Skip to content
Development
Skill

/google-cloud-waf-security

Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate workloads, identify security requirements, and provide actionable recommendations

From plugin
google-skills
17k104 skills
Install
$ npx -y skills add google/skills --skill google-cloud-waf-security --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/google-cloud-waf-security

Context preview

The summary Claude sees to decide when to auto-load this skill.

Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate workloads, identify security requirements, and provide actionable recommendations

SKILL.md

google-cloud-waf-security.SKILL.md
name: google-cloud-waf-security
metadata:
  category: WellArchitectedFramework
description: >-
  Generates security-focused guidance for Google Cloud workloads based on the
  design principles and recommendations in the Google Cloud Well-Architected
  Framework (WAF). Use this skill to evaluate workloads, identify security
  requirements, and provide actionable recommendations for IAM, network
  security, data protection, and operational security.

Google Cloud Well-Architected Framework skill for the Security pillar

Overview

The security pillar of the Google Cloud Well-Architected Framework provides design principles and best practices for building a robust security posture by integrating security into every layer of the architecture for cloud workloads. It focuses on maintaining confidentiality and integrity of data and systems while ensuring compliance and privacy. It provides a structured approach to risk management, threat defense, and identity control, enabling you to operate cloud workloads securely and at scale.

Workflow

When this skill is activated, follow these steps to evaluate and improve the security posture of the specified Google Cloud workload:

1. **Understand the context**: Ask targeted questions from the **Workload assessment questions** list to gather information about the user's current architecture, security requirements, and constraints. 2. **Analyze and identify gaps**: Evaluate the workload against the **Core principles** and the **Validation checklist** to identify security vulnerabilities, missing controls, or deviations from best practices. 3. **Formulate recommendations**: Provide actionable, prioritized guidance based on the Google Cloud Well-Architected Framework. Recommend specific products from **Relevant Google Cloud products** to address the identified gaps. 4. **Explain the recommendations**: Align all recommendations with the appropriate **Core principles** and state the benefits that each recommendation provides. 5. **Iterate and refine**: Help the user adapt the recommendations to their specific requirements and constraints.

Core principles

The recommendations in the security pillar of the Well-Architected Framework are aligned with the following core principles:

  • **Implement security by design**: Integrate cloud security and network

security considerations starting from the initial design phase of your applications and infrastructure. Google Cloud provides architecture blueprints and recommendations to help you apply this principle. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design.md.txt

  • **Implement zero trust**: Use a _never trust, always verify_ approach, where

access to resources is granted based on continuous verification of trust. Google Cloud supports this principle through products like Chrome Enterprise Premium, Identity-Aware Proxy (IAP) and IAM Recommender. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust.md.txt

  • **Implement shift-left security**: Implement security controls early in the

software development lifecycle. Avoid security defects before system changes are made. Detect and fix security bugs early, fast, and reliably after the system changes are committed. Google Cloud supports this principle through products like Cloud Build, Binary Authorization, and Artifact Registry. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security.md.txt

  • **Implement preemptive cyber defense**: Adopt a proactive approach to

security by implementing robust fundamental measures like threat intelligence. This approach helps you build a foundation for more effective threat detection and response. Google Cloud's approach to layered security controls aligns with this principle. Google Cloud supports this principle through products like Security Command Center, Google Threat Intelligence, and Google SecOps. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense.md.txt

  • **Use AI securely and responsibly**: Develop and deploy AI systems in a

responsible and secure manner. The recommendations for this principle are aligned with guidance in the AI and ML perspective of the Well-Architected Framework and in Google's Secure AI Framework (SAIF). Grounding document: https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly.md.txt

  • **Use AI for security**: Use AI capabilities to improve your existing

security systems and processes through Gemini in Security and overall platform-security capabilities. Use AI as a tool to increase the automation of remedial work and ensure security hygiene to make other systems more secure. Google Cloud supports this principle through products like Google Threat Intelligence and Google SecOps. Grounding document: https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security.md.txt

  • **Meet regulatory, compliance, and privacy needs**: Adhere to

industry-specific regulations, compliance standards, and privacy requirements. Google Cloud helps you meet these obligations through products like Assured Workloads, Organization Policy Service, and our compliance resource center. Grounding document: https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs.md.txt

  • **Shared responsibilities and shared fate on Google Cloud**: Understand that

Google is responsible for the security _of_ the cloud and you're responsible for the security of your workloads _in_ the cloud. Recognize how this division of responsibilities varies based on the workload type. Learn what Google does to help ensure that security _of_ t

Read more
Ships withgoogle-skills

This repository contains Agent Skills for Google products and technologies, including Google Cloud. This repository is under active development.

Get the whole plugin

Other skills on google-skills.