CtrlK
BlogDocsLog inGet started
Tessl Logo

gog

gog CLI: safe Google Workspace automation, JSON, auth, scoped reads/writes.

64

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/gog/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

96%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is an exemplar of operational skill writing: fully executable commands, non-obvious failure-mode knowledge, safety guards on every destructive path, and validation checkpoints wired into each multi-step workflow. The only structural weakness is that everything lives in one long SKILL.md with no reference files to split the detailed reauth flow and per-service command catalogs.

DimensionReasoningScore

Conciseness

The body is dense, command-first, and assumes Claude's competence — no OAuth, tmux, or Google-API tutorials — and every prose passage covers non-obvious operational gotchas ('-J is mandatory', expired listener diagnosis, UTF-16 START:END ranges) that Claude could not know. Nothing is padded or trimmable.

5 / 5

Actionability

Every section gives copy-paste-ready executable commands with concrete flags (--readonly, --json --wrap-untrusted, --no-input, --sanitize-content) and clearly marked placeholders (<messageId>, <documentId>, START:END), covering the common read, write, auth, and discovery cases.

5 / 5

Workflow Clarity

Multi-step flows are explicitly sequenced with validation checkpoints and feedback loops: 'gog auth list --check' before reauth, verifying the captured URL contains 'response_type', diagnosing an expired listener before re-driving the browser, '--dry-run' first for writes, and post-reauth verification of both account and scope breadth. Destructive and batch operations all have explicit guards.

5 / 5

Progressive Disclosure

Sections are well-organized and the Discovery section clearly signals docs/ paths (docs/index.md, docs/commands/README.md, docs/safety-profiles.md), but the ~260-line body inlines material — the full per-service write catalog and the entire browser-driven reauth flow — that could be split into one-level-deep reference files, and no bundle reference files exist.

4 / 5

Total

19

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise and names a distinct niche, but it reads as a compressed capability tagline rather than an operational description: it lacks any 'Use when...' trigger guidance and omits the Workspace service names (Gmail, Drive, Calendar, Sheets, Docs) that users and Claude would naturally match against. It would benefit most from an explicit trigger clause and fuller action/service coverage.

Suggestions

Add an explicit trigger clause, e.g. 'Use when built-in Google connectors are missing a feature, when you need stable JSON output from Gmail, Calendar, Drive, Docs, or Sheets, or when inspecting local Google auth state.'

Replace noun-phrase shorthand ('JSON, auth, scoped reads/writes') with concrete third-person actions such as 'Searches Gmail, lists Drive files, reads and writes Docs and Sheets, manages OAuth accounts' to improve specificity and trigger-term coverage.

Include the service names users naturally say (Gmail, Google Drive, Google Calendar, Sheets, Docs, Contacts) so the skill triggers reliably for those requests.

DimensionReasoningScore

Specificity

Names the domain ('Google Workspace automation') and a few concrete capabilities ('JSON', 'auth', 'scoped reads/writes'), but as compressed noun phrases rather than a list of several specific actions; no per-service operations (Gmail, Drive, Sheets, Calendar) are mentioned, so coverage is not comprehensive.

3 / 5

Completeness

It conveys a 'what' (safe Workspace automation with JSON output, auth, and scoped reads/writes) but has no 'Use when...' clause or any equivalent trigger guidance, which caps completeness at 3 per the rubric guidelines.

3 / 5

Trigger Term Quality

'Google Workspace', 'JSON', 'auth', and 'reads/writes' are relevant keywords, but the natural terms users would actually say — Gmail, Google Drive, Sheets, Calendar, email search — are missing, matching 'some relevant keywords but missing common variations or synonyms'.

3 / 5

Distinctiveness Conflict Risk

A named niche CLI ('gog CLI', 'Google Workspace automation') is mostly distinct with minor overlap risk against generic Google Workspace skills; not 5 because service-level triggers that would make it unmistakable are absent.

4 / 5

Total

13

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
openclaw/gogcli
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.