Agent skill

Google Workspace

by RedWoodOG in RedWoodOG/Hermes-Desktop

Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration via Python.

MITAuto-check passedBackend & APIs

Install Google Workspace

skills CLI
$ npx skills add RedWoodOG/Hermes-Desktop --skill google-workspace -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install RedWoodOG/Hermes-Desktop google-workspace --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/RedWoodOG/Hermes-Desktop.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/productivity/google-workspace .claude/skills/google-workspace && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
google-workspace
GitHub stars
177
Token cost
~2.1k tokens
SKILL.md length
722 words
Files
4 (incl. scripts, references)
Skills in repo
62
Repo updated
First seen
Licence
MIT

At a glance

Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration via Python.

  • Works in 6 steps: Check if already set up → Triage — ask the user what they need → Create OAuth credentials (one-time, ~5… → …
  • Tasks that involve Cloud office suites
  • SKILL.md covers References, Scripts, First-Time Setup and Usage, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Google Workspace is an agent skill from RedWoodOG/Hermes-Desktop. Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration via Python. Uses OAuth2 with automatic token refresh. No external binaries needed — runs entirely with Google's Python client libraries in the Hermes venv.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/gmail-search-syntax.md`, `scripts/google_api.py` and `scripts/setup.py`).

It sits in Backend & APIs, covering Cloud office suites, Email management and OAuth and OpenID Connect. It works with Gmail, Google Workspace and Python. The licence is MIT.

When your agent uses it

  • Tasks that involve Cloud office suites
  • Tasks that involve Email management
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/google-workspace”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Check if already set up
  2. Triage — ask the user what they need
  3. Create OAuth credentials (one-time, ~5 minutes)
  4. Get authorization URL
  5. Exchange the code
  6. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit be46b39. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • console.cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Workspace loads about 2.1k tokens when it runs, and up to ~2.6k if it reads all its reference files. Until then it costs about 59 tokens; SKILL.md has 722 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from RedWoodOG/Hermes-Desktop at commit be46b39, republished under its MIT licence (© RedWoodOG). 722 words, ~2,079 tokens.

Download SKILL.mdSave it as .claude/skills/google-workspace/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
google-workspace
description
Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration via Python. Uses OAuth2 with automatic token refresh. No external binaries needed — runs entirely with Google's Python client libraries in the Hermes venv.
version
1.0.0
author
Nous Research
license
MIT

Google Workspace

Gmail, Calendar, Drive, Contacts, Sheets, and Docs — all through Python scripts in this skill. No external binaries to install.

References

  • references/gmail-search-syntax.md — Gmail search operators (is:unread, from:, newer_than:, etc.)

Scripts

  • scripts/setup.py — OAuth2 setup (run once to authorize)
  • scripts/google_api.py — API wrapper CLI (agent uses this for all operations)

First-Time Setup

The setup is fully non-interactive — you drive it step by step so it works on CLI, Telegram, Discord, or any platform.

Define a shorthand first:

bash
GSETUP="python ~/.hermes/skills/productivity/google-workspace/scripts/setup.py"
Step 0: Check if already set up
bash
$GSETUP --check

If it prints AUTHENTICATED, skip to Usage — setup is already done.

Step 1: Triage — ask the user what they need

Before starting OAuth setup, ask the user TWO questions:

Question 1: "What Google services do you need? Just email, or also Calendar/Drive/Sheets/Docs?"

  • Email only → They don't need this skill at all. Use the himalaya skill instead — it works with a Gmail App Password (Settings → Security → App Passwords) and takes 2 minutes to set up. No Google Cloud project needed. Load the himalaya skill and follow its setup instructions.

  • Calendar, Drive, Sheets, Docs (or email + these) → Continue with this skill's OAuth setup below.

Question 2: "Does your Google account use Advanced Protection (hardware security keys required to sign in)? If you're not sure, you probably don't — it's something you would have explicitly enrolled in."

  • No / Not sure → Normal setup. Continue below.
  • Yes → Their Workspace admin must add the OAuth client ID to the org's allowed apps list before Step 4 will work. Let them know upfront.
Step 2: Create OAuth credentials (one-time, ~5 minutes)

Tell the user:

You need a Google Cloud OAuth client. This is a one-time setup:

  1. Go to https://console.cloud.google.com/apis/credentials
  2. Create a project (or use an existing one)
  3. Click "Enable APIs" and enable: Gmail API, Google Calendar API, Google Drive API, Google Sheets API, Google Docs API, People API
  4. Go to Credentials → Create Credentials → OAuth 2.0 Client ID
  5. Application type: "Desktop app" → Create
  6. Click "Download JSON" and tell me the file path

Once they provide the path:

bash
$GSETUP --client-secret /path/to/client_secret.json
Step 3: Get authorization URL
bash
$GSETUP --auth-url

This prints a URL. Send the URL to the user and tell them:

Open this link in your browser, sign in with your Google account, and authorize access. After authorizing, you'll be redirected to a page that may show an error — that's expected. Copy the ENTIRE URL from your browser's address bar and paste it back to me.

Step 4: Exchange the code

The user will paste back either a URL like http://localhost:1/?code=4/0A...&scope=... or just the code string. Either works. The --auth-url step stores a temporary pending OAuth session locally so --auth-code can complete the PKCE exchange later, even on headless systems:

bash
$GSETUP --auth-code "THE_URL_OR_CODE_THE_USER_PASTED"
Show full SKILL.md (279 more words)Show less
Step 5: Verify
bash
$GSETUP --check

Should print AUTHENTICATED. Setup is complete — token refreshes automatically from now on.

Notes
  • Token is stored at ~/.hermes/google_token.json and auto-refreshes.
  • Pending OAuth session state/verifier are stored temporarily at ~/.hermes/google_oauth_pending.json until exchange completes.
  • To revoke: $GSETUP --revoke

Usage

All commands go through the API script. Set GAPI as a shorthand:

bash
GAPI="python ~/.hermes/skills/productivity/google-workspace/scripts/google_api.py"
Gmail
bash
# Search (returns JSON array with id, from, subject, date, snippet)
$GAPI gmail search "is:unread" --max 10
$GAPI gmail search "from:boss@company.com newer_than:1d"
$GAPI gmail search "has:attachment filename:pdf newer_than:7d"

# Read full message (returns JSON with body text)
$GAPI gmail get MESSAGE_ID

# Send
$GAPI gmail send --to user@example.com --subject "Hello" --body "Message text"
$GAPI gmail send --to user@example.com --subject "Report" --body "<h1>Q4</h1><p>Details...</p>" --html

# Reply (automatically threads and sets In-Reply-To)
$GAPI gmail reply MESSAGE_ID --body "Thanks, that works for me."

# Labels
$GAPI gmail labels
$GAPI gmail modify MESSAGE_ID --add-labels LABEL_ID
$GAPI gmail modify MESSAGE_ID --remove-labels UNREAD
Calendar
bash
# List events (defaults to next 7 days)
$GAPI calendar list
$GAPI calendar list --start 2026-03-01T00:00:00Z --end 2026-03-07T23:59:59Z

# Create event (ISO 8601 with timezone required)
$GAPI calendar create --summary "Team Standup" --start 2026-03-01T10:00:00-06:00 --end 2026-03-01T10:30:00-06:00
$GAPI calendar create --summary "Lunch" --start 2026-03-01T12:00:00Z --end 2026-03-01T13:00:00Z --location "Cafe"
$GAPI calendar create --summary "Review" --start 2026-03-01T14:00:00Z --end 2026-03-01T15:00:00Z --attendees "alice@co.com,bob@co.com"

# Delete event
$GAPI calendar delete EVENT_ID
Drive
bash
$GAPI drive search "quarterly report" --max 10
$GAPI drive search "mimeType='application/pdf'" --raw-query --max 5
Contacts
bash
$GAPI contacts list --max 20
Sheets
bash
# Read
$GAPI sheets get SHEET_ID "Sheet1!A1:D10"

# Write
$GAPI sheets update SHEET_ID "Sheet1!A1:B2" --values '[["Name","Score"],["Alice","95"]]'

# Append rows
$GAPI sheets append SHEET_ID "Sheet1!A:C" --values '[["new","row","data"]]'
Docs
bash
$GAPI docs get DOC_ID

Output Format

All commands return JSON. Parse with jq or read directly. Key fields:

  • Gmail search: [{id, threadId, from, to, subject, date, snippet, labels}]
  • Gmail get: {id, threadId, from, to, subject, date, labels, body}
  • Gmail send/reply: {status: "sent", id, threadId}
  • Calendar list: [{id, summary, start, end, location, description, htmlLink}]
  • Calendar create: {status: "created", id, summary, htmlLink}
  • Drive search: [{id, name, mimeType, modifiedTime, webViewLink}]
  • Contacts list: [{name, emails: [...], phones: [...]}]
  • Sheets get: [[cell, cell, ...], ...]

Rules

  1. Never send email or create/delete events without confirming with the user first. Show the draft content and ask for approval.
  2. Check auth before first use — run setup.py --check. If it fails, guide the user through setup.
  3. Use the Gmail search syntax reference for complex queries — load it with skill_view("google-workspace", file_path="references/gmail-search-syntax.md").
  4. Calendar times must include timezone — always use ISO 8601 with offset (e.g., 2026-03-01T10:00:00-06:00) or UTC (Z).
  5. Respect rate limits — avoid rapid-fire sequential API calls. Batch reads when possible.

Troubleshooting

ProblemFix
NOT_AUTHENTICATEDRun setup Steps 2-5 above
REFRESH_FAILEDToken revoked or expired — redo Steps 3-5
HttpError 403: Insufficient PermissionMissing API scope — $GSETUP --revoke then redo Steps 3-5
HttpError 403: Access Not ConfiguredAPI not enabled — user needs to enable it in Google Cloud Console
ModuleNotFoundErrorRun $GSETUP --install-deps
Advanced Protection blocks authWorkspace admin must allowlist the OAuth client ID

Revoking Access

bash
$GSETUP --revoke

© RedWoodOG, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/productivity/google-workspace of RedWoodOG/Hermes-Desktop.

  • SKILL.md
  • references/gmail-search-syntax.md
  • scripts/google_api.py
  • scripts/setup.py

Open the folder on GitHubat commit be46b39

Compare with similar skills

Google Workspace next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Workspace compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Workspace this skillRedWoodOG/Hermes-Desktop177—~2.1kAutomated safety check: PassMIT
Community Google WorkspaceArgentAIOS/argentos-core126—~2.8kAutomated safety check: PassMIT
Google WorkspaceTommy-yw/RunbookHermes5461 repos~2.7kAutomated safety check: PassMIT
Google Workspaceericrisco/rsc-harness180—~3.2kAutomated safety check: PassMIT
Detecting Email Account Compromisemukul975/Anthropic-Cybersecurity-Skills34k—~823Automated safety check: PassApache-2.0
GCP Workspace Pivotwgpsec/AboutSecurity1.8k—~2.9kAutomated safety check: PassNone

Similar skills

  • Community Google Workspace

    ArgentAIOS/argentos-core

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration for community skills.

    126 GitHub stars~2.8k tokensUpdated 3 mo ago
    Documents & OfficeAuto-check passed
  • Google Workspace

    Tommy-yw/RunbookHermes

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration for Hermes.

    546 GitHub starsUsed in 1 repo~2.7k tokens
    Documents & OfficeAuto-check passed
  • Google Workspace

    ericrisco/rsc-harness

    A skill your agent uses when server-side code reads or writes Gmail, Drive, Calendar, or Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs…

    180 GitHub stars~3.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Detecting Email Account Compromise

    mukul975/Anthropic-Cybersecurity-Skills

    Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…

    34k GitHub stars~823 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • GCP Workspace Pivot

    wgpsec/AboutSecurity

    GCP 到 Google Workspace 的穿越攻击方法论。当已获取 GCP Service Account 或 Project 权限并发现目标组织使用 Google Workspace、需要从云平台穿越到企业邮件/文档/管理控制台、或发现 Domain-Wide Delegation 配置时使用。覆盖 Domain-Wide Delegation 滥用、OAuth…

    1.8k GitHub stars~2.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Pp Workspace Admin

    mvanhorn/printing-press-library

    GAT-style Google Workspace auditing as an agent-native CLI: sync Directory, Drive, Gmail, Reports, and Alert Center into a local store, then run offline cross-API audits, offboarding, and OAuth-app…

    2.1k GitHub stars~11k tokensUpdated today
    Backend & APIsAuto-check: notes

More from RedWoodOG/Hermes-Desktop

All 62 skills in this repo
  • Excalidraw

    RedWoodOG/Hermes-Desktop

    Create hand-drawn style diagrams using Excalidraw JSON format.

    177 GitHub starsUsed in 5 repos~1.8k tokens
    Auto-check passed
  • Obliteratus

    RedWoodOG/Hermes-Desktop

    Remove refusal behaviors from open-weight LLMs using OBLITERATUS — mechanistic interpretability techniques (diff-in-means, SVD, whitened SVD, LEACE, SAE decomposition, etc.) to excise guardrails…

    177 GitHub starsUsed in 5 repos~3.8k tokens
    Auto-check passed
  • Ascii Video

    RedWoodOG/Hermes-Desktop

    Production pipeline for ASCII art video — any format. An agent skill from RedWoodOG/Hermes-Desktop.

    177 GitHub starsUsed in 2 repos~3.2k tokens
    Auto-check passed
  • Systematic Debugging

    RedWoodOG/Hermes-Desktop

    A skill your agent uses when encountering any bug, test failure, or unexpected behavior.

    177 GitHub starsUsed in 6 repos~2.6k tokens
    Auto-check passed
  • Test Driven Development

    RedWoodOG/Hermes-Desktop

    A skill your agent uses when implementing any feature or bugfix, before writing implementation code.

    177 GitHub starsUsed in 6 repos~2.4k tokens
    Auto-check passed
  • Claude Code

    RedWoodOG/Hermes-Desktop

    Delegate coding tasks to Claude Code (Anthropic's CLI agent).

    177 GitHub starsUsed in 4 repos~784 tokens
    Auto-check passed

Questions about Google Workspace

What does Google Workspace do?

Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration via Python. Google Workspace is an agent skill from RedWoodOG/Hermes-Desktop. Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration via Python.

When should I use Google Workspace?

Google Workspace fits situations like: tasks that involve Cloud office suites; tasks that involve Email management; tasks that involve OAuth and OpenID Connect.

How do I install Google Workspace in Claude Code?

Run `npx skills add RedWoodOG/Hermes-Desktop --skill google-workspace -a claude-code`. Or copy the skill folder (skills/productivity/google-workspace in RedWoodOG/Hermes-Desktop) into .claude/skills/google-workspace in your project. Claude Code loads it when a task matches its description.

How do I install Google Workspace in Codex?

Run `npx skills add RedWoodOG/Hermes-Desktop --skill google-workspace -a codex`. Or copy the skill folder (skills/productivity/google-workspace in RedWoodOG/Hermes-Desktop) into .agents/skills/google-workspace in your project. Codex loads it when a task matches its description.

Can I use Google Workspace in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add RedWoodOG/Hermes-Desktop --skill google-workspace -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-workspace, .gemini/skills/google-workspace, .github/skills/google-workspace and .opencode/skills/google-workspace in your project.

What does Google Workspace need to run?

Going by SKILL.md and its folder, Google Workspace needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Google Workspace access the network?

SKILL.md names 1 domain. As links in the text: console.cloud.google.com. This is read from the text; nothing was executed.

Is Google Workspace safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Google Workspace use?

Google Workspace is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Workspace use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 538 tokens, read only when the agent opens those files.

What are the alternatives to Google Workspace?

Skills that share tags, products or a category with Google Workspace: Community Google Workspace (ArgentAIOS/argentos-core, 126 stars), Google Workspace (Tommy-yw/RunbookHermes, 546 stars), Google Workspace (ericrisco/rsc-harness, 180 stars) and Detecting Email Account Compromise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Workspace?

RedWoodOG (a GitHub user) maintains it in RedWoodOG/Hermes-Desktop, which has 177 GitHub stars. The repository holds 62 skills in this directory. The repository was last updated on May 30, 2026.

Source: RedWoodOG/Hermes-Desktop on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.