reports in Google Docs with the Docs API, authenticated with a service account.md before writing any script.

When should I use Google Docs Audit Reports?

Google Docs Audit Reports fits situations like: generating a security audit report in Google Docs from a list of findings; fixing a report whose code blocks have white gaps or broken styling; renumbering finding IDs and keeping cross-reference links working.

How do I install Google Docs Audit Reports in Claude Code?

Run `npx skills add forefy/.context --skill gdocs-audit-report -a claude-code`. Or copy the skill folder (skills/hunter-utils/gdocs-audit-report in forefy/.context) into .claude/skills/gdocs-audit-report in your project. Claude Code loads it when a task matches its description.

How do I install Google Docs Audit Reports in Codex?

Run `npx skills add forefy/.context --skill gdocs-audit-report -a codex`. Or copy the skill folder (skills/hunter-utils/gdocs-audit-report in forefy/.context) into .agents/skills/gdocs-audit-report in your project. Codex loads it when a task matches its description.

Can I use Google Docs Audit Reports in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill gdocs-audit-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gdocs-audit-report, .gemini/skills/gdocs-audit-report, .github/skills/gdocs-audit-report and .opencode/skills/gdocs-audit-report in your project.

What does Google Docs Audit Reports need to run?

Going by SKILL.md and its folder, Google Docs Audit Reports needs Python for the scripts in its folder. Our summary lists: A Google service account with access to the target document; Python for scripts/gdocs_auth.py; Network access to the Google Docs API. Compatibility (from SKILL.md): Requires Google Docs API (service-account creds).

Does Google Docs Audit Reports access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Google Docs Audit Reports safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Google Docs Audit Reports use?

Google Docs Audit Reports is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Docs Audit Reports use?

About 951 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Google Docs Audit Reports?

Skills that share tags, products or a category with Google Docs Audit Reports: Google Workspace CLI (alirezarezvani/claude-skills, 28k stars), Managing Google Workspace (taylorwilsdon/google_workspace_mcp, 3.3k stars), Colleague Distillation (ZhixiangLuo/10xProductivity, 478 stars) and Gws (kv0906/pm-kit, 138 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Docs Audit Reports?

forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.

Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.