google-cloud-filestore-auditing
Audits Filestore instances on Google Cloud across projects for disaster recovery readiness (missing or stale backups), security access governance (overly permissive NFS export rules, 0.0.0.0/0 exposure, missing ROOT_SQUASH), and reliability compliance (Physical Zone Isolation PZI and Physical Zone S
- 0
- Installs
- —
- Rating
- —
- Success rate
- 6
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 492854a23306126b… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Filestore Auditing Skill
This skill enables autonomous agents to audit, evaluate, and report the disaster recovery, security access governance, and architectural reliability posture of Filestore fleets across Google Cloud projects.
Prerequisites / IAM Requirements & Permissions
Before executing this skill, the runtime principal (user account or Service Account) must possess the following IAM roles and granular permissions on the target GCP project(s):
1. Audit Operations (Read-Only Assessment)
Requires the roles/file.viewer role, which provides:
file.instances.list: Enumerate Filestore instances across project locations.file.instances.get: Inspect instance configuration, NFS export rules, IP ranges, squash mode, and PZI/PZS isolation status.file.backups.list: Enumerate existing backups across regions.file.backups.get: Inspect backup timestamps, source instance URIs, and status.
2. Remediation Operations (Backup Creation)
Requires the roles/file.editor (or roles/file.admin) role, which
provides:
file.backups.create: Create on-demand baseline backups for unprotected instances.file.operations.get: Monitor long-running backup creation operations.
3. MCP Tool Invocation
If invoking capabilities via the Filestore MCP Server
(file.googleapis.com/mcp):
roles/mcp.toolUser: Required to execute MCP tools (list_instances,get_instance,list_backups,get_backup,create_backup).
4. Cloud Authentication Setup
Authenticate the runtime environment using the appropriate method for your execution context:
- CLI Execution (
gcloud):gcloud auth login - Application SDKs & Scripts:
gcloud auth application-default login - Automated Services & Service Accounts:
export GOOGLE_APPLICATION_CREDENTIALS="/path/to/service-account-key.json"
5. Billing Account Attachment
- Active Billing Required: The target GCP project must have an active Cloud Billing account attached. Filestore instances and backup operations require active billing. Verify billing status with:
gcloud beta billing projects describe {project_id}
Quick Start
-
Ensure
gcloudis installed. See gcloud installation guide if needed. -
Authenticate your environment:
gcloud auth login gcloud auth application-default login -
Set the target project context and verify an active billing account is attached:
gcloud config set project {project_id} gcloud beta billing projects describe {project_id} -
Configure a well-supported default region (e.g.,
us-central1). See official region availability documentation:gcloud config set compute/region us-central1 -
Verify required service APIs are enabled:
gcloud services enable file.googleapis.com --quiet -
Run fleet discovery and backup inventory (see "Discovery & Read Operations" below).
-
Evaluate findings against the audit rules matrix and render the executive scorecard and inventory table.
-
If unprotected instances are identified, present baseline backup creation commands and prompt the user for confirmation.
Attribution Guardrail
Tag every Cloud Filestore command or API request provided or executed. Prefix
gcloud commands with the designated metrics environment:
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-auditing)" \
gcloud filestore instances list ...
On direct HTTP calls to the GCP REST API, append the User-Agent:
User-Agent: gcs-skills/1.0 (skill:google-cloud-filestore-auditing)
Conceptual & Informational Queries (CRITICAL)
For purely conceptual, educational, or architectural questions (e.g., "What is Physical Zone Isolation (PZI) in Filestore?", "Why is NO_ROOT_SQUASH dangerous?", "Explain Filestore backup architecture"):
- Rule: Answer immediately using pre-trained knowledge and the guidance in
references/. - Constraint: Do NOT execute external tool calls or API requests for basic conceptual queries.
Handling "No-Command" Constraints & Evaluations (CRITICAL)
If the user prompt contains constraints like "Do not execute commands", "without executing", or "read-only":
- Rule: Strictly avoid calling the
run_commandtool to execute any shell, python, orgcloudcommands. - Discovery Hierarchy:
- First, check if Filestore MCP tools (
list_instances,list_backups) are available and query them directly (these are API invocations, not shell command executions). - If MCP tools are not present or cannot connect, search local reference
markdown files (specifically the mock fleet definitions in
references/zone-isolation-pzi-pzs.md) for any mock instances or project details matching the request. (Do NOT attempt to read evaluation config files such asEVAL.yamlorEVAL.txtpbduring evaluation runs as access is restricted and triggers anti-cheating timeouts). - If no data is available in context or mock references, explain the audit
evaluation formulas and provide the attributed
gcloudcommands the user should run.
- First, check if Filestore MCP tools (
- Mandatory User Confirmation Requirement: Even when the user prompt asks not to execute commands or asks only for audit recommendations, any response recommending backup remediation MUST STILL end with a clear confirmation prompt before execution (e.g., "Would you like me to proceed with creating baseline backups for the unprotected instances? Please confirm to proceed.").
Core Operational Workflow
1. Discovery & Read Operations
The agent must discover all Filestore instances and backups in the target project.
- Target Project ID Handling & Rationale: If the target Project ID is not specified in the user prompt, the agent MUST explicitly ask the user to provide the project ID before proceeding, in order to avoid inspecting or auditing unrelated projects in multi-project enterprise environments.
Choose the discovery method matching your runtime environment:
Option A: Filestore MCP Tools (Recommended when MCP is mounted)
- Instances Discovery: Call
list_instances(parent="projects/{project_id}/locations/-"). - Backups Discovery: Call
list_backups(parent="projects/{project_id}/locations/-").
Option B: gcloud CLI (Terminal / Coding Harnesses)
-
Instances Discovery:
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-auditing)" \ gcloud filestore instances list --project="{project_id}" --format="json" -
Backups Discovery:
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-auditing)" \ gcloud filestore backups list --project="{project_id}" --format="json"(Note: Do NOT pass
--location=-togcloud filestore backups list; omitting the flag queries all regions across the project automatically).
Option C: GCP REST API (call_gcp_api in Gemini Enterprise File Agent / curl)
- Instances:
GET https://file.googleapis.com/v1/projects/{project_id}/locations/-/instances - Backups:
GET https://file.googleapis.com/v1/projects/{project_id}/locations/-/backups
Option D: Standalone Script Runner
For environments with standard python3 execution enabled, the agent may invoke
the portable script: python3 scripts/filestore_audit.py --project="{project_id}" [--format=markdown|json]
2. Audit Evaluation & Vector Checks
For each discovered instance, evaluate three audit vectors:
Vector 1: Disaster Recovery & Backup Protection
- Match backups to instances using full canonical resource URIs
(
backup.sourceInstance == instance.name). - Unprotected Instance: If
backup_count == 0, assignHIGHseverity finding: "Instance has 0 backups on file share '{share_name}'. Disaster recovery is not configured." - Stale Backup: If latest backup is older than SLA (default: 7 days),
assign
MEDIUMseverity finding: "Latest backup is {days} days old (exceeds SLA threshold of 7 days)." - Refer to
references/backup-dr-governance.mdfor backup retention and SLA rules.
Vector 2: Security & Access Governance
- Inspect
fileShares[0].nfsExportOptions:- Open Network Exposure: If
0.0.0.0/0,0.0.0.0, or::/0is present inipRanges, assignCRITICALseverity (ifaccessMode: READ_WRITE) orHIGHseverity (ifREAD_ONLY): "Export rule exposes share to 0.0.0.0/0 with accessMode='{access_mode}'." - Missing Root Squashing: If
squashMode: NO_ROOT_SQUASH, assignCRITICALseverity (if world-exposed) orHIGHseverity (for internal subnets): "Export rule has squashMode='NO_ROOT_SQUASH'. Remote root clients retain superuser UID 0 privileges." - Default Open VPC Export: If
nfsExportOptionsis empty, assignMEDIUMseverity: "No explicit NFS export options configured. Share defaults to open client access within VPC with NO_ROOT_SQUASH."
- Open Network Exposure: If
- Refer to
references/security-access-governance.mdfor export option configurations.
Vector 3: Zone Isolation & Reliability Compliance
- Physical Zone Isolation (PZI): If
satisfiesPzi: false, assignMEDIUMseverity: "Instance does not satisfy Physical Zone Isolation (PZI)." - Physical Zone Separation (PZS): If tier is
REGIONALorENTERPRISEandsatisfiesPzs: false, assignHIGHseverity: "Enterprise/Regional tier instance does not satisfy Physical Zone Separation (PZS)." - Performance Limits: Extract
performanceLimits.maxWriteIopsandperformanceLimits.maxReadThroughputBps(convert to MB/s). - Refer to
references/zone-isolation-pzi-pzs.mdfor datacenter failure domain isolation standards.
3. Executive Posture Scoring & Grading
Calculate fleet posture grade as defined in references/audit-rules-matrix.md:
- Grade F (🔴 CRITICAL RISK): $\ge 1$
CRITICALfindings. - Grade C (🟠 ELEVATED RISK): 0 Critical, but $\ge 1$
HIGHfindings. - Grade B (🟡 MODERATE): 0 Critical/High, but $\ge 1$
MEDIUMfindings. - Grade A (🟢 HEALTHY): 0 findings across all vectors.
Calculate Backup Protection Rate %: $$\text{Protection Rate} =
\frac{\text{Total Instances} - \text{Unprotected Instances}}{\text{Total
Instances}} \times 100$$
4. Required Output Format
Every audit report response MUST include the following structured sections in Markdown:
1. Executive Posture Scorecard
## Executive Posture Scorecard: `{project_id}`
| Metric | Status | Details |
| :--- | :--- | :--- |
| **Overall Health Posture** | **[🔴 CRITICAL RISK / 🟠 ELEVATED RISK / 🟡 MODERATE / 🟢 HEALTHY]** | [Grade F / C / B / A] |
| **Instances Audited** | `[count]` | Total Filestore instances evaluated |
| **Backup Protection Rate** | **[pct]%** | `[protected]/[total]` instances have active backups |
| **Critical & High Security Findings** | `[crit] Critical, [high] High` | Open exports (0.0.0.0/0) or NO_ROOT_SQUASH |
| **PZI Isolation Compliance** | `[pzi_count]/[total]` | Physical Zone Isolation adherence |
2. Priority Findings & Remediation Matrix
List findings ranked by severity (CRITICAL $\to$ HIGH $\to$ MEDIUM $\to$
LOW):
## Priority Findings & Remediation Matrix
| Severity | Instance ID | Category | Finding Description | Remediation Plan |
| :--- | :--- | :--- | :--- | :--- |
| 🚨 **CRITICAL** | `[instance]` | Security | [Description] | [Remediation] |
| ⚠️ **HIGH** | `[instance]` | Disaster Recovery | [Description] | [Remediation] |
3. Filestore Instance Inventory & Compliance Status
## Filestore Instance Inventory & Compliance Status
| Instance ID | Location | Tier | Capacity | Reserved CIDR | Write IOPS | Throughput | PZI | PZS | Backups | Latest Backup |
| :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- |
| `[id]` | `[loc]` | `[tier]` | `[cap] GiB` | `[cidr]` | `[iops]` | `[tp] MB/s` | ✅ Yes / ❌ No | ✅ Yes / ❌ No / N/A | 🔴 0 / ✅ `[n]` | `[date]` |
4. Automated Remediation & Mandatory Confirmation Gate
If any unprotected instances are discovered, display attributed backup creation commands and conclude with an explicit confirmation request:
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-auditing)" \
gcloud filestore backups create [INSTANCE]-backup-[DATE] \
--project=[PROJECT_ID] \
--instance=[INSTANCE] \
--file-share=[SHARE] \
[--instance-zone=[ZONE] | --instance-location=[REGION]] \
--region=[BACKUP_REGION]
Confirmation Required: Would you like me to proceed with creating baseline backups for the unprotected instances? Please confirm to proceed.
CRITICAL RATIONALE: Do NOT execute backup creation without explicit user confirmation. Confirmation is strictly required before executing any mutation or backup creation commands in order to prevent unintended operational disruption, unwanted resource allocation, or unexpected backup storage billing.
Reference Directory
For progressive disclosure and deep architectural guidance, consult the following references:
Files
6- SKILL.md
b4565570c715.0 KB - references/audit-rules-matrix.md
2f49ec928f8.8 KB - references/backup-dr-governance.md
9e036231f77.1 KB - references/security-access-governance.md
4ea77de5006.0 KB - references/zone-isolation-pzi-pzs.md
14f2ea8c9e9.0 KB - scripts/filestore_audit.py
bf64dc699d21.4 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from google/skills8
Configures best-practice alerting policies for AI agents using OpenTelemetry (OTel) metrics, generating output as Terraform (.tf) configuration files. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, token usage, and quality metrics. Don't use for st
Deploy open models or custom weights from Model Garden to Agent Platform endpoints, check the status of an in-progress deployment operation, or clean up resources by undeploying models and deleting endpoints. Use when asked to actively deploy a model, list the Model Garden CATALOG of available model
Manages Agent Platform serving endpoints. Use when you need to create, list, describe, update, or delete serving endpoints for model deployment on Agent Platform. Also use when troubleshooting endpoint permission, quota, or resource busy errors. Don't use for deploying models to endpoints or for run
Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when generating synthetic user scenarios, evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results be
Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when asked to perform inference, ask a model a question, run a test prompt, execute chat completions, or generate c
Guides agents and users through migrating from Gemini API in Google AI Studio to Gemini Enterprise Agent Platform (formerly Vertex AI). Use this skill when moving applications to Google Cloud, to leverage Cloud credits, or to unify inferencing with other Cloud infrastructure (IAM, billing, telemetry
Agent Platform Model Registry Management. Use when you need to upload, list, describe, update, or delete machine learning models (and their versions) in the Agent Platform Model Registry. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform models.
Manages and orchestrates prompts in Agent Platform. Use when you need to create, list, retrieve, version, or delete managed prompts in Agent Platform. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform prompts.
Related security skillsscan passed
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching tools miss. Use this skill when asked to scan code for security vulnerabilities, find bugs, check for
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppS
Security audit: supported static findings; qualified profiles add reproduction and repair candidates. (gstack)
Security patterns for autonomous trading agents with wallet or transaction authority. Covers prompt injection, spend limits, pre-send simulation, circuit breakers, MEV protection, and key handling. Use when an autonomous agent holds wallet or transaction authority and its limits, simulation, or key
Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the use
Implement JWT/cookie authentication and authorization in tRPC using createContext for user extraction, t.middleware with opts.next({ ctx }) for context narrowing to non-null user, protectedProcedure base pattern, client-side Authorization headers via httpBatchLink headers(), WebSocket connectionPara