Run production Google Analytics 4 Data API reports with gateway-injected bearer auth, safe request review, traffic source, landing-page, time-series, revenue, session, and key-event reporting.

MITAuto-check passedData & Analytics

Install Ga4

skills CLI
$ npx skills add HybridAIOne/hybridclaw --skill ga4 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HybridAIOne/hybridclaw ga4 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ga4 .claude/skills/ga4 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ga4
GitHub stars
159
Token cost
~1.9k tokens
SKILL.md length
584 words
Files
3 (incl. scripts)
Skills in repo
72
Repo updated
First seen
Licence
MIT

At a glance

Run production Google Analytics 4 Data API reports with gateway-injected bearer auth, safe request review, traffic source, landing-page, time-series, revenue, session, and key-event reporting.

  • Works in 5 steps: Start with report-plan for… → Review generated or user-supplied… → For live GA4 API calls inside… → …
  • Tasks that involve Landing pages
  • SKILL.md covers Scope, Default Workflow, Auth Contract and Command Contract, plus 2 more sections
  • Runs Python scripts from its folder; calls python3; reaches googleapis.com; needs GA4_SERVICE_ACCOUNT_PRIVATE_KEY and GOOGLE_WORKSPACE_CLI_TOKEN

What it does

Ga4 is an agent skill from HybridAIOne/hybridclaw. Run production Google Analytics 4 Data API reports with gateway-injected bearer auth, safe request review, traffic source, landing-page, time-series, revenue, session, and key-event reporting.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `evals/scenarios.json` and `scripts/ga4.py`).

It sits in Data & Analytics, covering Landing pages and Forecasting and time series. It works with Google Analytics. The repository describes itself as: Enterprise-ready self-hosted AI assistant runtime with sandboxed execution, secure credentials, approvals, and memory. The licence is MIT.

When your agent uses it

  • Tasks that involve Landing pages
  • Tasks that involve Forecasting and time series

Example prompts

  • “/ga4”

Requirements

  • Python 3
  • A credential in GOOGLE_WORKSPACE_CLI_TOKEN
  • A credential in GA4_SERVICE_ACCOUNT_PRIVATE_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Start with report-plan for natural-language requests unless the user
  2. Review generated or user-supplied request JSON with review-request before
  3. For live GA4 API calls inside HybridClaw, use http_request directly when
  4. Use the helper for offline planning/review and for gateway-proxied execution
  5. Treat all GA4 operations in this skill as read-only. Do not attempt Admin

What it can do on your machine

Read from SKILL.md and the folder at commit 8162701. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • googleapis.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GA4_SERVICE_ACCOUNT_PRIVATE_KEY
    • GOOGLE_WORKSPACE_CLI_TOKEN
    • GA4_SERVICE_ACCOUNT_EMAIL_SECRET
    • GA4_SERVICE_ACCOUNT_PRIVATE_KEY_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ga4 loads about 1.9k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 584 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from HybridAIOne/hybridclaw at commit 8162701, republished under its MIT licence (© HybridAIOne). 584 words, ~1,873 tokens.

Download SKILL.mdSave it as .claude/skills/ga4/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
ga4
description
Run production Google Analytics 4 Data API reports with gateway-injected bearer auth, safe request review, traffic source, landing-page, time-series, revenue, session, and key-event reporting.
user-invocable
true
requires.bins
python3

GA4

Use this skill for Google Analytics 4 reporting through the Google Analytics Data API: sessions, key events, revenue, traffic-source breakdowns, landing-page breakdowns, time-series queries, ad-hoc analyst reads, dashboards, scheduled reporting, ETL, and monitoring.

Scope

  • run GA4 runReport requests for a configured property
  • translate common English analyst requests into reviewable Data API payloads
  • review GA4 request JSON before execution
  • build traffic-source, channel-group, landing-page, daily trend, revenue, session, user, and key-event reports
  • support delegated-user OAuth and service-account auth through the same gateway bearer handle contract
  • keep auth-mode selection in tenant/runtime config, not in prompt logic
  • measure skill run cost through normal HybridClaw UsageTotals

Default Workflow

  1. Start with report-plan for natural-language requests unless the user already supplied a GA4 Data API request JSON.
  2. Review generated or user-supplied request JSON with review-request before a live call.
  3. For live GA4 API calls inside HybridClaw, use http_request directly when available. Pass the emitted httpRequest object from the helper to the tool.
  4. Use the helper for offline planning/review and for gateway-proxied execution when http_request is unavailable:
    bash
    python3 skills/ga4/scripts/ga4.py ...
  5. Treat all GA4 operations in this skill as read-only. Do not attempt Admin API mutations, property access changes, key-event changes, or tag changes.

Auth Contract

The skill supports two auth modes without exposing tokens or private keys to the model:

  • delegated-user OAuth through a bearer secret handle
  • Google service-account JWT bearer exchange through the gateway

Tenant config decides which mode to use.

Default delegated-user OAuth handle:

bash
hybridclaw auth login google \
  --client-id "<google-oauth-client-id>" \
  --client-secret "<google-oauth-client-secret>" \
  --account you@example.com \
  --scopes "https://www.googleapis.com/auth/analytics.readonly"

hybridclaw auth status google

For delegated OAuth, use the default bearerSecretName: "GOOGLE_WORKSPACE_CLI_TOKEN" or a google-oauth URL auth route.

For service-account automation, store the service-account client_email and PEM private_key as encrypted runtime secrets. The gateway reads those named secrets, signs the JWT assertion server-side, exchanges it for a short-lived Google access token, and injects that token into the GA4 request.

Set or update those secrets in this order:

  1. Browser admin: open the active HybridClaw admin URL ending in /admin/secrets.
  2. Browser /chat or TUI fallback: /secret set GA4_SERVICE_ACCOUNT_EMAIL "<client-email>" and /secret set GA4_SERVICE_ACCOUNT_PRIVATE_KEY "<pem-private-key>".
  3. Local console fallback:
bash
hybridclaw secret set GA4_SERVICE_ACCOUNT_EMAIL "<client-email>"
hybridclaw secret set GA4_SERVICE_ACCOUNT_PRIVATE_KEY '<pem-private-key>'

Do not paste OAuth access tokens, refresh tokens, service-account private keys, or downloaded JSON key files into the prompt. Real credentials stay in the HybridClaw secret runtime and are used server-side by the gateway.

Optional stored defaults use the same setup order: browser admin at /admin/secrets, then /secret set in browser /chat or TUI, then local console fallback.

bash
hybridclaw secret set GA4_PROPERTY_ID "<numeric-property-id>"
hybridclaw secret set GA4_BEARER_SECRET_NAME "GOOGLE_WORKSPACE_CLI_TOKEN"

For unattended service-account jobs, set environment defaults in the tenant runtime:

bash
GA4_SERVICE_ACCOUNT_EMAIL_SECRET=GA4_SERVICE_ACCOUNT_EMAIL
GA4_SERVICE_ACCOUNT_PRIVATE_KEY_SECRET=GA4_SERVICE_ACCOUNT_PRIVATE_KEY
Show full SKILL.md (180 more words)Show less

Command Contract

Plan a report from natural language:

bash
python3 skills/ga4/scripts/ga4.py --format json report-plan \
  "Show me last week's organic conversions vs the prior week"

Build an http_request payload for a planned or hand-written request:

bash
python3 skills/ga4/scripts/ga4.py --format json http-request 123456789 \
  --request-json '{"dateRanges":[{"startDate":"7daysAgo","endDate":"yesterday"}],"dimensions":[{"name":"date"}],"metrics":[{"name":"sessions"}],"limit":25}'

Run a report through the gateway helper path:

bash
python3 skills/ga4/scripts/ga4.py --format json run-report 123456789 \
  --request-json '{"dateRanges":[{"startDate":"7daysAgo","endDate":"yesterday"}],"metrics":[{"name":"sessions"}]}'

Use service-account auth by choosing the stored service-account secret names:

bash
python3 skills/ga4/scripts/ga4.py --format json http-request 123456789 \
  --google-service-account-email-secret GA4_SERVICE_ACCOUNT_EMAIL \
  --google-service-account-private-key-secret GA4_SERVICE_ACCOUNT_PRIVATE_KEY \
  --request-json '{"dateRanges":[{"startDate":"7daysAgo","endDate":"yesterday"}],"metrics":[{"name":"sessions"}]}'

Review request JSON offline:

bash
python3 skills/ga4/scripts/ga4.py --format json review-request \
  '{"dateRanges":[{"startDate":"30daysAgo","endDate":"yesterday"}],"dimensions":[{"name":"landingPagePlusQueryString"}],"metrics":[{"name":"sessions"},{"name":"totalRevenue"}],"limit":25}'

Emit the analyst-query prompt-template payload:

bash
python3 skills/ga4/scripts/ga4.py --format json prompt-template \
  "Daily sessions and revenue for the last 30 days"

Run the bundled eval suite:

bash
python3 skills/ga4/scripts/ga4.py --format json eval-scenarios

Working Rules

  • Use numeric GA4 property ids. Accept properties/<id> input, but normalize it before API calls.
  • Use keyEvents for conversion-style reporting unless the user explicitly requests a custom event metric.
  • Use sessionDefaultChannelGroup, sessionSourceMedium, landingPagePlusQueryString, and date for the common production breakdowns before reaching for custom dimensions.
  • Include a row limit. Default to 25 for ad-hoc reports and increase only when the user asks for an export or ETL-sized result.
  • Ask for clarification when the request names a quarter without a year.
  • Do not add Admin API writes to this skill. A separate admin skill would need explicit approval tiers and boundary tests.

Eval Suite

The bundled scenarios cover 25 representative analyst requests across sessions, key events, revenue, traffic source, landing page, time series, comparisons, ecommerce, geographic, device, and safety/clarification cases.

© HybridAIOne, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in skills/ga4 of HybridAIOne/hybridclaw.

  • SKILL.md
  • evals/scenarios.json
  • scripts/ga4.py

Open the folder on GitHubat commit 8162701

Compare with similar skills

Ga4 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ga4 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ga4 this skillHybridAIOne/hybridclaw159—~1.9kAutomated safety check: PassMIT
Competitive Pricing Intelgooseworks-ai/goose-skills1.2k1 repos~2.2kAutomated safety check: PassMIT
Link In Bio And Trafficsocial-media-skills/skills134—~1.5kAutomated safety check: PassMIT
TimesFM Forecastinggoogle-research/timesfm34k—~4.7kAutomated safety check: PassApache-2.0
StatsmodelszLanqing/codex-claude-academic-skills4.7k15 repos~4.9kAutomated safety check: PassBSD-3-Clause
Timesfm ForecastingzLanqing/codex-claude-academic-skills4.7k3 repos~7.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Competitive Pricing Intel

    gooseworks-ai/goose-skills

    Monitor competitor pricing pages via live web scrape and Web Archive snapshots.

    1.2k GitHub starsUsed in 1 repo~2.2k tokens
    Data & AnalyticsAuto-check passed
  • Link In Bio And Traffic

    social-media-skills/skills

    Link-in-bio and traffic strategy — convert social reach into clicks, subscribers, and owned audience.

    134 GitHub stars~1.5k tokensUpdated 9 days ago
    Marketing & SEOAuto-check passed
  • TimesFM Forecasting

    google-research/timesfm

    Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.

    34k GitHub stars~4.7k tokensUpdated 11 days ago
    Data & AnalyticsAuto-check passed
  • Statsmodels

    zLanqing/codex-claude-academic-skills

    Statistical models library for Python. An agent skill from zLanqing/codex-claude-academic-skills.

    4.7k GitHub starsUsed in 15 repos~4.9k tokens
    Data & AnalyticsAuto-check passed
  • Timesfm Forecasting

    zLanqing/codex-claude-academic-skills

    Zero-shot time series forecasting with Google's TimesFM foundation model.

    4.7k GitHub starsUsed in 3 repos~7.5k tokens
    Data & AnalyticsAuto-check: notes
  • Find Hypertable Candidates

    timescale/pg-aiguide

    A skill your agent uses to analyze an existing PostgreSQL database and identify which tables should be converted to Timescale/TimescaleDB hypertables.

    1.9k GitHub starsUsed in 1 repo~2.6k tokens
    Data & AnalyticsAuto-check passed

More from HybridAIOne/hybridclaw

All 72 skills in this repo
  • Hermes3000 Writing

    HybridAIOne/hybridclaw

    Use Hermes3000 to plan, draft, revise, save, check consistency, and export long-form manuscripts through the Hermes3000 AI writing portal API.

    159 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Manim Video

    HybridAIOne/hybridclaw

    Plan, script, render, and stitch Manim Community Edition videos in Python.

    159 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Skill Creator

    HybridAIOne/hybridclaw

    Create and update SKILL.md-based skills with strong trigger metadata, lean docs, and reliable init, validate, package, and publish workflows.

    159 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • XLSX

    HybridAIOne/hybridclaw

    Create, edit, inspect, and analyze .xlsx spreadsheets and Excel workbooks.

    159 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Excalidraw

    HybridAIOne/hybridclaw

    Create and revise editable .excalidraw diagrams as Excalidraw JSON for architecture diagrams, flowcharts, sequence diagrams, concept maps, and other hand-drawn explainers.

    159 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Google Ads

    HybridAIOne/hybridclaw

    Manage Google Ads accounts with safe GAQL reporting, campaign planning, guarded mutations, and gateway-proxied REST API calls.

    159 GitHub stars~4k tokensUpdated today
    Auto-check passed

Questions about Ga4

What does Ga4 do?

Run production Google Analytics 4 Data API reports with gateway-injected bearer auth, safe request review, traffic source, landing-page, time-series, revenue, session, and key-event reporting. Ga4 is an agent skill from HybridAIOne/hybridclaw. Run production Google Analytics 4 Data API reports with gateway-injected bearer auth, safe request review, traffic source, landing-page, time-series, revenue, session, and key-event reporting.

When should I use Ga4?

Ga4 fits situations like: tasks that involve Landing pages; tasks that involve Forecasting and time series.

How do I install Ga4 in Claude Code?

Run `npx skills add HybridAIOne/hybridclaw --skill ga4 -a claude-code`. Or copy the skill folder (skills/ga4 in HybridAIOne/hybridclaw) into .claude/skills/ga4 in your project. Claude Code loads it when a task matches its description.

How do I install Ga4 in Codex?

Run `npx skills add HybridAIOne/hybridclaw --skill ga4 -a codex`. Or copy the skill folder (skills/ga4 in HybridAIOne/hybridclaw) into .agents/skills/ga4 in your project. Codex loads it when a task matches its description.

Can I use Ga4 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HybridAIOne/hybridclaw --skill ga4 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ga4, .gemini/skills/ga4, .github/skills/ga4 and .opencode/skills/ga4 in your project.

What does Ga4 need to run?

Going by SKILL.md and its folder, Ga4 needs Python for the scripts in its folder, the command-line tools its instructions call (python3) and credentials named GA4_SERVICE_ACCOUNT_PRIVATE_KEY, GOOGLE_WORKSPACE_CLI_TOKEN, GA4_SERVICE_ACCOUNT_EMAIL_SECRET and GA4_SERVICE_ACCOUNT_PRIVATE_KEY_SECRET. Our summary lists: Python 3; A credential in GOOGLE_WORKSPACE_CLI_TOKEN; A credential in GA4_SERVICE_ACCOUNT_PRIVATE_KEY.

Does Ga4 access the network?

SKILL.md names 1 domain. In commands or code: googleapis.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Ga4 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ga4 use?

Ga4 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ga4 use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ga4?

Skills that share tags, products or a category with Ga4: Competitive Pricing Intel (gooseworks-ai/goose-skills, 1.2k stars), Link In Bio And Traffic (social-media-skills/skills, 134 stars), TimesFM Forecasting (google-research/timesfm, 34k stars) and Statsmodels (zLanqing/codex-claude-academic-skills, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ga4?

HybridAIOne (a GitHub organization) maintains it in HybridAIOne/hybridclaw, which has 159 GitHub stars. The repository holds 72 skills in this directory. The repository was last updated on October 9, 2026.

Source: HybridAIOne/hybridclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.