skills/ google/skills

google-cloud-scc-query

Queries and retrieves active security findings, external exposures, toxic combinations, vulnerabilities, threats, and sensitive data risks from Security Command Center on Google Cloud. Use when retrieving details for a security finding by its name, validating finding scope (e.g., verifying findingCl

0
Installs
—
Rating
—
Success rate
2
Files scanned
Scan passedsecurity
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

2 files scannedscanner v1.2.0Oct 10, 2026

Content sha256 f33f36ab9f94b1ec… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Security Command Center Query Skill on Google Cloud

Provides guidelines and read-only gcloud CLI command patterns for querying and retrieving security findings, external exposures, toxic combinations, vulnerabilities, threats, and sensitive data risks from Security Command Center on Google Cloud.

[!IMPORTANT] There is NO gcloud scc findings describe command (Invalid choice: 'describe'). To retrieve details for a specific finding by its name, always use gcloud scc findings list with a filter on name.


Core Execution Rules

  1. Read-Only & Zero-Speculation (Parent Scope Required): Keep all executions strictly read-only. Every gcloud scc findings list or group command strictly requires an explicit {parent} scope (organizations/{id}, projects/{id}, or folders/{id}). If the parent scope is missing from the prompt and cannot be inferred from a full finding name, DO NOT run any gcloud commands (do not execute queries without parent, and never inspect gcloud config). Halt immediately before executing commands and ask the user for the parent resource scope.
  2. Bounded Execution & No Runaway Loops:
    • Limit tool calls to what is strictly necessary to complete the query (typically 1 call for direct queries, or 2 calls for List → Deep Dive workflows).
    • If a command fails due to permission/auth errors, or if a specific finding query returns [], halt immediately. Do not attempt blind brute-force retries with different flags, and never search the local workspace for credentials.
  3. Immediate Halt on Errors: If any command fails with PERMISSION_DENIED, IAM_PERMISSION_DENIED, credential expiration, or network timeouts, halt immediately and report the verbatim error message. Do not search the workspace for credentials or run diagnostic loops.
  4. Ambiguous or Multiple Findings: If multiple finding names are provided when a single finding report is requested, or if listing returns multiple findings, do not investigate all of them or unilaterally pick one. Halt immediately without running queries and ask the user to clarify which specific finding name they want details for. If zero findings are returned from a query, report that no active findings exist and halt immediately.
  5. Do Not Query Attack Path Resources: Analyze only the data present in the Security Command Center finding JSON payload. Do not run commands to describe, verify, or query underlying Google Cloud resources (such as VMs, Cloud Storage buckets, service accounts, or IAM policies).
  6. Parent Scope Resolution:
    • For listing and grouping, format the parent resource path as organizations/{org_id}, projects/{project_id}, or folders/{folder_id}.
    • For deep dive queries on a specific finding name, extract the {parent} resource prefix before /sources/...:
      • organizations/{org_id}/sources/... → {parent} is organizations/{org_id}
      • folders/{folder_id}/sources/... → {parent} is folders/{folder_id}
      • projects/{project_id}/sources/... → {parent} is projects/{project_id} Extract the parent prefix regardless of whether the finding resource name is global (4-segment) or location-qualified (5-segment with /locations/{location}/). Execute the deep dive query using the extracted {parent}. Do not reject or halt on project- or folder-level findings.

Data Residency & Regional Endpoints

When Data Residency (DRZ) is enabled, findings are stored and accessible only within their designated regional location (us, eu, or me-central2). Queries across different locations do not return findings from other regions.

1. Location Parameterization

All gcloud scc findings commands require specifying the target location via --location={location}:

  • Default: global (used when data residency is not enabled or for global findings).
  • Supported Regional Locations:
    • us (United States multi-region)
    • eu (European Union multi-region)
    • me-central2 (Kingdom of Saudi Arabia regional location)

2. API Endpoint Overrides

When data residency (DRZ) is enabled for an organization in a regional location (us, eu, or me-central2), configure the regional API endpoint override before executing finding queries:

gcloud config set api_endpoint_overrides/securitycenter https://securitycenter.{LOCATION}.rep.googleapis.com/

Example for the European Union (eu) region:

gcloud config set api_endpoint_overrides/securitycenter https://securitycenter.eu.rep.googleapis.com/

To reset the endpoint back to default global routing:

gcloud config unset api_endpoint_overrides/securitycenter

3. Location-Qualified Finding Resource Names

Regional finding resource names include the /locations/{location}/ path segment:

  • Organization-level: organizations/{org_id}/sources/{source_id}/locations/{location}/findings/{finding_id}
  • Folder-level: folders/{folder_id}/sources/{source_id}/locations/{location}/findings/{finding_id}
  • Project-level: projects/{project_id}/sources/{source_id}/locations/{location}/findings/{finding_id}

When performing a Deep Dive on a location-qualified finding name:

  1. Extract the {parent} scope (the prefix before /sources/..., e.g., organizations/{org_id}).
  2. Extract the {location} from /locations/{location}/ (e.g., eu, us, me-central2). If not present in the finding name, default to global (or the user-specified location).
  3. Execute the query with --location={location} and --filter="name=\"{finding_name}\"".

Intent-Based Query Strategies

1. Deep Dive (Specific Finding Details)

Intent: User provides a specific finding name or explicitly asks to retrieve all details for one finding.
Action: Execute gcloud scc findings list with a strict filter on name and NO --field-mask to retrieve the complete JSON payload. Specify --location={location} (default global unless a regional location is indicated or present in the finding name).

gcloud scc findings list {parent} \
  --location={location} \
  --filter="name=\"{finding_name}\"" \
  --format="json" --limit=1

2. Listing (Filtered Projection)

Intent: User wants to list active findings matching criteria without pulling full nested payloads.
Action: Use --field-mask projection to restrict output size. Specify --location={location} (default global unless querying a specific region).

gcloud scc findings list {parent} \
  --location={location} \
  --filter="{filter_expression}" \
  --field-mask="finding.name,finding.parentDisplayName,finding.findingClass,finding.category,finding.state,finding.eventTime,finding.severity,finding.resourceName" \
  --format="json" --order-by="severity,event_time desc" --limit=100
Intent / Target Finding Class--filter Expression
All Active Findingsstate="ACTIVE"
Vulnerabilities`state="ACTIVE" AND
: : findingClass="VULNERABILITY"` :
Misconfigurations`state="ACTIVE" AND
: : findingClass="MISCONFIGURATION"` :
Toxic Combinations`state="ACTIVE" AND
: : findingClass="TOXIC_COMBINATION"` :
External Exposures`state="ACTIVE" AND
: : findingClass="EXTERNAL_EXPOSURE"` :
Threatsstate="ACTIVE" AND findingClass="THREAT"
Observations`state="ACTIVE" AND
: : findingClass="OBSERVATION"` :
Sensitive Data Risks`state="ACTIVE" AND
: : findingClass="SENSITIVE_DATA_RISK"` :
Chokepoints`state="ACTIVE" AND
: : findingClass="CHOKEPOINT"` :
Posture Violations`state="ACTIVE" AND
: : findingClass="POSTURE_VIOLATION"` :
Secretsstate="ACTIVE" AND findingClass="SECRET"
SCC Errors`state="ACTIVE" AND
: : findingClass="SCC_ERROR"` :
Specific Categorystate="ACTIVE" AND category="{category}"

3. Discovery & Aggregation (Grouping)

Intent: User wants high-level counts or landscape overview (e.g., "What are the most common findings?", "Show me a summary by category").
Action: Use gcloud scc findings group. Specify --location={location} (default global unless querying a specific region). Allowed fields for --group-by are strictly: resource_name, category, state, parent.

gcloud scc findings group {parent} \
  --location={location} \
  --group-by="{group_by_field}" \
  --filter="state=\"ACTIVE\"" \
  --format="json"

Payload Analysis & Handoff

Once the finding JSON payload is retrieved:

  • For TOXIC_COMBINATION Findings:
    1. Verify the attackExposure field is present and has a score > 0.
    2. Inspect the attack path nodes, edges, or referenced attackExposureResult to identify exposed resources and attack trajectories.
  • For VULNERABILITY Findings:
    1. Extract CVSS scores, exploit signals (exploitationActivity, observedInTheWild, zeroDay), upstream fix status (upstreamFixAvailable), and affected package details from the vulnerability object to evaluate risk:
      • vulnerability.cve.id
      • vulnerability.cve.cvssv3.baseScore
      • vulnerability.cve.cvssv3.attackVector
      • vulnerability.cve.exploitationActivity
      • vulnerability.cve.observedInTheWild
      • vulnerability.cve.zeroDay
      • vulnerability.cve.upstreamFixAvailable
      • vulnerability.offendingPackage.packageName
      • vulnerability.offendingPackage.packageVersion
      • vulnerability.fixedPackage.packageVersion
      • vulnerability.securityBulletin.suggestedUpgradeVersion
  • Handoff: Do not draft remediation plans, patch resources, or execute configuration commands. Pass the extracted finding payload to the appropriate remediation or IAM analyzer skill to manage the remediation action loop.

Reference Schema

See finding_schema.md for the JSON structure of a Security Command Center finding.

Files

2
15.7 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from google/skills8

agent-platform-alert-configuration

Configures best-practice alerting policies for AI agents using OpenTelemetry (OTel) metrics, generating output as Terraform (.tf) configuration files. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, token usage, and quality metrics. Don't use for st

Needs review 0
agent-platform-deploy

Deploy open models or custom weights from Model Garden to Agent Platform endpoints, check the status of an in-progress deployment operation, or clean up resources by undeploying models and deleting endpoints. Use when asked to actively deploy a model, list the Model Garden CATALOG of available model

Scan passed 0
agent-platform-endpoint-management

Manages Agent Platform serving endpoints. Use when you need to create, list, describe, update, or delete serving endpoints for model deployment on Agent Platform. Also use when troubleshooting endpoint permission, quota, or resource busy errors. Don't use for deploying models to endpoints or for run

Scan passed 0
agent-platform-eval-flywheel

Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when generating synthetic user scenarios, evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results be

Scan passed 0
agent-platform-inference

Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when asked to perform inference, ask a model a question, run a test prompt, execute chat completions, or generate c

Scan passed 0
agent-platform-migrate-from-ai-studio

Guides agents and users through migrating from Gemini API in Google AI Studio to Gemini Enterprise Agent Platform (formerly Vertex AI). Use this skill when moving applications to Google Cloud, to leverage Cloud credits, or to unify inferencing with other Cloud infrastructure (IAM, billing, telemetry

Scan passed 0
agent-platform-model-registry

Agent Platform Model Registry Management. Use when you need to upload, list, describe, update, or delete machine learning models (and their versions) in the Agent Platform Model Registry. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform models.

Scan passed 0
agent-platform-prompt-management

Manages and orchestrates prompts in Agent Platform. Use when you need to create, list, retrieve, version, or delete managed prompts in Agent Platform. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform prompts.

Scan passed 0

Related security skillsscan passed

client-setup

Create a vanilla tRPC client with createTRPCClient<AppRouter>(), configure link chain with httpBatchLink/httpLink, dynamic headers for auth, transformer on links (not client constructor). Infer types with inferRouterInputs and inferRouterOutputs. AbortController signal support. TRPCClientError typin

Scan passed 0
security-and-hardening

Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data,

Scan passed 0
ponytail-audit

Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split. Ranked, each finding explained in plain English. One-shot report, changes nothing. Use for "audit this codebase", "review the whole repo", "find

Scan passed 0
opensource-pipeline

Open-source pipeline: fork, sanitize, and package private projects for safe public release. Chains 3 agents (forker, sanitizer, packager). Triggers: '/opensource', 'open source this', 'make this public', 'prepare for open source'. Use when a private project must be forked, stripped of secrets, and p

Scan passed 0
extension-to-functions-codebase

Skill for converting an installed Firebase Extension (or extension source) into a standalone Cloud Functions for Firebase codebase or publishable npm package, including V1 to V2 trigger upgrades, lifecycle hooks, and declarative security

Scan passed 0
creating-secrets-using-best-practices

Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management that are essential for product

Scan passed 0