Google Workspace
NousResearch/hermes-agent
Gmail, Calendar, Drive, Docs, Sheets via gws CLI or Python. An agent skill from NousResearch/hermes-agent.
gog CLI: safe Google Workspace automation, JSON, auth, scoped reads/writes.
$ npx skills add openclaw/gogcli --skill gog -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openclaw/gogcli gog --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openclaw/gogcli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/gog .claude/skills/gog && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gog" agent skill from https://github.com/openclaw/gogcli/tree/main/.agents/skills/gog into .claude/skills/gog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gog", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openclaw/gogcli/tree/main/.agents/skills/gogType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openclaw/gogcli --skill gog -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openclaw/gogcli gog --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/gogcli.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/gog .agents/skills/gog && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gog" agent skill from https://github.com/openclaw/gogcli/tree/main/.agents/skills/gog into .agents/skills/gog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gog", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/gogcli --skill gog -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openclaw/gogcli gog --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/gogcli.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/gog .cursor/skills/gog && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gog" agent skill from https://github.com/openclaw/gogcli/tree/main/.agents/skills/gog into .cursor/skills/gog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gog", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openclaw/gogcli.git --path .agents/skills/gog--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openclaw/gogcli --skill gog -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openclaw/gogcli gog --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/gogcli.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/gog .gemini/skills/gog && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gog" agent skill from https://github.com/openclaw/gogcli/tree/main/.agents/skills/gog into .gemini/skills/gog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gog", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openclaw/gogcli gogInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openclaw/gogcli --skill gog -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openclaw/gogcli.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/gog .github/skills/gog && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gog" agent skill from https://github.com/openclaw/gogcli/tree/main/.agents/skills/gog into .github/skills/gog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gog", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/gogcli --skill gog -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openclaw/gogcli gog --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/gogcli.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/gog .opencode/skills/gog && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gog" agent skill from https://github.com/openclaw/gogcli/tree/main/.agents/skills/gog into .opencode/skills/gog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gog", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
goggog CLI: safe Google Workspace automation, JSON, auth, scoped reads/writes.
Gog is an agent skill from openclaw/gogcli. gog CLI: safe Google Workspace automation, JSON, auth, scoped reads/writes.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Documents & Office, covering Cloud office suites. It works with Google Workspace. The repository describes itself as: Google Workspace in your terminal. The licence is MIT.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4d7478e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
mail.google.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GOG_KEYRING_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gog loads about 2.9k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 1,160 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openclaw/gogcli at commit 4d7478e, republished under its MIT licence (© openclaw). 1,160 words, ~2,896 tokens.
.claude/skills/gog/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use gog when built-in Google connectors are missing a feature, when shell
automation needs stable JSON, or when you need to inspect local Google auth
state before acting.
gog --version
gog auth list --check --json --no-input
gog auth doctor --check --json --no-input
GOG_HELP=agent gog --help
gog schema --jsonGOG_HELP=agent makes root help emit a compact automation contract and common
read-only recipes; commands and behavior stay unchanged. Machine output,
non-interactive behavior, stable exit codes, command guards, and
untrusted-content wrapping apply across the CLI. schema exposes command
syntax, stable exit codes, and effective safety state for automation.
For JSON output projection, --fields is accepted as an alias for --select on
commands that do not define their own API field-mask --fields; commands with a
local field-mask flag keep that command-specific meaning.
--results-only unwraps the primary result before --select projects it. For
lists, select item-relative fields: --results-only --select id. Dot paths do
not broadcast through nested arrays (--select items.id selects nothing).
Unmatched object fields are omitted.
Pick the account explicitly for API work:
gog --readonly --account user@example.com gmail search 'newer_than:7d' --json --wrap-untrustedPrefer --json --wrap-untrusted for agent parsing when reading Google content.
Human hints and progress should stay on stderr; stdout is for data.
GOG_KEYRING_PASSWORD is provided by a shell startup file or service
environment, use the matching shell/entrypoint so gog can unlock the file
keyring non-interactively. Do not print the value.GOG_KEYRING_BACKEND=file, GOG_KEYRING_PASSWORD, and HOME must be
present in the process that launches gog.--no-input in automation so auth/keyring prompts fail clearly.--dry-run first where commands support it.--readonly for tasks that must not mutate Google data; remove it only
for the exact write the user approved.--force; do not add it unless the user asked
for that exact mutation.--gmail-no-send or GOG_GMAIL_NO_SEND=1 unless sending mail is the
requested task.docs/safety-profiles.md.Runtime command guards:
gog --readonly --enable-commands gmail.search,gmail.get --gmail-no-send \
--account user@example.com gmail search 'from:example@example.com' --json
gog --enable-commands drive.ls,docs.cat --disable-commands drive.delete \
--account user@example.com drive ls --max 10 --jsonOAuth setup is partly interactive. An agent can inspect and diagnose it, but a human normally completes browser consent:
gog auth credentials list
gog auth add user@example.com --services all-user --force-consent
gog auth remove user@example.comDefault for existing human/user OAuth reauth: preserve broad service access.
Before reauth, run gog auth list --check --json --no-input and inspect the
account's existing services. When replacing an expired or revoked token, do
not silently reduce scope; prefer --services all-user --force-consent unless
the user explicitly asks for narrower scopes.
Use narrow services only for throwaway/test accounts, service-specific bot
accounts, explicit user requests, or scoped security experiments. Safety should
normally be enforced at command time with --enable-commands,
--disable-commands, --gmail-no-send, dry-runs, and account selection, not by
under-scoping durable user auth.
Service accounts are Workspace-only and mainly fit Admin, Groups, Keep, and
domain-wide delegation flows; they do not solve consumer @gmail.com OAuth.
For OpenClaw/systemd setups, run the diagnostic through the actual agent entrypoint after restarting the service:
openclaw agent --agent main --message \
'Run: gog auth doctor --check --no-input && gog gmail search "newer_than:1d" --max 1 --json'If this fails with keyring.password while the same gog auth doctor works in
the shell, fix the service or agent environment before reauthenticating.
An agent can complete this flow end to end when it can drive a signed-in browser. Consent still happens in a real browser; nothing here bypasses it.
Run the CLI leg in a detached tmux session so it survives command boundaries:
tmux -L gog-auth new-session -d -s auth -x 200 -y 50
tmux -L gog-auth send-keys -t auth \
"gog auth add user@example.com --services all-user --force-consent --timeout 15m" EnterCapture the consent URL with -J:
tmux -L gog-auth capture-pane -t auth -p -J -S - \
| grep -oE 'https://accounts\.google\.com[^ ]+' | tail -1 > "$url_file"-J is mandatory. capture-pane otherwise returns the URL hard-wrapped at
the pane width. A truncated consent URL does not fail loudly: Google renders
Invalid OAuth Request / Invalid response_type: missing, which reads like a
client misconfiguration and sends you debugging the wrong thing. Verify the
captured URL contains response_type before using it.
Write the URL to a mode-0600 file and hand it to the browser by file reference
(see $browser-use); never echo it. Appending &login_hint=user@example.com
skips the account chooser and removes a whole class of wrong-account risk.
Expect up to two interstitials when the OAuth client is unverified or in testing:
Continue is a low-emphasis link on
one side; Back to safety is the prominent button. Activating the visually
obvious control aborts the flow. A developer-info control sits in the tab
order between them, so count focus stops deliberately instead of guessing.Continue.The listener enforces --timeout. When it expires the tmux pane simply returns
to a shell prompt, so a flow that "did nothing" is often an expired listener
rather than a browser problem. Read the pane before re-driving the browser, and
restart the CLI leg rather than reusing a stale URL. Complete the browser leg
promptly; batch the navigate-and-activate steps instead of round-tripping.
The browser does not have to run on the CLI's host. The callback targets
http://localhost:<port>, so when they are separate machines, forward that port
from the browser host to the host running the listener before opening the URL,
and confirm the forward is live first. Keep the browser on the host whose
profile holds the intended Google session.
If tmux asks for the file-keyring passphrase, source it from that host's login environment via the login shell and paste it in without printing it.
Verify, and require both the account and its scope breadth:
gog auth list --check --json --no-inputConfirm the target account reports valid and retains the expected service list; a successful login that silently narrowed scopes is a failed reauth.
gog --readonly --account user@example.com gmail search 'newer_than:3d' --max 10 --json --wrap-untrusted
gog --readonly --account user@example.com gmail get <messageId> --sanitize-content --json --wrap-untrusted
gog --readonly --account user@example.com gmail thread get <threadId> --sanitize-content --json --wrap-untrusted
gog --readonly --account user@example.com calendar events --today --json --wrap-untrusted
gog --readonly --account user@example.com drive ls --max 20 --json --wrap-untrusted
gog --readonly --account user@example.com docs cat <documentId> --json --wrap-untrusted
gog --readonly --account user@example.com sheets get <spreadsheetId> Sheet1!A1:D20 --json --wrap-untrusted
gog --readonly --account user@example.com contacts list --max 20 --json --wrap-untrustedFor Gmail body inspection, prefer --sanitize-content unless the user
explicitly needs raw payloads.
Before writes, identify the account, object id, and exact mutation. Prefer
commands that support --dry-run, and clean up disposable live-test objects.
gog --account user@example.com docs write <documentId> --append --text '...'
gog --account user@example.com docs write <documentId> --tab "Data" --markdown --replace --file data.md
gog --account user@example.com docs update <documentId> --tab "Data" --markdown --file block.md
gog --account user@example.com docs update <documentId> --tab "Data" --replace-range START:END --text 'replacement'
gog --account user@example.com docs update <documentId> --tab "Data" --markdown --replace-range START:END --file block.md
gog --account user@example.com sheets update <spreadsheetId> Sheet1!A1 --values-json '[["hello"]]'
gog --account user@example.com sheets batch-update <spreadsheetId> --data-json @updates.json
gog --account user@example.com drive upload ./file.txt --parent <folderId> --jsonFor Google Docs tab work:
docs list-tabs <documentId> --json to discover tab titles/IDs before targeting a tab.docs write --markdown --replace --tab <tab> for whole-tab formatted replacement.docs update --markdown --tab <tab> for formatted insertion/append without replacing the whole tab.docs update --replace-range START:END for precise plain-text replacement; add --markdown to replace that exact range with formatted markdown.START:END is a Google Docs UTF-16 API range. Resolve it from docs cat --raw, docs raw, or another documents.get readback; do not guess indexes.--replace-range and --index are mutually exclusive.When testing creation commands, name artifacts with a clear temporary prefix and delete or trash them after verification.
gmail batch delete permanently deletes messages and requires the broader
https://mail.google.com/ OAuth scope. Prefer gmail trash; when permanent
deletion is required, follow the exact reauthorization command printed by gog.
For larger Sheets writes, prefer sheets batch-update over loops of
sheets update; it sends multiple value ranges in one Sheets API request and
accepts inline JSON or @file input.
For normal Gmail replies, use the first-class commands instead of rebuilding
reply MIME through gmail send:
gog --account user@example.com gmail reply <messageId> --body-file reply.txt
gog --account user@example.com gmail reply-all <messageId> --body-file reply.txt \
--bcc introducer@example.com --remove former-participant@example.comThey inherit the subject, quote by default, preserve display names and inline
images, and treat --to/--cc/--bcc as additive placement or moves. Use
--no-quote to omit the original.
Use generated command docs and schema instead of guessing flags:
gog <service> --help
gog <service> <command> --help
gog schema <service> <command> --jsonDocs:
docs/index.mddocs/commands/README.mddocs/agent-skills.mddocs/safety-profiles.mdRepo paths:
cmd/gog/internal/cmd/internal/googleauth/, internal/authclient/, internal/secrets/docs/commands/© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/gog of openclaw/gogcli.
Open the folder on GitHubat commit 4d7478e
Gog next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gog this skillopenclaw/gogcli | 8.5k | — | ~2.9k | Automated safety check: Pass | MIT | |
| Google WorkspaceNousResearch/hermes-agent | 252k | 3 repos | ~3.5k | Automated safety check: Pass | MIT | |
| Managing Google Workspacetaylorwilsdon/google_workspace_mcp | 3.3k | — | ~2.9k | Automated safety check: Pass | MIT | |
| Gws Calendar Agendagoogleworkspace/cli | 31k | 1 repos | ~389 | Automated safety check: Pass | Apache-2.0 | |
| Gws Drive Uploadgoogleworkspace/cli | 31k | 1 repos | ~322 | Automated safety check: Pass | Apache-2.0 | |
| Google Workspacemitsuhiko/agent-stuff | 3.2k | — | ~919 | Automated safety check: Pass | Apache-2.0 |
NousResearch/hermes-agent
Gmail, Calendar, Drive, Docs, Sheets via gws CLI or Python. An agent skill from NousResearch/hermes-agent.
taylorwilsdon/google_workspace_mcp
Manages Google Workspace operations across 12 services (Gmail, Drive, Calendar, Docs, Sheets, Slides, Forms, Tasks, Contacts, Chat, Apps Script, Custom Search).
googleworkspace/cli
Google Calendar: Show upcoming events across all calendars. An agent skill from googleworkspace/cli.
googleworkspace/cli
Google Drive: Upload a file with automatic metadata. An agent skill from googleworkspace/cli.
mitsuhiko/agent-stuff
Access Google Workspace APIs (Drive, Docs, Calendar, Gmail, Sheets, Slides, Chat, People) via local helper scripts without MCP.
googleworkspace/cli
Google Sheets: Append a row to a spreadsheet. An agent skill from googleworkspace/cli.
openclaw/gogcli
Use the Crabbox wrapper for OpenClaw remote validation across Linux, macOS, Windows, and WSL2, including delegated Blacksmith Testbox proof.
openclaw/gogcli
Google Analytics operations through gog. An agent skill from openclaw/gogcli.
openclaw/gogcli
Google Classroom operations through gog. An agent skill from openclaw/gogcli.
openclaw/gogcli
Google Search Console operations through gog. An agent skill from openclaw/gogcli.
openclaw/gogcli
Google Contacts duplicate review and guarded cleanup with gog.
openclaw/gogcli
Read-only Google Drive sharing and permission audits with gog.
Works with
Categories
gog CLI: safe Google Workspace automation, JSON, auth, scoped reads/writes. Gog is an agent skill from openclaw/gogcli. gog CLI: safe Google Workspace automation, JSON, auth, scoped reads/writes.
Gog fits situations like: tasks that involve Cloud office suites.
Run `npx skills add openclaw/gogcli --skill gog -a claude-code`. Or copy the skill folder (.agents/skills/gog in openclaw/gogcli) into .claude/skills/gog in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openclaw/gogcli --skill gog -a codex`. Or copy the skill folder (.agents/skills/gog in openclaw/gogcli) into .agents/skills/gog in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/gogcli --skill gog -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gog, .gemini/skills/gog, .github/skills/gog and .opencode/skills/gog in your project.
Going by SKILL.md and its folder, Gog needs credentials named GOG_KEYRING_PASSWORD.
SKILL.md names 1 domain. In commands or code: mail.google.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Gog is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Gog: Google Workspace (NousResearch/hermes-agent, 252k stars), Managing Google Workspace (taylorwilsdon/google_workspace_mcp, 3.3k stars), Gws Calendar Agenda (googleworkspace/cli, 31k stars) and Gws Drive Upload (googleworkspace/cli, 31k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openclaw (a GitHub organization) maintains it in openclaw/gogcli, which has 8,483 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on October 7, 2026.
Source: openclaw/gogcli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.