Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计异常

gws-setup网关设置

Agent Skill

gws-setup 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

10,894

周安装

445

GitHub Stars

750

下载量

3,489
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:gws-setup(网关设置)
来源仓库:https://github.com/jezweb/claude-skills
仓库路径:skills/gws-setup
安装命令:
npx skills add https://github.com/jezweb/claude-skills --skill gws-setup
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/jezweb/claude-skills --skill gws-setup

简介

gws-setup 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中快速定位候选结果。

  • 适用于需要根据关键词或任务场景从来源线索中获取信息的场景。
  • 通过 npx skills add 命令安装,需结合原始 README 核验具体用法。
  • 安装前建议确认权限范围、维护状态及是否触发联网或文件读写操作。
  • gws-setup 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Google Workspace CLI — First-Time Setup

Set up the gws CLI (@googleworkspace/cli) with OAuth credentials and 90+ agent skills for Claude Code. Produces a fully authenticated CLI with skills for Gmail, Drive, Calendar, Sheets, Docs, Chat, Tasks, and more.

Prerequisites

  • Node.js 18+
  • A Google account (personal or Workspace)
  • Access to Google Cloud Console (console.cloud.google.com)

Workflow

Step 1: Pre-flight Checks

Check what's already done and skip completed steps:

# Check if gws is installed
which gws && gws --version

# Check if client_secret.json exists
ls ~/.config/gws/client_secret.json

# Check if already authenticated
gws auth status

If gws auth status shows "status": "success" with scopes, skip to Step 6 (Install Skills).

Step 2: Install the CLI

npm install -g @googleworkspace/cli
gws --version

Step 3: Create a GCP Project and OAuth Credentials

The user needs to create OAuth Desktop App credentials in Google Cloud Console. Walk them through each step.

3a. Create or select a GCP project:

Direct the user to: https://console.cloud.google.com/projectcreate

Or use an existing project. Ask the user which they prefer.

3b. Enable Google Workspace APIs:

Direct the user to the API Library for their project: https://console.cloud.google.com/apis/library?project=PROJECT_ID

Enable these APIs (search for each):

  • Gmail API
  • Google Drive API
  • Google Calendar API
  • Google Sheets API
  • Google Docs API
  • Google Chat API (requires extra Chat App config — see below)
  • Tasks API
  • People API
  • Google Slides API
  • Google Forms API
  • Admin SDK API (optional — for Workspace admin features)

3c. Configure Google Chat App (required for Chat API):

Enabling the Chat API alone isn't enough — Google requires a Chat App configuration even for user-context OAuth access. Without this, all Chat API calls return errors.

Direct the user to: https://console.cloud.google.com/apis/api/chat.googleapis.com/hangouts-chat?project=PROJECT_ID

  1. Click the Configuration tab
  2. Fill in app details (name, avatar, description — values don't matter for CLI use)
  3. Under "Functionality", check Spaces and group conversations
  4. Under "Connection settings", select Apps Script or HTTP endpoint (pick any — we just need the config to exist)
  5. Save

This creates the app identity that the Chat API requires. Messages sent via gws still appear as coming from the authenticated user (OAuth user context), not from a bot.

3e. Configure OAuth consent screen:

Direct the user to: https://console.cloud.google.com/apis/credentials/consent?project=PROJECT_ID

Settings:

  • User Type: External (works for any Google account)
  • App name: gws CLI (or any name)
  • User support email: their email
  • Developer contact: their email
  • Leave scopes blank (gws requests scopes at login time)
  • Add their Google account as a test user (required while app is in "Testing" status)
  • Save and continue through all screens

3f. Create OAuth client ID:

Direct the user to: https://console.cloud.google.com/apis/credentials?project=PROJECT_ID

  1. Click Create CredentialsOAuth client ID
  2. Application type: Desktop app
  3. Name: gws CLI
  4. Click Create
  5. Copy the JSON or download the client_secret_*.json file

3g. Save the credentials:

Ask the user to provide the client_secret.json content (paste the JSON or provide the downloaded file path).

mkdir -p ~/.config/gws

Write the JSON to ~/.config/gws/client_secret.json. The expected format:

{
  "installed": {
    "client_id": "...",
    "project_id": "...",
    "auth_uri": "https://accounts.google.com/o/oauth2/auth",
    "token_uri": "https://oauth2.googleapis.com/token",
    "client_secret": "...",
    "redirect_uris": ["http://localhost"]
  }
}

Step 4: Choose Scopes

Ask the user what level of access they want:

OptionCommandWhat it grants
Full access (recommended)gws auth login --fullAll Workspace scopes including admin, pubsub, cloud-platform
Core servicesgws auth login -s gmail,drive,calendar,sheets,docs,chat,tasksMost-used services only
Minimalgws auth login -s gmail,calendarJust email and calendar

Recommend full access for power users. The OAuth consent screen shows all requested scopes so the user can review before granting.

Note: If the GCP app is in "Testing" status, scope selection is limited to ~25 scopes. Use -s service1,service2 to request targeted scopes, or publish the app (Publish → In Production) for broader scope access.

Step 5: Authenticate

IMPORTANT: This step prints a very long OAuth URL (30+ scopes) that the user must open in their browser. The URL is too long to copy from terminal output — it wraps across lines and breaks. Always extract it to a file and open it programmatically.

  1. Run the login command and capture the output:
gws auth login --full 2>&1 | tee /tmp/gws-auth-output.txt
# Or with specific services:
# gws auth login -s gmail,drive,calendar,sheets,docs,chat,tasks 2>&1 | tee /tmp/gws-auth-output.txt

Running as a background task is fine — it will complete once the user approves in browser.

  1. Extract and open the URL (run separately after output appears):
grep -o 'https://accounts.google.com[^ ]*' /tmp/gws-auth-output.txt > /tmp/gws-auth-url.txt
cat /tmp/gws-auth-url.txt | xargs open

If open doesn't work, tell the user: "The auth URL is saved at /tmp/gws-auth-url.txt — open that file and copy the URL."

  1. Wait for the user to approve in their browser.

After browser approval, gws stores encrypted credentials at ~/.config/gws/credentials.enc.

Verify:

gws auth status

Should show "status": "success" with the authenticated account and granted scopes.

Step 6: Install Agent Skills

Install the 90+ gws agent skills globally for Claude Code:

npx skills add googleworkspace/cli -g --agent claude-code --all

Verify skills are installed:

ls ~/.claude/skills/gws-* | wc -l

Should show 30+ gws skill directories.

Step 7: Save Credentials for Other Machines

If the user has other machines to set up, suggest exporting the client credentials:

gws auth export

This prints decrypted credentials (including refresh token) to stdout. The client_secret.json file is the portable part — the same OAuth client can be used on any machine, with gws auth login generating fresh user tokens per machine.

Tell the user to save the client_secret.json content somewhere secure (password manager, encrypted note) for use with the gws-install skill on other machines.

Step 8: Verify Everything Works

Run a few commands to confirm:

# Check auth
gws auth status

# Check calendar
gws calendar +agenda --today

# Check email
gws gmail +triage

If any command fails with auth errors, re-run gws auth login with the needed scopes.


Critical Patterns

Testing vs Production OAuth Apps

GCP OAuth apps start in "Testing" status with a 7-day token expiry and ~25 scope limit. For long-term use:

  • Push the app to Production in the OAuth consent screen settings
  • Production apps have no token expiry limit
  • For personal/internal use, Google does not require verification

Scope Reference

Service flagWhat it enables
gmailSend, read, manage email, labels, filters
driveFiles, folders, shared drives
calendarEvents, calendars, free/busy
sheetsRead and write spreadsheets
docsRead and write documents
chatSpaces, messages
tasksTask lists and tasks
slidesPresentations
formsForms and responses
peopleContacts and profiles
adminWorkspace admin (directory, devices, groups)

Environment Variable Alternative

Instead of client_secret.json, credentials can be provided via environment variables:

export GOOGLE_WORKSPACE_CLI_CLIENT_ID="your-client-id"
export GOOGLE_WORKSPACE_CLI_CLIENT_SECRET="your-client-secret"
gws auth login

Config Directory

All gws config lives in ~/.config/gws/:

FilePurpose
client_secret.jsonOAuth client credentials (portable)
credentials.encEncrypted user tokens (per-machine)
token_cache.jsonToken refresh cache
cache/API discovery schema cache

See Also

  • gws-install — Quick setup on additional machines with existing credentials
  • gws-shared — Auth patterns and global flags for gws commands

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

33.79%
按下载量换算1,179

Claude

31.28%
按下载量换算1,091

Cursor

18.61%
按下载量换算649

Gemini CLI

8.35%
按下载量换算291

安全审计

Gen Agent Trust Hub

通过

Socket

可疑

Snyk

未通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills