finding-google-skills
Google platform decision and setup guidance, loaded on demand from Google's skill catalog.…
Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations. Use when asked to fix, remediate, or mitigate a Security Command Center finding or address attack paths. Don't use
$ npx -y skills add google/skills --skill google-cloud-scc-remediation --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/google-cloud-scc-remediationContext preview
The summary Claude sees to decide when to auto-load this skill.
Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations. Use when asked to fix, remediate, or mitigate a Security Command Center finding or address attack paths. Don't use
name: google-cloud-scc-remediation metadata: category: Security version: "1.0.0" description: >- Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations. Use when asked to fix, remediate, or mitigate a Security Command Center finding or address attack paths. Don't use for general IAM policy querying without a Security Command Center finding. For runtime threat detections, this skill provides containment and investigation guidance rather than automated configuration fixes.
A unified remediation skill for Google Cloud Security Command Center findings. It handles both single-domain findings and multi-domain Toxic Combinations.
Security Command Center remediations modify infrastructure, access policies, or workload deployments.
API commands without first presenting a structured remediation plan and the exact command/config diff to the user. STOP after presenting the plan and ALWAYS ask: "Do you approve executing this remediation plan?" before execution. Automatic mutation of security policies or resource configurations can cause unintended outages, lockouts, or compliance violations.
`gcloud` account and project match the project of the finding's resource. Every mutating command MUST specify the target explicitly, with `--project` or a full resource path, rather than relying on the default `gcloud` project.
explicitly include, for each mutating step:
that the step cannot be undone (for example, service account key deletion).
Use the commands from the loaded playbook where they exist. If the playbook lacks a verification or rollback command for a step, derive the command and label it as not sourced from a playbook.
break as a result of each change and ask the user to confirm nothing depends on it. For example:
verify cross-project dependencies and CI/CD pipeline workflows that rely on the existing permissions before revoking a project-level role binding.
traffic on ports 80 or 443).
VM.
read it publicly.
turn that you present the remediation plan. You MUST end your turn immediately after asking for approval and wait for the user's next message.
run), stop at the plan and never execute.
approval, present the updated plan and ask for approval again before executing.
resolves the finding. When more than one fix would work, prefer reversible changes over irreversible ones (for example, disable a key before deleting it), resource-level changes over project, folder, or organization-level changes, and changes that affect only the finding's resource over changes that affect other resources. Do not bundle fixes for unrelated issues noticed along the way; mention them to the user separately.
Do not load all reference playbooks into memory at once. Analyze the Security Command Center finding's `category`, `findingClass`, or attack path, then read ONLY the relevant reference document(s).
Match on the finding's `category` **first**, and fall back to `findingClass` only when no category matches. Routing on `findingClass` alone misroutes IAM findings: Security Health Analytics IAM findings are `MISCONFIGURATION` class, and IAM recommender findings are `Vulnerability` class, so neither would ever reach the IAM playbook.
| Match On | Values | Target Reference Playbook | | :---------------------- | :---------------------------------------- | :--------------------------------------------------------------------------- | | `category` | `PRIMITIVE_ROLES_USED`, | [`references/remediation_iam.md`](references/remediation_iam.md) | : (Security Health : `OVER_PRIVILEGED_SERVICE_ACCOUNT_USER`, : : : Analytics) : `ADMIN_SERVICE_ACCOUNT`, : : : : `SERVICE_ACCOUNT_ROLE_SEPARATION`, : : : : `KMS_ROLE_SEPARATION`, : : : : `USER_MANAGED_SERVICE_ACCOUNT_KEY`, : : :
This repository contains Agent Skills for Google products and technologies, including Google Cloud.
Repo: google/skills
Google platform decision and setup guidance, loaded on demand from Google's skill catalog.…
Provides safety-critical validation, guardrails, and data reduction for gcloud CLI operations…
Provides expert guidance on Identity and Access Management (IAM) and authenticating and…
Guides a developer's first steps on Google Cloud, covering account creation, billing setup,…
Searches, retrieves, and synthesizes official Google developer documentation across Google…
Guides developers through managing (adding, removing, and clearing) audience members for…