Google Workspace CLI for Gmail, Calendar, Drive, Contacts, Sheets, and Docs.
Security Analysis
medium confidenceThe skill's instructions look like a legitimate Google Workspace CLI, but the registry metadata and SKILL.md disagree about required binaries/install, and the skill asks you to supply OAuth credentials and run local commands — verify the source before installing or granting account access.
The SKILL.md describes a Google Workspace CLI (Gmail, Calendar, Drive, Contacts, Sheets, Docs) and its commands — that purpose aligns with the actions shown. However the registry metadata shown to the platform lists no required binaries or install spec, while the SKILL.md includes metadata that requires the 'gog' binary and even provides a Homebrew formula (steipete/tap/gogcli). This mismatch between declared requirements and the runtime instructions is an inconsistency worth verifying.
The instructions stay on-topic: they show how to perform OAuth setup with a client_secret.json, add an account and run Gmail/Calendar/Drive/Sheets/Docs commands. They require running a local CLI and providing OAuth credentials (sensitive by nature) but do not instruct the agent to read unrelated system files or exfiltrate data to unexpected endpoints.
There is no install spec in the registry listing, yet SKILL.md metadata includes a Homebrew install entry (steipete/tap/gogcli). Installing a third‑party Homebrew tap is moderately risky if you don't trust its source; the registry's omission of the install step is an incoherence that makes it unclear whether the platform will automatically install the binary or expect it preinstalled.
No environment variables or primary credentials are declared in the registry, but the SKILL.md requires OAuth credentials (client_secret.json) and suggests setting GOG_ACCOUNT. Requesting OAuth client secrets and access to Google services is proportionate to a workspace CLI, but these are sensitive and the lack of declared credentials in the registry metadata is an omission to confirm.
The skill does not request always:true and does not declare persistent system-wide changes. It is user-invocable and allows autonomous invocation by default (platform default) — notable but not a standalone red flag in this case.
Guidance
This skill appears to be a wrapper for the 'gog' CLI and legitimately needs OAuth credentials and a local binary. Before installing or using it: 1) Verify the upstream project/homepage (https://gogcli.sh) and the Homebrew tap (steipete/tap/gogcli) are trustworthy — inspect the repository and releases; 2) Prefer installing the 'gog' binary yourself and testing it independently rather than letting an automated installer run; 3) Only provide OAuth client_secret.json and authorize scopes from an account you control (prefer a dedicated/test Google account with least privilege); 4) Be aware the SKILL.md and registry metadata disagree about install/requirements — ask the publisher to clarify why the registry shows no install/binaries while SKILL.md references them; 5) If you are uncomfortable, do not grant access to your primary Google account and consider running the CLI locally instead.
Latest Release
v1.0.0
More by @steipete
Published by @steipete on ClawHub