Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fakoli/fakoli-plugins/gws-authnpx skills add fakoli/fakoli-plugins --skill gws-authgit clone --depth 1 https://github.com/fakoli/fakoli-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fakoli/fakoli-plugins/gws-auth)<a href="https://agentmods.dev/skills/fakoli/fakoli-plugins/gws-auth"><img src="https://agentmods.dev/badge/skills/fakoli/fakoli-plugins/gws-auth.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00029 | $0.00827 |
| Opus 5 | $0.00015 | $0.00413 |
| Sonnet 5 | $0.00006 | $0.00165 |
| Haiku 4.5 | $0.00003 | $0.00083 |
Grade A, and why
gws-auth scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 117 lines — stays where its author put it; the contents beside it link to each section on GitHub.
gws auth
Note: See the gws-shared skill for global flags and security rules.
Manage authentication and credentials for the gws CLI.
Auth Subcommands
gws auth login # Interactive OAuth2 login (opens browser)
gws auth logout # Remove stored credentials
gws auth setup # Guided first-run setup wizard
gws auth status # Show current auth state and active scopes
gws auth export # Export credentials for use in other tools
Login Options
Minimal scopes (default — safest for unverified apps)
gws auth login
Default scopes: Drive, Sheets, Gmail, Calendar, Docs, Slides, Tasks.
Full scopes (includes Pub/Sub and Cloud Platform)
gws auth login --full
Adds pubsub and cloud-platform scopes. Requires a verified OAuth app or Workspace domain admin approval.
Custom scopes
gws auth login --scopes drive,gmail,sheets,pubsub
Unrecognized service names are resolved dynamically from Discovery docs.
Read-only access
gws auth login --readonly
Grants only .readonly scopes for all services.
Credential Sources (Priority Order)
GOOGLE_WORKSPACE_CLI_TOKEN— Pre-obtained OAuth2 access token (highest priority)GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE— Path to OAuth credentials JSON- Encrypted credentials — AES-256-GCM encrypted at
~/.config/gws/ GOOGLE_APPLICATION_CREDENTIALS— Standard Google ADC (fallback)
Service Account Support
export GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE=/path/to/service-account.json
gws drive files list
Credential Storage
- Credentials are stored at
~/.config/gws/(override withGOOGLE_WORKSPACE_CLI_CONFIG_DIR) - Encrypted with AES-256-GCM
- Encryption key stored in OS keyring by default
- For headless/Docker/CI:
export GOOGLE_WORKSPACE_CLI_KEYRING_BACKEND=file
Environment Variables
| Variable | Description |
|---|---|
GOOGLE_WORKSPACE_CLI_TOKEN |
Pre-obtained OAuth2 access token |
GOOGLE_WORKSPACE_CLI_CREDENTIALS_FILE |
Path to OAuth credentials JSON |
GOOGLE_WORKSPACE_CLI_CLIENT_ID |
OAuth client ID |
GOOGLE_WORKSPACE_CLI_CLIENT_SECRET |
OAuth client secret |
GOOGLE_WORKSPACE_CLI_CONFIG_DIR |
Override config directory |
GOOGLE_WORKSPACE_CLI_KEYRING_BACKEND |
keyring (default) or file |
GOOGLE_APPLICATION_CREDENTIALS |
Standard Google ADC path |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 117 lines · 29 tokens per session scan A d90397a6bf67
gws-auth is a skill published in the GitHub repository fakoli/fakoli-plugins (4 stars, last pushed 27d ago), licensed MIT. It adds 29 tokens to every session and 827 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
better-auth-knowledge-patch
Use this skill when implementing, upgrading, debugging, or reviewing Better Auth applications. Start with the quick references below, then load the topic file that matches the task.
caddy-knowledge-patch
Use this patch when writing or reviewing Caddyfile or JSON configuration, upgrading Caddy, building custom binaries, or operating Caddy's HTTP, proxy, certificate, and telemetry features.
clickhouse-knowledge-patch
Use this skill when writing, reviewing, upgrading, or operating ClickHouse SQL and server configurations. Start with the compatibility-sensitive items below, then load the topic reference that matches the task.
arch-knowledge-patch
Restart the daemon immediately after upgrading openssh to 9.8p1 because the old daemon cannot accept new connections.
axum-knowledge-patch
Axum 0.8 uses return-position impl Trait in FromRequestParts and FromRequest. Implement their methods with native async fn; do not retain the old #[asynctrait] annotation.
cloudflare-d1-knowledge-patch
Use this skill when designing, implementing, migrating, operating, or debugging Cloudflare D1 databases. Check the project’s Wrangler configuration, binding usage, database generation, account plan, and remote-versus-local command flags before applying guidance.