Agent skill

Implementing Google Workspace Phishing Protection

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Configures Google Workspace advanced phishing and malware protection settings in the Admin Console — pre-delivery message scanning, attachment protection, spoofing/impersonation detection, and…

Apache-2.0Auto-check passedDocuments & Office

Install Implementing Google Workspace Phishing Protection

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-google-workspace-phishing-protection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-google-workspace-phishing-protection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-google-workspace-phishing-protection .claude/skills/implementing-google-workspace-phishing-protection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-google-workspace-phishing-protection
GitHub stars
34k
Token cost
~1.4k tokens
SKILL.md length
534 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configures Google Workspace advanced phishing and malware protection settings in the Admin Console — pre-delivery message scanning, attachment protection, spoofing/impersonation detection, and…

  • Works in 6 steps: Configure Advanced Phishing Protection → Enable Enhanced Pre-Delivery Scanning → Configure Attachment Protection → …
  • Hardening Gmail against phishing
  • SKILL.md covers Overview, When to Use, Prerequisites and Workflow, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Implementing Google Workspace Phishing Protection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Configures Google Workspace advanced phishing and malware protection settings in the Admin Console — pre-delivery message scanning, attachment protection, spoofing/impersonation detection, and Enhanced Safe Browsing enforcement. Use when hardening Gmail against phishing, spoofing, and malware, or when tuning Workspace email security policies.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Documents & Office, covering Cloud office suites and Email management. It works with Google Workspace and Gmail. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Hardening Gmail against phishing
  • Tuning Workspace email security policies

Example prompts

  • “Use the implementing-google-workspace-phishing-protection skill to configure Google Workspace advanced phishing and malware protection settings in…”
  • “/implementing-google-workspace-phishing-protection”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Configure Advanced Phishing Protection
  2. Enable Enhanced Pre-Delivery Scanning
  3. Configure Attachment Protection
  4. Enable Enhanced Safe Browsing
  5. Enroll High-Risk Users in Advanced Protection Program
  6. Configure Email Authentication

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Google Workspace Phishing Protection loads about 1.4k tokens when it runs, and up to ~2.6k if it reads all its reference files. Until then it costs about 99 tokens; SKILL.md has 534 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 534 words, ~1,443 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-google-workspace-phishing-protection/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-google-workspace-phishing-protection
description
Configures Google Workspace advanced phishing and malware protection settings in the Admin Console — pre-delivery message scanning, attachment protection, spoofing/impersonation detection, and Enhanced Safe Browsing enforcement. Use when hardening Gmail against phishing, spoofing, and malware, or when tuning Workspace email security policies.
domain
cybersecurity
subdomain
phishing-defense
tags
google-workspace, gmail, phishing, email-security, safe-browsing, anti-spoofing, admin-console
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.AT-01, DE.CM-09, RS.CO-02, DE.AE-02
mitre_attack
T1566, T1598, T1534, T1036, T1027
mitre_f3.version
1.1
mitre_f3.tactics
reconnaissance, resource-development, initial-access, stealth

Implementing Google Workspace Phishing Protection

Overview

Google Workspace provides advanced phishing and malware protection through the Admin Console under Apps > Google Workspace > Gmail > Safety. Key features include Enhanced Pre-Delivery Scanning that examines messages more thoroughly before they reach inboxes, attachment and link protection that scans for malware and checks against known malicious sites, and spoofing detection for domain and employee name impersonation. Google's Advanced Protection Program (APP) provides the strongest account security for high-privilege users.

When to Use

  • When deploying or configuring implementing google workspace phishing protection capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Google Workspace Business Standard or higher license
  • Gmail Settings administrator privilege
  • Understanding of organizational email flow and third-party integrations
  • Access to Google Admin Console (admin.google.com)
  • DNS management access for SPF, DKIM, DMARC configuration

Workflow

Step 1: Configure Advanced Phishing Protection
  • Navigate to Admin Console > Apps > Google Workspace > Gmail > Safety
  • Enable "Protect against domain spoofing based on similar domain names"
  • Enable "Protect against spoofing of employee names"
  • Enable "Protect against inbound emails spoofing your domain"
  • Set action for detected spoofing: quarantine or move to spam with warning banner
  • Apply settings to all organizational units or specific high-risk groups
Step 2: Enable Enhanced Pre-Delivery Scanning
  • In Safety settings, enable "Enhanced pre-delivery message scanning"
  • This adds additional delay (seconds) to scan messages more thoroughly
  • Configure to detect phishing attempts that evade initial filters
  • Enable "Identify links behind shortened URLs"
  • Enable "Scan linked images" for image-based phishing detection
Step 3: Configure Attachment Protection
  • Enable "Protect against encrypted attachments from untrusted senders"
  • Enable "Protect against attachments with scripts from untrusted senders"
  • Enable "Protect against anomalous attachment types in emails"
  • Configure action: warn users, move to spam, or quarantine
  • Create exceptions for known legitimate encrypted file senders
Show full SKILL.md (226 more words)Show less
Step 4: Enable Enhanced Safe Browsing
  • Navigate to Admin Console > Security > Gmail Enhanced Safe Browsing
  • Enable Enhanced Safe Browsing for the organization (off by default)
  • This provides real-time protection against phishing URLs in emails
  • Configure at organizational unit level for phased rollout
  • Monitor user feedback for false positive impact
Step 5: Enroll High-Risk Users in Advanced Protection Program
  • Identify high-privilege accounts: super admins, executives, finance leadership
  • Enroll users in Google's Advanced Protection Program (APP)
  • APP requires FIDO2 security keys for authentication
  • APP blocks third-party app access unless explicitly approved
  • APP provides enhanced scanning for Gmail and Drive downloads
Step 6: Configure Email Authentication
  • Publish SPF record: v=spf1 include:_spf.google.com ~all
  • Enable DKIM signing in Admin Console > Apps > Google Workspace > Gmail > Authenticate email
  • Configure DMARC with monitoring: v=DMARC1; p=none; rua=mailto:dmarc@company.com
  • Progress DMARC to enforcement per organizational readiness

Tools & Resources

  • Google Admin Console: Central management for all security settings
  • Google Workspace Security Investigation Tool: Threat analysis and response
  • Google Security Center: Security health recommendations and dashboard
  • Gmail Security Sandbox: Attachment detonation for enterprise licenses
  • Google Advanced Protection Program: Strongest account security

Validation

  • Spoofing protection blocks test email with lookalike domain
  • Pre-delivery scanning catches test phishing with delayed weaponization
  • Attachment protection warns on test encrypted attachment
  • Enhanced Safe Browsing blocks known phishing URL clicked in email
  • APP-enrolled accounts reject non-FIDO2 authentication attempts
  • SPF, DKIM, DMARC all pass for outbound messages

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-google-workspace-phishing-protection of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Google Workspace Phishing Protection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Google Workspace Phishing Protection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Google Workspace Phishing Protection this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.4kAutomated safety check: PassApache-2.0
Managing Google Workspacetaylorwilsdon/google_workspace_mcp3.3k—~2.9kAutomated safety check: PassMIT
Google Workspacemitsuhiko/agent-stuff3.2k—~919Automated safety check: PassApache-2.0
Extrasuitethink41/extrasuite166—~421Automated safety check: PassMIT
Community Google WorkspaceArgentAIOS/argentos-core126—~2.8kAutomated safety check: PassMIT
Google WorkspaceTommy-yw/RunbookHermes5461 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Managing Google Workspace

    taylorwilsdon/google_workspace_mcp

    Manages Google Workspace operations across 12 services (Gmail, Drive, Calendar, Docs, Sheets, Slides, Forms, Tasks, Contacts, Chat, Apps Script, Custom Search).

    3.3k GitHub stars~2.9k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Google Workspace

    mitsuhiko/agent-stuff

    Access Google Workspace APIs (Drive, Docs, Calendar, Gmail, Sheets, Slides, Chat, People) via local helper scripts without MCP.

    3.2k GitHub stars~919 tokensUpdated 12 days ago
    Documents & OfficeAuto-check passed
  • Extrasuite

    think41/extrasuite

    CRUD on google workspace files - Sheets, Slides, Docs, Forms.

    166 GitHub stars~421 tokensUpdated 5 mo ago
    Documents & OfficeAuto-check passed
  • Community Google Workspace

    ArgentAIOS/argentos-core

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration for community skills.

    126 GitHub stars~2.8k tokensUpdated 3 mo ago
    Documents & OfficeAuto-check passed
  • Google Workspace

    Tommy-yw/RunbookHermes

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration for Hermes.

    546 GitHub starsUsed in 1 repo~2.7k tokens
    Documents & OfficeAuto-check passed
  • Gog CLI

    intellectronica/agent-skills

    A skill your agent uses whenever the user wants to operate Google Workspace from the command line with gog/gogcli, including Gmail, Calendar, Drive, Docs, Sheets, Slides, Forms, Apps Script, Chat…

    295 GitHub stars~2.2k tokensUpdated 5 mo ago
    Documents & OfficeAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing Google Workspace Phishing Protection

What does Implementing Google Workspace Phishing Protection do?

Configures Google Workspace advanced phishing and malware protection settings in the Admin Console — pre-delivery message scanning, attachment protection, spoofing/impersonation detection, and…. Implementing Google Workspace Phishing Protection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Configures Google Workspace advanced phishing and malware protection settings in the Admin Console — pre-delivery message scanning, attachment protection, spoofing/impersonation detection, and Enhanced Safe Browsing enforcement.

When should I use Implementing Google Workspace Phishing Protection?

Implementing Google Workspace Phishing Protection fits situations like: hardening Gmail against phishing; tuning Workspace email security policies.

How do I install Implementing Google Workspace Phishing Protection in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-google-workspace-phishing-protection -a claude-code`. Or copy the skill folder (skills/implementing-google-workspace-phishing-protection in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-google-workspace-phishing-protection in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Google Workspace Phishing Protection in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-google-workspace-phishing-protection -a codex`. Or copy the skill folder (skills/implementing-google-workspace-phishing-protection in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-google-workspace-phishing-protection in your project. Codex loads it when a task matches its description.

Can I use Implementing Google Workspace Phishing Protection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-google-workspace-phishing-protection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-google-workspace-phishing-protection, .gemini/skills/implementing-google-workspace-phishing-protection, .github/skills/implementing-google-workspace-phishing-protection and .opencode/skills/implementing-google-workspace-phishing-protection in your project.

What does Implementing Google Workspace Phishing Protection need to run?

Going by SKILL.md and its folder, Implementing Google Workspace Phishing Protection needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Google Workspace Phishing Protection access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Google Workspace Phishing Protection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Google Workspace Phishing Protection use?

Implementing Google Workspace Phishing Protection is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Google Workspace Phishing Protection use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Google Workspace Phishing Protection?

Skills that share tags, products or a category with Implementing Google Workspace Phishing Protection: Managing Google Workspace (taylorwilsdon/google_workspace_mcp, 3.3k stars), Google Workspace (mitsuhiko/agent-stuff, 3.2k stars), Extrasuite (think41/extrasuite, 166 stars) and Community Google Workspace (ArgentAIOS/argentos-core, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Google Workspace Phishing Protection?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.