Agent skill

Implementing Google Workspace Admin Security

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Hardens a Google Workspace tenant via Admin Console configuration: phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth third-party app control, and…

Apache-2.0Auto-check passedDocuments & Office

Install Implementing Google Workspace Admin Security

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-google-workspace-admin-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-google-workspace-admin-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-google-workspace-admin-security .claude/skills/implementing-google-workspace-admin-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-google-workspace-admin-security
GitHub stars
34k
Token cost
~4.3k tokens
SKILL.md length
615 words
Files
4 (incl. scripts, references)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Hardens a Google Workspace tenant via Admin Console configuration: phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth third-party app control, and…

  • Works in 6 steps: Harden Super Admin Accounts → Enforce Phishing-Resistant Multi-Factor… → Configure Email Authentication and… → …
  • Hardening a Google Workspace
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls openssl; reaches siem.corp.com; needs SECURITY_KEY

What it does

Implementing Google Workspace Admin Security is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Hardens a Google Workspace tenant via Admin Console configuration: phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth third-party app control, and external sharing restrictions. Use when hardening a Google Workspace or G Suite tenant, enforcing MFA and OAuth app controls, or configuring cloud office security administration.

Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Documents & Office, covering Cloud office suites. It works with Google Workspace. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Hardening a Google Workspace
  • Enforcing MFA and OAuth app controls
  • Configuring cloud office security administration

Example prompts

  • “Use the implementing-google-workspace-admin-security skill to harden a Google Workspace tenant via Admin Console configuration: phishing-resistant…”
  • “/implementing-google-workspace-admin-security”

Requirements

  • Python 3
  • A credential in SECURITY_KEY

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Harden Super Admin Accounts
  2. Enforce Phishing-Resistant Multi-Factor Authentication
  3. Configure Email Authentication and Anti-Phishing
  4. Implement Data Loss Prevention (DLP)
  5. Control OAuth Applications and Third-Party Access
  6. Configure External Sharing and Drive Security

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • siem.corp.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECURITY_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Google Workspace Admin Security loads about 4.3k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 615 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~4.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 615 words, ~4,317 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-google-workspace-admin-security/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-google-workspace-admin-security
description
Hardens a Google Workspace tenant via Admin Console configuration: phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth third-party app control, and external sharing restrictions. Use when hardening a Google Workspace or G Suite tenant, enforcing MFA and OAuth app controls, or configuring cloud office security administration.
domain
cybersecurity
subdomain
identity-access-management
tags
Google-Workspace, admin-security, MFA, DMARC, DLP, OAuth, cloud-security
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.AA-01, PR.AA-02, PR.AA-05, PR.AA-06
mitre_attack
T1078, T1110, T1556, T1098, T1566
mitre_f3.version
1.1
mitre_f3.tactics
initial-access, stealth, positioning

Implementing Google Workspace Admin Security

When to Use

  • Deploying or hardening a Google Workspace environment for enterprise use
  • CIS benchmark compliance assessment for Google Workspace configuration
  • Protecting against business email compromise (BEC) and phishing attacks targeting Google accounts
  • Implementing Data Loss Prevention controls for Gmail and Google Drive
  • Restricting OAuth application access and third-party integrations
  • Configuring admin account security with Advanced Protection Program enrollment

Do not use for Microsoft 365 environments; Google Workspace has distinct admin console settings and API configurations that differ from Azure AD/Entra ID controls.

Prerequisites

  • Google Workspace Business Plus, Enterprise Standard, or Enterprise Plus license
  • Super Admin access to the Google Admin Console (admin.google.com)
  • DNS management access for SPF, DKIM, and DMARC record configuration
  • Google Cloud Identity or Cloud Identity Premium for advanced security features
  • FIDO2 security keys for super admin accounts (YubiKey 5 Series recommended)

Workflow

Step 1: Harden Super Admin Accounts

Secure the highest-privilege accounts in the Google Workspace tenant:

bash
# Google Workspace Admin SDK - configure admin account security
# Using gam (Google Apps Manager) CLI tool

# List all super admin accounts for audit
gam print admins role "Super Admin" > super_admins.csv
echo "Review and minimize super admin count (recommended: 2-3 maximum)"

# Enforce Advanced Protection Program for super admins
# APP provides strongest account protections:
# - Requires FIDO2 security key for sign-in
# - Blocks third-party app access to Gmail and Drive
# - Enhanced account recovery verification
gam update user superadmin@corp.com \
    advanced_protection true

# Create dedicated break-glass admin account
gam create user breakglass-admin@corp.com \
    firstname "Break" lastname "Glass Admin" \
    password "$(openssl rand -base64 32)" \
    changepassword true \
    org "/Emergency Accounts"

# Assign super admin role to break-glass account
gam create admin breakglass-admin@corp.com "Super Admin"

# Configure admin activity alerts
# Alert Center API - create alert for admin actions
cat > admin_alert_policy.json << 'EOF'
{
  "alertPolicies": [
    {
      "name": "Super Admin Sign-In Alert",
      "conditions": {
        "eventType": "login",
        "filterCriteria": "actor.adminRole=SUPER_ADMIN"
      },
      "notifications": {
        "email": ["security-team@corp.com"],
        "webhook": "https://siem.corp.com/webhook/google-admin"
      }
    },
    {
      "name": "Admin Role Change Alert",
      "conditions": {
        "eventType": "admin_role_change"
      },
      "notifications": {
        "email": ["security-team@corp.com"]
      }
    }
  ]
}
EOF
Step 2: Enforce Phishing-Resistant Multi-Factor Authentication

Configure MFA policies that eliminate phishable authentication factors:

bash
# Enforce 2-Step Verification for all organizational units
# Using Admin SDK Directory API

# Enable 2SV enforcement for the entire organization
gam update org "/" settings \
    2sv_enforcement true \
    2sv_enrollment_grace_period 14 \
    2sv_new_user_enrollment_period 1

# Configure allowed 2SV methods - restrict to phishing-resistant only
# For high-security OUs: Security keys only
gam update org "/Executive" settings \
    2sv_allowed_methods "SECURITY_KEY_ONLY"

# For general staff: Security keys or phone prompts (no SMS/voice)
gam update org "/" settings \
    2sv_allowed_methods "SECURITY_KEY,PHONE_PROMPT" \
    2sv_disallowed_methods "SMS,VOICE_CALL,BACKUP_CODES"

# Bulk check 2SV enrollment status
gam print users \
    fields primaryEmail,isEnrolledIn2Sv,isEnforcedIn2Sv \
    query "isEnrolledIn2Sv=false" > users_without_2sv.csv

# Count users without 2SV
echo "Users without 2SV enrolled:"
wc -l < users_without_2sv.csv

# Configure context-aware access policies
# Require 2SV + managed device for sensitive apps
cat > context_aware_policy.json << 'EOF'
{
  "accessLevels": [
    {
      "name": "Managed Device Required",
      "conditions": {
        "devicePolicy": {
          "requireScreenLock": true,
          "requireAdminApproval": true,
          "allowedEncryptionStatuses": ["ENCRYPTED"],
          "requireCorpOwned": false
        },
        "requiredAccessLevels": ["VERIFIED_2SV"]
      }
    }
  ],
  "applicationPolicies": [
    {
      "applications": ["Google Drive", "Gmail", "Admin Console"],
      "accessLevel": "Managed Device Required"
    }
  ]
}
EOF
Step 3: Configure Email Authentication and Anti-Phishing

Set up SPF, DKIM, DMARC and advanced phishing protections:

bash
# Step 3a: Configure SPF record
# Add to DNS TXT record for corp.com
echo 'DNS TXT Record for SPF:'
echo 'corp.com TXT "v=spf1 include:_spf.google.com ~all"'
echo ''
echo 'After testing, change ~all to -all (hard fail) for enforcement'

# Step 3b: Generate and configure DKIM signing
# Generate 2048-bit DKIM key via Admin Console or API
gam create dkim domain corp.com selector google bitlength 2048

echo 'Add DKIM DNS TXT record:'
echo 'google._domainkey.corp.com TXT "v=DKIM1; k=rsa; p=<public_key_from_admin_console>"'

# Verify DKIM is working
gam info dkim domain corp.com

# Step 3c: Configure DMARC policy
echo 'DNS TXT Record for DMARC (start with monitoring):'
echo '_dmarc.corp.com TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@corp.com; ruf=mailto:dmarc-forensics@corp.com; pct=100; adkim=s; aspf=s"'
echo ''
echo 'After 30 days monitoring, escalate to quarantine then reject:'
echo '_dmarc.corp.com TXT "v=DMARC1; p=reject; rua=mailto:dmarc-reports@corp.com; pct=100; adkim=s; aspf=s"'

# Step 3d: Enable advanced phishing and malware protection
# Configure in Admin Console > Security > Email Safety
gam update settings email_safety \
    protect_against_domain_spoofing true \
    protect_against_employee_spoofing true \
    protect_against_inbound_spoofing true \
    protect_unauthenticated_email true \
    identify_spoofed_groups true \
    auto_move_suspicious_to_spam true

# Configure attachment security
gam update settings email_safety \
    protect_encrypted_attachments true \
    protect_anomalous_attachment_types true \
    protect_scripts_from_untrusted true \
    whitelist_sender_domains "" \
    apply_future_recommended_settings true
Step 4: Implement Data Loss Prevention (DLP)

Configure DLP rules to prevent sensitive data exfiltration:

bash
# Create DLP rules for Gmail and Drive
# Using Google Workspace DLP API

cat > dlp_rules.json << 'EOF'
{
  "dlpRules": [
    {
      "name": "PII Detection - SSN",
      "description": "Detect Social Security Numbers in outbound email and Drive sharing",
      "trigger": {
        "contentMatchers": [
          {
            "infoType": "US_SOCIAL_SECURITY_NUMBER",
            "likelihood": "LIKELY",
            "minMatchCount": 1
          }
        ],
        "scope": ["GMAIL_OUTBOUND", "DRIVE_EXTERNAL_SHARE"]
      },
      "action": {
        "blockAction": "QUARANTINE",
        "notifyAdmin": true,
        "notifyUser": true,
        "userMessage": "This message contains a Social Security Number and has been quarantined for review.",
        "auditLog": true
      }
    },
    {
      "name": "Credit Card Number Detection",
      "description": "Block credit card numbers in outbound communications",
      "trigger": {
        "contentMatchers": [
          {
            "infoType": "CREDIT_CARD_NUMBER",
            "likelihood": "LIKELY",
            "minMatchCount": 1
          }
        ],
        "scope": ["GMAIL_OUTBOUND", "DRIVE_EXTERNAL_SHARE", "CHAT"]
      },
      "action": {
        "blockAction": "BLOCK",
        "notifyAdmin": true,
        "notifyUser": true,
        "auditLog": true
      }
    },
    {
      "name": "Confidential Document Detection",
      "description": "Detect documents marked as Confidential or Internal Only",
      "trigger": {
        "contentMatchers": [
          {
            "customRegex": "(?i)(CONFIDENTIAL|INTERNAL ONLY|DO NOT DISTRIBUTE|RESTRICTED)",
            "minMatchCount": 2
          }
        ],
        "metadataMatchers": [
          {
            "driveLabels": ["Confidential", "Restricted"]
          }
        ],
        "scope": ["DRIVE_EXTERNAL_SHARE"]
      },
      "action": {
        "blockAction": "WARN",
        "requireJustification": true,
        "auditLog": true
      }
    }
  ]
}
EOF

echo "Apply DLP rules via Admin Console > Security > Data Protection"
echo "Or use the Google Workspace DLP API for programmatic deployment"
Step 5: Control OAuth Applications and Third-Party Access

Restrict which third-party applications can access organizational data:

bash
# Configure OAuth app access control
# Admin Console > Security > API Controls > App Access Control

# Block all third-party apps by default, then allowlist approved ones
gam update org "/" settings \
    third_party_app_access "BLOCKED" \
    allow_users_to_install_apps false

# Allowlist approved applications
cat > approved_apps.json << 'EOF'
{
  "allowedApps": [
    {
      "appId": "slack-app-id",
      "name": "Slack",
      "scopes": ["gmail.readonly", "calendar.readonly"],
      "approvedBy": "security-team",
      "reviewDate": "2026-01-15"
    },
    {
      "appId": "zoom-app-id",
      "name": "Zoom",
      "scopes": ["calendar.events"],
      "approvedBy": "security-team",
      "reviewDate": "2026-01-15"
    },
    {
      "appId": "salesforce-app-id",
      "name": "Salesforce",
      "scopes": ["gmail.send", "contacts.readonly"],
      "approvedBy": "security-team",
      "reviewDate": "2026-01-15"
    }
  ]
}
EOF

# Audit current OAuth tokens granted by users
gam all users print tokens > oauth_tokens_audit.csv
echo "Review oauth_tokens_audit.csv for unauthorized third-party access"

# Revoke tokens for unapproved applications
gam all users deprovision tokens \
    clientid "unapproved-app-client-id"

# Configure API scopes restriction
# Limit which API scopes third-party apps can request
gam update org "/" settings \
    api_access_restricted true \
    allowed_api_scopes "gmail.readonly,calendar.readonly,drive.readonly"
Step 6: Configure External Sharing and Drive Security

Lock down data sharing controls:

bash
# Configure Google Drive sharing restrictions
gam update org "/" settings \
    drive_sharing_outside_domain "WHITELISTED_DOMAINS" \
    drive_sharing_whitelisted_domains "partner1.com,partner2.com" \
    drive_allow_file_requests false \
    drive_shared_drive_creation "ADMIN_ONLY" \
    drive_default_link_sharing "RESTRICTED"

# Configure sharing alerts
gam create alert \
    name "External Sharing Alert" \
    type "drive_external_share" \
    condition "shared_outside_domain=true AND file_type IN ('spreadsheet','document','presentation')" \
    action "notify_admin security-team@corp.com"

# Audit current external shares
gam all users print filelist \
    fields id,name,owners,permissions \
    query "visibility='anyoneWithLink' or visibility='anyoneCanFind'" \
    > external_shares_audit.csv

echo "External shares requiring review:"
wc -l < external_shares_audit.csv

# Configure Google Groups security
gam update org "/" settings \
    groups_external_members false \
    groups_external_posting false \
    groups_creation "ADMIN_ONLY" \
    groups_allow_external_invitations false

Key Concepts

TermDefinition
Advanced Protection Program (APP)Google's strongest account security requiring FIDO2 security keys, blocking third-party app access, and enhanced identity verification for account recovery
Context-Aware AccessSecurity policy framework that evaluates device posture, location, and user identity before granting access to Google Workspace applications
DMARCDomain-based Message Authentication, Reporting and Conformance protocol that prevents email domain spoofing by validating SPF and DKIM alignment
DLP RuleData Loss Prevention policy that scans content in Gmail, Drive, and Chat for sensitive data patterns and triggers block, quarantine, or warn actions
OAuth App AllowlistingAdmin control restricting which third-party applications can access organizational data through Google OAuth API scopes
2-Step Verification (2SV)Google's multi-factor authentication implementation supporting security keys, phone prompts, TOTP, and backup codes as second factors
Show full SKILL.md (257 more words)Show less

Tools & Systems

  • Google Admin Console: Web-based administration portal for managing all Google Workspace security settings, users, and organizational units
  • GAM (Google Apps Manager): Open-source command-line tool for bulk Google Workspace administration and automation
  • Google Workspace Alert Center: Centralized dashboard for security alerts including suspicious login activity, DLP violations, and device compromise
  • Google BeyondCorp Enterprise: Zero-trust access solution integrated with Google Workspace for context-aware access policies

Common Scenarios

Scenario: Securing a Newly Acquired Google Workspace Tenant

Context: Post-acquisition security audit reveals the acquired company's Google Workspace has no MFA enforcement, open external sharing, no DLP policies, and multiple unauthorized OAuth applications accessing user data.

Approach:

  1. Immediately enforce 2SV for all super admin accounts using FIDO2 security keys
  2. Reduce super admin count to 3 (primary, secondary, break-glass)
  3. Deploy SPF, DKIM, and DMARC starting with monitoring mode (p=none)
  4. Enable all anti-phishing and anti-spoofing settings in Email Safety
  5. Audit and revoke all unauthorized OAuth application tokens
  6. Set third-party app access to blocked with allowlist of approved applications
  7. Restrict external Drive sharing to approved partner domains only
  8. Deploy DLP rules for PII, financial data, and confidential documents
  9. Enable context-aware access requiring managed devices for sensitive applications
  10. Configure security alerts and SIEM integration for ongoing monitoring

Pitfalls:

  • Enforcing MFA without enrollment grace period locks users out of accounts
  • Setting DMARC to reject before monitoring period causes legitimate email delivery failures
  • Blocking all OAuth apps without identifying business-critical integrations disrupts workflows
  • Not auditing existing external shares before restricting sharing leaves data exposed

Output Format

GOOGLE WORKSPACE SECURITY ASSESSMENT REPORT
=============================================
Tenant:            corp.com
License:           Enterprise Plus
Total Users:       3,847
Organizational Units: 12

AUTHENTICATION SECURITY
2SV Enforced:           YES (all OUs)
2SV Enrollment:         3,712 / 3,847 (96.5%)
Security Keys Only:     Executive OU (47 users)
Advanced Protection:    3 super admin accounts
Super Admin Count:      3 (within recommended limit)

EMAIL AUTHENTICATION
SPF:                    CONFIGURED (hard fail: -all)
DKIM:                   CONFIGURED (2048-bit, selector: google)
DMARC:                  ENFORCED (p=reject, 100%)
Anti-Phishing:          ALL PROTECTIONS ENABLED
Anti-Spoofing:          ENABLED (domain + employee name)

DATA PROTECTION
DLP Rules Active:       7
  PII Detection:        SSN, Credit Card, Passport
  Content Labels:       Confidential, Restricted
  Custom Patterns:      3 organization-specific rules
DLP Violations (30d):   89 (67 blocked, 22 warned)

APPLICATION CONTROL
Third-Party App Policy: BLOCKED (allowlist mode)
Approved Apps:          12
Unauthorized Tokens:    0 (all revoked)
API Scope Restrictions: ENABLED

SHARING CONTROLS
External Sharing:       RESTRICTED (allowlisted domains only)
Public Link Sharing:    DISABLED
External Group Members: DISABLED
Shared Drive Creation:  ADMIN ONLY

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-google-workspace-admin-security of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Google Workspace Admin Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Google Workspace Admin Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Google Workspace Admin Security this skillmukul975/Anthropic-Cybersecurity-Skills34k—~4.3kAutomated safety check: PassApache-2.0
Google WorkspaceNousResearch/hermes-agent252k3 repos~3.5kAutomated safety check: PassMIT
Google WorkspaceTommy-yw/RunbookHermes5462 repos~2.7kAutomated safety check: PassMIT
Community Google WorkspaceArgentAIOS/argentos-core126—~2.8kAutomated safety check: PassMIT
Google Workspacegoogle/adk-recipes10k—~4.6kAutomated safety check: PassApache-2.0
Gws Installjezweb/claude-skills1.1k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Google Workspace

    NousResearch/hermes-agent

    Gmail, Calendar, Drive, Docs, Sheets via gws CLI or Python. An agent skill from NousResearch/hermes-agent.

    252k GitHub starsUsed in 3 repos~3.5k tokens
    Documents & OfficeAuto-check passed
  • Google Workspace

    Tommy-yw/RunbookHermes

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration for Hermes.

    546 GitHub starsUsed in 2 repos~2.7k tokens
    Documents & OfficeAuto-check passed
  • Community Google Workspace

    ArgentAIOS/argentos-core

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration for community skills.

    126 GitHub stars~2.8k tokensUpdated 3 mo ago
    Documents & OfficeAuto-check passed
  • Google Workspace

    google/adk-recipes

    Official

    Read/write Google Drive, Docs, Sheets, Gmail, Calendar, Chat, Tasks, Slides via the gws CLI.

    10k GitHub stars~4.6k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Gws Install

    jezweb/claude-skills

    Quick install of the Google Workspace CLI (gws) on an additional machine using existing OAuth credentials.

    1.1k GitHub stars~1.1k tokensUpdated 3 days ago
    Documents & OfficeAuto-check passed
  • Gws Setup

    jezweb/claude-skills

    Set up the Google Workspace CLI (gws) from scratch. An agent skill from jezweb/claude-skills.

    1.1k GitHub stars~2.3k tokensUpdated 3 days ago
    Documents & OfficeAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing Google Workspace Admin Security

What does Implementing Google Workspace Admin Security do?

Hardens a Google Workspace tenant via Admin Console configuration: phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth third-party app control, and…. Implementing Google Workspace Admin Security is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Hardens a Google Workspace tenant via Admin Console configuration: phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth third-party app control, and external sharing restrictions.

When should I use Implementing Google Workspace Admin Security?

Implementing Google Workspace Admin Security fits situations like: hardening a Google Workspace; enforcing MFA and OAuth app controls; configuring cloud office security administration.

How do I install Implementing Google Workspace Admin Security in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-google-workspace-admin-security -a claude-code`. Or copy the skill folder (skills/implementing-google-workspace-admin-security in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-google-workspace-admin-security in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Google Workspace Admin Security in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-google-workspace-admin-security -a codex`. Or copy the skill folder (skills/implementing-google-workspace-admin-security in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-google-workspace-admin-security in your project. Codex loads it when a task matches its description.

Can I use Implementing Google Workspace Admin Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-google-workspace-admin-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-google-workspace-admin-security, .gemini/skills/implementing-google-workspace-admin-security, .github/skills/implementing-google-workspace-admin-security and .opencode/skills/implementing-google-workspace-admin-security in your project.

What does Implementing Google Workspace Admin Security need to run?

Going by SKILL.md and its folder, Implementing Google Workspace Admin Security needs Python for the scripts in its folder, the command-line tools its instructions call (openssl) and credentials named SECURITY_KEY. Our summary lists: Python 3; A credential in SECURITY_KEY.

Does Implementing Google Workspace Admin Security access the network?

SKILL.md names 1 domain. In commands or code: siem.corp.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Implementing Google Workspace Admin Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Google Workspace Admin Security use?

Implementing Google Workspace Admin Security is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Google Workspace Admin Security use?

About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 558 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Google Workspace Admin Security?

Skills that share tags, products or a category with Implementing Google Workspace Admin Security: Google Workspace (NousResearch/hermes-agent, 252k stars), Google Workspace (Tommy-yw/RunbookHermes, 546 stars), Community Google Workspace (ArgentAIOS/argentos-core, 126 stars) and Google Workspace (google/adk-recipes, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Google Workspace Admin Security?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.