Google Workspace Security Audit

$2.99Official

Use when auditing a Google Workspace tenant: admin roles, 2SV coverage, third-party OAuth grants, external Drive sharing and login anomalies.

cloudgoogle-workspacesecurity-auditidentityoauthaudit-logscompliance· by SkillingMain

What you get

  • 7-step procedure
  • Runnable Python included
  • 6-point quality checklist
  • 6 pitfalls to avoid
  • Installs into 6 tools
Version
v1
Last updated
today
Length
8 min read
Requires
Best with a strong model (claude-opus-5)

Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes · Built for large codebases

What you'll need to set up

Some setup · 25-40 min

Create a Google Cloud service account with a JSON key, then have a Workspace super admin authorise its numeric Client ID for a fixed list of read-only Admin SDK, Drive and Alert Center scopes via domain-wide delegation.

GOOGLE_WORKSPACE_SA_KEY_JSONGOOGLE_WORKSPACE_ADMIN_SUBJECTGOOGLE_WORKSPACE_CUSTOMER_ID
Full setup guide · 19 API calls

Preview

When to use

Invoke this skill to assess the security posture of a Google Workspace tenant, or for any narrower question it decomposes into: "who has super admin?", "are our admins on 2SV?", "which third-party OAuth apps can read our Gmail and Drive?", "what is shared publicly or outside our domains?", "any suspicious logins or password spray this month?". Also use it for SOC 2 CC6.1/CC6.6, ISO 27001 A.5.15/A.8.2 or CIS Google Workspace Benchmark evidence, and to size the blast radius of one phished account. Do not use it for Google Cloud IAM (a different resource hierarchy) or Gmail message content (that is Vault). The skill is read-only by design: if asked to revoke a token or suspend a

🔒 Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.