/google-cloud-waf-security
Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate workloads, identify security requirements, and provide actionable recommendations
$ npx -y skills add google/skills --skill google-cloud-waf-security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/google-cloud-waf-security
Context preview
The summary Claude sees to decide when to auto-load this skill.
Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate workloads, identify security requirements, and provide actionable recommendations
SKILL.md
google-cloud-waf-security.SKILL.mdname: google-cloud-waf-security
metadata:
category: WellArchitectedFramework
description: >-
Generates security-focused guidance for Google Cloud workloads based on the
design principles and recommendations in the Google Cloud Well-Architected
Framework (WAF). Use this skill to evaluate workloads, identify security
requirements, and provide actionable recommendations for IAM, network
security, data protection, and operational security.
Google Cloud Well-Architected Framework skill for the Security pillar
Overview
The security pillar of the Google Cloud Well-Architected Framework provides design principles and best practices for building a robust security posture by integrating security into every layer of the architecture for cloud workloads. It focuses on maintaining confidentiality and integrity of data and systems while ensuring compliance and privacy. It provides a structured approach to risk management, threat defense, and identity control, enabling you to operate cloud workloads securely and at scale.
Workflow
When this skill is activated, follow these steps to evaluate and improve the security posture of the specified Google Cloud workload:
1. **Understand the context**: Ask targeted questions from the **Workload assessment questions** list to gather information about the user's current architecture, security requirements, and constraints. 2. **Analyze and identify gaps**: Evaluate the workload against the **Core principles** and the **Validation checklist** to identify security vulnerabilities, missing controls, or deviations from best practices. 3. **Formulate recommendations**: Provide actionable, prioritized guidance based on the Google Cloud Well-Architected Framework. Recommend specific products from **Relevant Google Cloud products** to address the identified gaps. 4. **Explain the recommendations**: Align all recommendations with the appropriate **Core principles** and state the benefits that each recommendation provides. 5. **Iterate and refine**: Help the user adapt the recommendations to their specific requirements and constraints.
Core principles
The recommendations in the security pillar of the Well-Architected Framework are aligned with the following core principles:
- **Implement security by design**: Integrate cloud security and network
security considerations starting from the initial design phase of your applications and infrastructure. Google Cloud provides architecture blueprints and recommendations to help you apply this principle. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt
- **Implement zero trust**: Use a _never trust, always verify_ approach, where
access to resources is granted based on continuous verification of trust. Google Cloud supports this principle through products like Chrome Enterprise Premium, Identity-Aware Proxy (IAP) and IAM Recommender. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt
- **Implement shift-left security**: Implement security controls early in the
software development lifecycle. Avoid security defects before system changes are made. Detect and fix security bugs early, fast, and reliably after the system changes are committed. Google Cloud supports this principle through products like Cloud Build, Binary Authorization, and Artifact Registry. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt
- **Implement preemptive cyber defense**: Adopt a proactive approach to
security by implementing robust fundamental measures like threat intelligence. This approach helps you build a foundation for more effective threat detection and response. Google Cloud's approach to layered security controls aligns with this principle. Google Cloud supports this principle through products like Security Command Center, Google Threat Intelligence, and Google SecOps. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt
- **Use AI securely and responsibly**: Develop and deploy AI systems in a
responsible and secure manner. The recommendations for this principle are aligned with guidance in the AI and ML perspective of the Well-Architected Framework and in Google's Secure AI Framework (SAIF). Grounding document: https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt
- **Use AI for security**: Use AI capabilities to improve your existing
security systems and processes through Gemini in Security and overall platform-security capabilities. Use AI as a tool to increase the automation of remedial work and ensure security hygiene to make other systems more secure. Google Cloud supports this principle through products like Google Threat Intelligence and Google SecOps. Grounding document: https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt
- **Meet regulatory, compliance, and privacy needs**: Adhere to
industry-specific regulations, compliance standards, and privacy requirements. Google Cloud helps you meet these obligations through products like Assured Workloads, Organization Policy Service, and our compliance resource center. Grounding document: https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt
- **Shared responsibilities and shared fate on Google Cloud**: Understand that
Google is responsible for the security _of_ the cloud and you're responsible for the security of your workloads _in_ the cloud. Recognize how this division of responsibilities varies based on the workload type. Learn what Google does to help ensure that security _of_ t
Read more
name: google-cloud-waf-security metadata: category: WellArchitectedFramework description: >- Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate workloads, identify security requirements, and provide actionable recommendations for IAM, network security, data protection, and operational security.
Google Cloud Well-Architected Framework skill for the Security pillar
Overview
The security pillar of the Google Cloud Well-Architected Framework provides design principles and best practices for building a robust security posture by integrating security into every layer of the architecture for cloud workloads. It focuses on maintaining confidentiality and integrity of data and systems while ensuring compliance and privacy. It provides a structured approach to risk management, threat defense, and identity control, enabling you to operate cloud workloads securely and at scale.
Workflow
When this skill is activated, follow these steps to evaluate and improve the security posture of the specified Google Cloud workload:
1. **Understand the context**: Ask targeted questions from the **Workload assessment questions** list to gather information about the user's current architecture, security requirements, and constraints. 2. **Analyze and identify gaps**: Evaluate the workload against the **Core principles** and the **Validation checklist** to identify security vulnerabilities, missing controls, or deviations from best practices. 3. **Formulate recommendations**: Provide actionable, prioritized guidance based on the Google Cloud Well-Architected Framework. Recommend specific products from **Relevant Google Cloud products** to address the identified gaps. 4. **Explain the recommendations**: Align all recommendations with the appropriate **Core principles** and state the benefits that each recommendation provides. 5. **Iterate and refine**: Help the user adapt the recommendations to their specific requirements and constraints.
Core principles
The recommendations in the security pillar of the Well-Architected Framework are aligned with the following core principles:
- **Implement security by design**: Integrate cloud security and network
security considerations starting from the initial design phase of your applications and infrastructure. Google Cloud provides architecture blueprints and recommendations to help you apply this principle. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt
- **Implement zero trust**: Use a _never trust, always verify_ approach, where
access to resources is granted based on continuous verification of trust. Google Cloud supports this principle through products like Chrome Enterprise Premium, Identity-Aware Proxy (IAP) and IAM Recommender. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt
- **Implement shift-left security**: Implement security controls early in the
software development lifecycle. Avoid security defects before system changes are made. Detect and fix security bugs early, fast, and reliably after the system changes are committed. Google Cloud supports this principle through products like Cloud Build, Binary Authorization, and Artifact Registry. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt
- **Implement preemptive cyber defense**: Adopt a proactive approach to
security by implementing robust fundamental measures like threat intelligence. This approach helps you build a foundation for more effective threat detection and response. Google Cloud's approach to layered security controls aligns with this principle. Google Cloud supports this principle through products like Security Command Center, Google Threat Intelligence, and Google SecOps. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt
- **Use AI securely and responsibly**: Develop and deploy AI systems in a
responsible and secure manner. The recommendations for this principle are aligned with guidance in the AI and ML perspective of the Well-Architected Framework and in Google's Secure AI Framework (SAIF). Grounding document: https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt
- **Use AI for security**: Use AI capabilities to improve your existing
security systems and processes through Gemini in Security and overall platform-security capabilities. Use AI as a tool to increase the automation of remedial work and ensure security hygiene to make other systems more secure. Google Cloud supports this principle through products like Google Threat Intelligence and Google SecOps. Grounding document: https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt
- **Meet regulatory, compliance, and privacy needs**: Adhere to
industry-specific regulations, compliance standards, and privacy requirements. Google Cloud helps you meet these obligations through products like Assured Workloads, Organization Policy Service, and our compliance resource center. Grounding document: https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt
- **Shared responsibilities and shared fate on Google Cloud**: Understand that
Google is responsible for the security _of_ the cloud and you're responsible for the security of your workloads _in_ the cloud. Recognize how this division of responsibilities varies based on the workload type. Learn what Google does to help ensure that security _of_ t
This repository contains Agent Skills for Google products and technologies, including Google Cloud. This repository is under active development.
Repo: google/skills
Other skills on google-skills.
- /data-manager-api-audience-ingestion
Guides developers through managing (adding, removing, and clearing) audience members for Google products using the Data Manager API and its associated client libraries. Use this skill when the user wants to upload audience members, remove specific users, or clear/replace an
Open skill - /data-manager-api-event-ingestion
Guides developers through implementing event and conversion ingestion to Google products using the Data Manager API /v1/events/ingest endpoint and its associated client libraries. Use this skill when the user wants to upload offline conversions, enhanced conversions for leads,
Open skill - /data-manager-api-setup
Guides developers through client library installation and authentication setup steps for the Data Manager API. Use this skill when a user is getting started with the Data Manager API and needs to setup their local environment, install the client library, or setup access to the
Open skill - /google-ads-api-account-diagnostics
Diagnoses Google Ads account performance issues such as conversion loss (value or volume), low lead flow/volume, and lost impression share (opportunities) due to ad rank, bids, or budgets. Use when troubleshooting sudden performance drops, analyzing campaign impression share
Open skill - /google-ads-api-mcp-setup
Guides developers through downloading, configuring, and installing the official open-source Google Ads MCP Server. Use this skill when a user wants to connect their AI assistant (such as Gemini, Claude Code, or Cursor) to their Google Ads account to query campaigns or retrieve
Open skill - /google-ads-api-quickstart
Guides developers through Google Ads API quickstart: credential setup, choosing from 6 client libraries/REST, configuring environments, and running a "retrieve campaigns" script. Troubleshoots common setup errors: USER_PERMISSION_DENIED, login_customer_id issues, and
Open skill

