Google Workspace Security Audit
$2.99OfficialUse when auditing a Google Workspace tenant: admin roles, 2SV coverage, third-party OAuth grants, external Drive sharing and login anomalies.
What you get
- ✓7-step procedure
- ✓Runnable Python included
- ✓6-point quality checklist
- ✓6 pitfalls to avoid
- ✓Installs into 6 tools
- Version
- v1 →
- Last updated
- today
- Length
- 8 min read
- Requires
- Best with a strong model (claude-opus-5)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes · Built for large codebases
What you'll need to set up
Some setup · 25-40 minCreate a Google Cloud service account with a JSON key, then have a Workspace super admin authorise its numeric Client ID for a fixed list of read-only Admin SDK, Drive and Alert Center scopes via domain-wide delegation.
GOOGLE_WORKSPACE_SA_KEY_JSONGOOGLE_WORKSPACE_ADMIN_SUBJECTGOOGLE_WORKSPACE_CUSTOMER_IDPreview
When to use
Invoke this skill to assess the security posture of a Google Workspace tenant, or for any narrower question it decomposes into: "who has super admin?", "are our admins on 2SV?", "which third-party OAuth apps can read our Gmail and Drive?", "what is shared publicly or outside our domains?", "any suspicious logins or password spray this month?". Also use it for SOC 2 CC6.1/CC6.6, ISO 27001 A.5.15/A.8.2 or CIS Google Workspace Benchmark evidence, and to size the blast radius of one phished account. Do not use it for Google Cloud IAM (a different resource hierarchy) or Gmail message content (that is Vault). The skill is read-only by design: if asked to revoke a token or suspend a
…
🔒 Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.