Google
Use this skill when Kate needs to read or act on the user's Google
services: email, calendar, tasks, and Drive files.
The google extension implements REST API calls; OAuth refresh tokens
are handled via environment variables.
Use when
- Read, search, or summarize emails
- List/create/update calendar events
- Query or add Tasks items
- List/download/upload Drive files
Do not use when
- You want write actions without the corresponding operator write flag
enabled — the tool returns
-32043
- You want a full Google API catalog — this extension covers only
Gmail/Calendar/Tasks/Drive
Tool surface
21 tools grouped by service. Reads are unrestricted; writes are gated.
Status
status — credential presence, endpoints, write-flag state
Gmail (5 tools)
gmail_list(query?, label_ids?, max_results?, include_spam_trash?, page_token?) — metadata (id + thread_id)
gmail_read(id, format?) — full message (headers, decoded body_text, labels)
gmail_search(query, max_results?) — list alias with required query
gmail_send(to, subject, body) — requires GOOGLE_ALLOW_SEND=true
gmail_modify_labels(id, add_labels?, remove_labels?) — gated (mark_read, archive, trash)
Calendar (5 tools)
calendar_list_calendars
calendar_list_events(calendar_id?, time_min?, time_max?, q?, max_results?, single_events?, order_by?)
calendar_create_event(calendar_id?, summary, description?, location?, start, end, time_zone?, attendees?) — requires GOOGLE_ALLOW_CALENDAR_WRITE=true
calendar_update_event(calendar_id?, event_id, patch) — gated
calendar_delete_event(calendar_id?, event_id) — gated
Tasks (5 tools)
tasks_list_lists(max_results?)
tasks_list_tasks(list_id, show_completed?, show_hidden?, max_results?)
tasks_add(list_id, title, notes?, due?) — requires GOOGLE_ALLOW_TASKS_WRITE=true
tasks_complete(list_id, task_id) — gated
tasks_delete(list_id, task_id) — gated
Drive (6 tools)
drive_list(q?, page_size?, fields?, page_token?, spaces?)
drive_get(id, fields?)
drive_download(id, output_path) — writes to disk; output_path must be under GOOGLE_DRIVE_SANDBOX_ROOT
drive_upload(source_path, name?, parent_id?, mime_type?) — requires GOOGLE_ALLOW_DRIVE_WRITE=true; source path must be under sandbox
drive_create_folder(name, parent_id?) — gated
drive_delete(id) — gated
Execution guidance
Read email
gmail_search query:"is:unread newer_than:1d" max_results:10 → ids
gmail_read id:<id> for each relevant message → body_text + headers
- Optional:
gmail_modify_labels to mark as read (gated)
Daily summary
calendar_list_events time_min:<today 00:00Z> time_max:<tomorrow 00:00Z> → agenda
tasks_list_tasks list_id:@default show_completed:false → pending tasks
gmail_search query:"is:unread" → urgent inbox
Process a Drive PDF
drive_list q:"mimeType='application/pdf' and name contains 'factura'" → id
drive_download id:<id> output_path:/sandbox/factura.pdf → local
pdf-extract.extract_text path:/sandbox/factura.pdf → text
summarize.summarize_text text:<...> → summary
Anti-patterns
- Do not expose full email body_text to end users if it contains
third-party PII; quote only relevant excerpts.
- Do not loop
tasks_add without confirmation; each call persists a row.
- Do not download files that exceed memory limits (hard cap ~50 MB in
blocking reqwest body); use storage flow for larger payloads.
Required OAuth scopes
GOOGLE_REFRESH_TOKEN must be generated with the required scopes.
Recommended setup (full usage):
https://www.googleapis.com/auth/gmail.readonly
https://www.googleapis.com/auth/gmail.send
https://www.googleapis.com/auth/gmail.modify
https://www.googleapis.com/auth/calendar.readonly
https://www.googleapis.com/auth/calendar.events
https://www.googleapis.com/auth/tasks
https://www.googleapis.com/auth/drive
If your token has read-only scopes, write tools may pass local gating
but Google returns 403 insufficient permissions, surfaced as
-32012 Forbidden.
Errors
| Code |
Meaning |
| -32011 |
unauthorized / refresh failed / missing scope for read calls |
| -32012 |
forbidden (missing scope for write calls) |
| -32001 |
not found (invalid id) |
| -32013 |
rate limited (with retry_after_secs) |
| -32043 |
write denied — set the required write flag |
| -32602 |
bad input (path outside sandbox, malformed URL, invalid enum) |
| -32003 / -32005 / -32004 |
transport / timeout / circuit open |
1---2name: google3description: Gmail, Calendar, Tasks, Drive, Contacts (People), and Photos via Google APIs with OAuth refresh tokens.4---5
6# Google
7
8Use this skill when Kate needs to read or act on the user's Google
9services: email, calendar, tasks, and Drive files.
10The `google` extension implements REST API calls; OAuth refresh tokens
11are handled via environment variables.
12
13## Use when
14
15- Read, search, or summarize emails
16- List/create/update calendar events
17- Query or add Tasks items
18- List/download/upload Drive files
19
20## Do not use when
21
22- You want write actions without the corresponding operator write flag
23 enabled — the tool returns `-32043`
24- You want a full Google API catalog — this extension covers only
25 Gmail/Calendar/Tasks/Drive
26
27## Tool surface
28
29**21 tools** grouped by service. Reads are unrestricted; writes are gated.
30
31### Status
32- `status` — credential presence, endpoints, write-flag state
33
34### Gmail (5 tools)
35- `gmail_list(query?, label_ids?, max_results?, include_spam_trash?, page_token?)` — metadata (id + thread_id)
36- `gmail_read(id, format?)` — full message (headers, decoded body_text, labels)
37- `gmail_search(query, max_results?)` — `list` alias with required query
38- `gmail_send(to, subject, body)` — **requires `GOOGLE_ALLOW_SEND=true`**
39- `gmail_modify_labels(id, add_labels?, remove_labels?)` — **gated** (mark_read, archive, trash)
40
41### Calendar (5 tools)
42- `calendar_list_calendars`
43- `calendar_list_events(calendar_id?, time_min?, time_max?, q?, max_results?, single_events?, order_by?)`
44- `calendar_create_event(calendar_id?, summary, description?, location?, start, end, time_zone?, attendees?)` — **requires `GOOGLE_ALLOW_CALENDAR_WRITE=true`**
45- `calendar_update_event(calendar_id?, event_id, patch)` — **gated**
46- `calendar_delete_event(calendar_id?, event_id)` — **gated**
47
48### Tasks (5 tools)
49- `tasks_list_lists(max_results?)`
50- `tasks_list_tasks(list_id, show_completed?, show_hidden?, max_results?)`
51- `tasks_add(list_id, title, notes?, due?)` — **requires `GOOGLE_ALLOW_TASKS_WRITE=true`**
52- `tasks_complete(list_id, task_id)` — **gated**
53- `tasks_delete(list_id, task_id)` — **gated**
54
55### Drive (6 tools)
56- `drive_list(q?, page_size?, fields?, page_token?, spaces?)`
57- `drive_get(id, fields?)`
58- `drive_download(id, output_path)` — writes to disk; `output_path` must be under `GOOGLE_DRIVE_SANDBOX_ROOT`
59- `drive_upload(source_path, name?, parent_id?, mime_type?)` — **requires `GOOGLE_ALLOW_DRIVE_WRITE=true`**; source path must be under sandbox
60- `drive_create_folder(name, parent_id?)` — **gated**
61- `drive_delete(id)` — **gated**
62
63## Execution guidance
64
65### Read email
661. `gmail_search query:"is:unread newer_than:1d" max_results:10` → ids
672. `gmail_read id:<id>` for each relevant message → body_text + headers
683. Optional: `gmail_modify_labels` to mark as read (gated)
69
70### Daily summary
711. `calendar_list_events time_min:<today 00:00Z> time_max:<tomorrow 00:00Z>` → agenda
722. `tasks_list_tasks list_id:@default show_completed:false` → pending tasks
733. `gmail_search query:"is:unread"` → urgent inbox
74
75### Process a Drive PDF
761. `drive_list q:"mimeType='application/pdf' and name contains 'factura'"` → id
772. `drive_download id:<id> output_path:/sandbox/factura.pdf` → local
783. `pdf-extract.extract_text path:/sandbox/factura.pdf` → text
794. `summarize.summarize_text text:<...>` → summary
80
81### Anti-patterns
82
83- **Do not expose full email body_text** to end users if it contains
84 third-party PII; quote only relevant excerpts.
85- **Do not loop `tasks_add`** without confirmation; each call persists a row.
86- **Do not download files** that exceed memory limits (hard cap ~50 MB in
87 blocking reqwest body); use storage flow for larger payloads.
88
89## Required OAuth scopes
90
91`GOOGLE_REFRESH_TOKEN` must be generated with the required scopes.
92Recommended setup (full usage):
93
94```
95https://www.googleapis.com/auth/gmail.readonly
96https://www.googleapis.com/auth/gmail.send
97https://www.googleapis.com/auth/gmail.modify
98https://www.googleapis.com/auth/calendar.readonly
99https://www.googleapis.com/auth/calendar.events
100https://www.googleapis.com/auth/tasks
101https://www.googleapis.com/auth/drive
102```
103
104If your token has read-only scopes, write tools may pass local gating
105but Google returns `403 insufficient permissions`, surfaced as
106`-32012` Forbidden.
107
108## Errors
109
110| Code | Meaning |
111|------|----------------|
112| -32011 | unauthorized / refresh failed / missing scope for read calls |
113| -32012 | forbidden (missing scope for write calls) |
114| -32001 | not found (invalid id) |
115| -32013 | rate limited (with `retry_after_secs`) |
116| -32043 | write denied — set the required write flag |
117| -32602 | bad input (path outside sandbox, malformed URL, invalid enum) |
118| -32003 / -32005 / -32004 | transport / timeout / circuit open |