gws-install — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited gws-install (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Install gws on an additional machine using OAuth credentials from a previous setup. Produces an authenticated CLI with all agent skills ready to use.
Prerequisite: The user must have client_secret.json from a previous gws-setup (or from Google Cloud Console). If they don't have it, use the gws-setup skill instead.
which gws && gws --version
ls ~/.config/gws/client_secret.json
gws auth statusIf already authenticated with the right scopes, skip to Step 4.
npm install -g @googleworkspace/cli
gws --versionAsk the user to provide their client_secret.json. Three options:
Option A — Paste the JSON content:
Ask the user to paste the JSON. Write it to ~/.config/gws/client_secret.json:
mkdir -p ~/.config/gwsExpected format:
{
"installed": {
"client_id": "...",
"project_id": "...",
"auth_uri": "https://accounts.google.com/o/oauth2/auth",
"token_uri": "https://oauth2.googleapis.com/token",
"client_secret": "...",
"redirect_uris": ["http://localhost"]
}
}Option B — File path:
If the user has the file locally (e.g. in Downloads):
mkdir -p ~/.config/gws
cp /path/to/client_secret.json ~/.config/gws/client_secret.jsonOption C — Environment variables:
export GOOGLE_WORKSPACE_CLI_CLIENT_ID="your-client-id"
export GOOGLE_WORKSPACE_CLI_CLIENT_SECRET="your-client-secret"IMPORTANT: This step prints a very long OAuth URL (30+ scopes) that the user must open in their browser. The URL is too long to copy from terminal output — it wraps across lines and breaks. Always extract it to a file and open it programmatically.
Ask which Google account to use, then:
gws auth login -s gmail,drive,calendar,sheets,docs,chat,tasks 2>&1 | tee /tmp/gws-auth-output.txtRunning as a background task is fine — it will complete once the user approves in browser.
grep -o 'https://accounts.google.com[^ ]*' /tmp/gws-auth-output.txt > /tmp/gws-auth-url.txt
cat /tmp/gws-auth-url.txt | xargs openIf open doesn't work, tell the user: "The auth URL is saved at /tmp/gws-auth-url.txt — open that file and copy the URL from there."
gws auth statusAlternative — `--full` for all scopes:
gws auth login --fullThe user can check their original machine's scopes with gws auth status to see what was granted.
npx skills add googleworkspace/cli -g --agent claude-code --allThis installs 90+ skills into ~/.claude/skills/. Safe to re-run if skills are already installed.
gws auth status
gws calendar +agenda --today
gws gmail +triage~/.config/gws/client_secret.json exists and has valid JSONgws auth logingws auth login to refreshls ~/.claude/skills/gws-* | wc -l should show 30+ directories~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.