google-cloud-solution-multi-agent-security
Designs, deploys, and secures Google Cloud Agent Gateway solutions. Use when the user needs to configure multi-agent security, ingress (CLIENT_TO_AGENT), or egress (AGENT_TO_ANYWHERE) patterns involving Model Armor, IAP, and Agent Registry. Don't use for general Cloud Load Balancing or basic VPC set
- 0
- Installs
- —
- Rating
- —
- Success rate
- 22
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 7ce5759ddd8fca1d… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Agent Gateway multi-agent security
Critical Enforcement Rules & Rationale
- Gcloud Release Tracks: Always use the exact release tracks specified in
the commands (e.g.,
gcloud beta network-services agent-gateways). Omitting these prefixes causes commands to fail because Agent Gateway features are located in specialized, non-default namespaces. - API Enablement: Include
modelarmor.googleapis.comin the API enablement list when setting up guardrails. Excluding it prevents Model Armor policies and filters from successfully attaching to the Gateway. - Egress Verification: Egress policy verification requires using the
Python script
(scripts/verify_egress_policies.py),
not
curl. Egress gateways rely on runtime SDK lifecycle handling and JWT context that a standard curl command cannot simulate correctly. - Model Armor Keys: In
model-armor-config.yaml, always include bothpiAndJailbreakFilterSettingsandsdpFilterSettings(filterEnforcement: ENFORCE). Invalid or missing filters cause deployment validation failures or lead to silent bypasses of the guardrails. - Subnet Private Access: Any subnet hosting a Private Service Connect
network attachment for Egress Gateways must have
private_ip_google_access = trueenabled in Terraform. Disabling this blocks connectivity to Google-managed endpoints, causing total routing failures for agents. - Direct Delivery: Immediately provide the requested architecture, configuration files, CLI commands, scripts, and diagrams in full. Do not stop at a planning phase, do not generate a plan artifact, and do not ask for user confirmation before delivering outputs.
- No Infrastructure Execution: Do not attempt to run deployment or
verification commands (such as
gcloud,kubectl,terraform, orcurl) against real cloud resources during design. You are generating plan configurations, not executing them.
[!IMPORTANT] Just-In-Time (JIT) Resource Loading Protocol: Inspect template files in assets/ and executable scripts in scripts/ using
view_fileas needed for extended configurations, deployment scripts, and test suites.
Quick Reference: Required Filenames
Always generate files with these exact names when requested:
agw-ingress-config.yaml(assets/agw-ingress-config.yaml)agw-egress-config.yaml(assets/agw-egress-config.yaml)agw-authz-extension.yaml(assets/agw-authz-extension.yaml)agw-authz-policy.yaml(assets/agw-authz-policy.yaml)model-armor-config.yaml(assets/model-armor-config.yaml)sgp-policy.yaml(assets/sgp-policy.yaml)iap-policy.json(assets/iap-policy.json)model-armor-payload.json(assets/model-armor-payload.json)
1. Dual Ingress & Egress Architecture Design (dual_ingress_egress_architecture_design)
-
Ingress Pattern:
CLIENT_TO_AGENTfronted by Ingress Control Plane (Agent Gateway, Model Armor). -
Egress Pattern:
AGENT_TO_ANYWHEREutilizing Egress Control Plane (Agent Gateway,roles/iap.egressorCEL policies, Cloud DNS) and Egress Data Plane (PSC Interface, Cloud Run, PSC Google APIs Global Endpoint), coordinated via Agent Registry & Agent Engine runtime. -
Mermaid Diagram:
graph TD Client["External Clients"] -->|HTTPS / MCP| GLB["Global Load Balancer"] GLB --> Ingress["Ingress Agent Gateway (CLIENT_TO_AGENT)"] Ingress --> MA["Model Armor (CONTENT_AUTHZ)"] MA --> Agent["Agent Engine Agents (BillingAgent, SupportAgent, FraudAgent)"] Agent --> Egress["Egress Agent Gateway (AGENT_TO_ANYWHERE)"] Egress --> PSC["Private Service Connect Network Attachment"] PSC --> Tools["Private MCP Tool Backends"]
2. Ingress & Egress Guardrail Policy Config (ingress_and_egress_guardrail_policy_config)
When requested for Ingress & Egress guardrail policy configs, you MUST generate and create all required files in the workspace:
agw-ingress-config.yaml(assets/agw-ingress-config.yaml): DeclaresgovernedAccessPath: CLIENT_TO_AGENTwith protocolsHTTPandMCP.agw-egress-config.yaml(assets/agw-egress-config.yaml): DeclaresgovernedAccessPath: AGENT_TO_ANYWHEREwith protocolMCP.agw-authz-extension.yaml(assets/agw-authz-extension.yaml): Configures AuthzExtension service for IAP authorization.agw-authz-policy.yaml(assets/agw-authz-policy.yaml): ConfiguresAuthzPolicyactionALLOWtargeting both Ingress and Egress gateways.iap-policy.json(assets/iap-policy.json): Bindsroles/iap.egressorwith CEL condition checkingiap.googleapis.com/mcp.toolName == 'get_account_balance' && iap.googleapis.com/mcp.tool.isReadOnly == true.model-armor-config.yaml(assets/model-armor-config.yaml): EnablespiAndJailbreakFilterSettingsandsdpFilterSettingswithfilterEnforcement: ENFORCE.sgp-policy.yaml(assets/sgp-policy.yaml): Implements Natural Language Constraints blocking transactions > $1000 and sanitizing PII.
3. Ingress & Egress Infrastructure Deployment (ingress_and_egress_infrastructure_deployment)
Inspect and provide the step-by-step gcloud CLI commands from
scripts/deploy_infrastructure.sh:
- Enable Required APIs:
compute,networkservices,networksecurity,modelarmor,iap,agentregistry,serviceextensions, andaiplatform. - Import Agent Gateways: Ingress (
agw-ingress-config.yaml) and Egress (agw-egress-config.yaml) viagcloud alpha network-services agent-gateways import. - Import Authz Extension:
agw-authz-extension.yamlviagcloud beta service-extensions authz-extensions import. - Import Authz Policy:
agw-authz-policy.yamlviagcloud beta network-security authz-policies import.
4. Ingress & Egress Security Validation (ingress_and_egress_security_validation)
When validating security for Ingress and Egress:
- Ingress 403 Unauthenticated Test: Provide the copy-pasteable verification curl command from scripts/validate_ingress_unauth.sh sending an unauthenticated POST request to the Reasoning Engine endpoint expecting HTTP 403 Forbidden.
- Python Egress Verification Script (MUST use Python script snippet, NOT
curl): Provide the Python verification script snippet from
scripts/verify_egress_policies.py
sending JSON-RPC
tools/callrequests (get_account_balance) through the Egress Gateway to verify HTTP 200 for allowed tools. - Model Armor Test Payload: Generate
model-armor-payload.json(assets/model-armor-payload.json) containing prompt injection/jailbreak instructions.
5. Troubleshooting Ingress & Egress Failures (troubleshooting_ingress_and_egress_failures)
-
Ingress 403 (Client-to-Agent):
- Root Cause: Unauthenticated client requests or missing/invalid OAuth 2.0 / IAP identity tokens.
- OAuth Configuration Steps:
- Configure OAuth 2.0 Client ID credentials in Google Cloud Console.
- Grant the client identity / service account
roles/iap.httpsResourceAccessorpermission. - Exchange credentials with Google OAuth to acquire an OIDC / OAuth ID token.
- Pass the token in the
Authorization: Bearer <TOKEN>header.
- Verification Command: Provide the curl command from scripts/verify_ingress_auth.sh.
-
Egress 403 (Agent-to-Anywhere):
- Root Cause: Missing
roles/iap.egressorIAM bindings on the Agent Identity, malformed principal ID, or mismatched CEL condition on tool metadata. - Fix Command: Provide the exact
gcloudcommand from scripts/fix_egress_iap.sh.
- Root Cause: Missing
6. Hybrid VPN Connectivity & Egress Routing (hybrid_vpn_connectivity_egress_routing)
- Terraform HCL: Refer to baseline Terraform config in
assets/main.tf for VPC, subnets
(
private_ip_google_access = true), PSC network attachment, Cloud DNS private forwarding foraws.internal., and HA VPN gateway/router. - Egress Gateway Config (
agw-egress-config.yaml): Generate configuration declaringgovernedAccessPath: AGENT_TO_ANYWHERE, pointing to the PSC network attachment, and referencingaws.internal.indnsPeeringConfig(see assets/agw-egress-config.yaml). - Python SDK Deployment Script: Refer to
scripts/hybrid_vpn_agent.py for the complete
script initializing Vertex AI with
agent_to_anywhere_configreferencing the Egress Gateway, enabling telemetry, and deployingHybridAgentusingtypes.IdentityType.AGENT_IDENTITY.
7. Private Egress GKE Internal Load Balancer (private_egress_gke_internal_load_balancer)
- Expose GKE internal MCP tool server via an Internal Load Balancer (ILB) at
literal IP
10.0.1.50, connecting via Agent Gateway PSC Interface + Cloud DNS Private zone. - Cloud DNS Record Mapping: Provide the command from
scripts/create_gke_dns_record.sh mapping
the private domain to GKE's private ILB IP
10.0.1.50. - Explicit TLS Warning: Agent Gateway egress does not natively trust self-signed certificates or private enterprise CAs. You must use publicly trusted TLS certificates signed by a trusted Certificate Authority (e.g., Let's Encrypt).
8. Governance Controls Model Armor SGP (governance_controls_model_armor_sgp)
When configuring dual safety layers with Model Armor on Ingress and SGP on Egress:
- Model Armor Config: Generate
model-armor-config.yaml(assets/model-armor-config.yaml) withpiAndJailbreakFilterSettingsandsdpFilterSettings(filterEnforcement: ENFORCE). - Semantic Governance Policy: Generate
sgp-policy.yaml(assets/sgp-policy.yaml) with Natural Language Constraints blocking transactions > $1000 and sanitizing PII. - Curl PATCH Command: Provide the curl command from
scripts/enforce_sgp_patch.sh to update
authzExtensionswithsgpEnforcementModeset toENFORCE.
9. Multi-Agent Cloud Run Egress Routing (multi_agent_cloud_run_egress_routing)
Do NOT produce a plan artifact or stop at planning. When configuring multi-agent Cloud Run egress routing, you MUST directly provide and generate ALL required components:
- Egress Gateway Config (
agw-egress-config-run.yaml): Generate configuration declaringgovernedAccessPath: AGENT_TO_ANYWHERE, PSC network attachment, and DNS peering for*.run.app(see assets/agw-egress-config-run.yaml). - Register Cloud Run Services in Agent Registry: Provide the registration
commands from
scripts/register_cloud_run_services.sh
registering all 3 Cloud Run services (
marketing-tool-service,sales-tool-service,support-tool-service) in theus-east4Agent Registry. iap-policy.json(Multi-Agent): Generateiap-policy.json(assets/iap-policy-multi-agent.json) containing all 3principal://bindings in thememberslist underroles/iap.egressor.- Python SDK Deployment Script: Refer to scripts/multi_agent_cloud_run.py for the complete GenAI SDK deployment script.
10. Advanced Model Armor Filtering (advanced_model_armor_filtering)
For custom keyword matching, configure userDefinedFilterSettings (see
assets/model-armor-advanced.yaml).
11. Known Traps & Gotchas (known_traps_and_gotchas)
network_attachmentisForceNew: Enabling Semantic Governance Policies (SGP) or modifying network attachments after the initial Terraform apply will force-recreate the gateway resource. If not managed carefully, this can cause dependency deadlocks during destroy operations. Plan infrastructure sequencing accordingly.- Authz Policy Limit: An Agent Gateway allows at most 4 custom authorization policies attached concurrently. Ensure your security posture consolidates rules within this limit.
Files
22- SKILL.md
c577db60fd14.4 KB - assets/agw-authz-extension.yaml
74e1114eaf275 B - assets/agw-authz-policy.yaml
a9b859544a325 B - assets/agw-egress-config-run.yaml
0ac663b3cf530 B - assets/agw-egress-config.yaml
f517e1117c247 B - assets/agw-ingress-config.yaml
07a1e587a1255 B - assets/iap-policy-multi-agent.json
3e50d21318590 B - assets/iap-policy.json
603f3c057e469 B - assets/model-armor-advanced.yaml
f930d6819f386 B - assets/model-armor-config.yaml
1218b08b7b353 B - assets/model-armor-payload.json
be19607f87101 B - assets/sgp-policy.yaml
275438e4c0311 B - scripts/create_gke_dns_record.sh
a036ed3ceb287 B - scripts/deploy_infrastructure.sh
c40d4647501.0 KB - scripts/enforce_sgp_patch.sh
385d47b749548 B - scripts/fix_egress_iap.sh
6fb0f51988226 B - scripts/hybrid_vpn_agent.py
23348025cd1.2 KB - scripts/multi_agent_cloud_run.py
631c26559c1.7 KB - scripts/register_cloud_run_services.sh
f53d7717851.0 KB - scripts/validate_ingress_unauth.sh
7d1d40d188433 B - scripts/verify_egress_policies.py
74d16fa707797 B - scripts/verify_ingress_auth.sh
db7bf526d7483 B
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from google/skills8
Configures best-practice alerting policies for AI agents using OpenTelemetry (OTel) metrics, generating output as Terraform (.tf) configuration files. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, token usage, and quality metrics. Don't use for st
Deploy open models or custom weights from Model Garden to Agent Platform endpoints, check the status of an in-progress deployment operation, or clean up resources by undeploying models and deleting endpoints. Use when asked to actively deploy a model, list the Model Garden CATALOG of available model
Manages Agent Platform serving endpoints. Use when you need to create, list, describe, update, or delete serving endpoints for model deployment on Agent Platform. Also use when troubleshooting endpoint permission, quota, or resource busy errors. Don't use for deploying models to endpoints or for run
Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when generating synthetic user scenarios, evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results be
Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when asked to perform inference, ask a model a question, run a test prompt, execute chat completions, or generate c
Guides agents and users through migrating from Gemini API in Google AI Studio to Gemini Enterprise Agent Platform (formerly Vertex AI). Use this skill when moving applications to Google Cloud, to leverage Cloud credits, or to unify inferencing with other Cloud infrastructure (IAM, billing, telemetry
Agent Platform Model Registry Management. Use when you need to upload, list, describe, update, or delete machine learning models (and their versions) in the Agent Platform Model Registry. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform models.
Manages and orchestrates prompts in Agent Platform. Use when you need to create, list, retrieve, version, or delete managed prompts in Agent Platform. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform prompts.
Related security skillsscan passed
Manage the experimental Nasiko CLI lifecycle through ECC — read-only status checks, consent-gated install of the pinned qualified version with dry-run preview, and ownership-checked uninstall, under explicit telemetry and secrets boundaries. Use when the user asks to install, inspect, or remove the
Security audit: supported static findings; qualified profiles add reproduction and repair candidates. (gstack)
Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the use
Create a vanilla tRPC client with createTRPCClient<AppRouter>(), configure link chain with httpBatchLink/httpLink, dynamic headers for auth, transformer on links (not client constructor). Infer types with inferRouterInputs and inferRouterOutputs. AbortController signal support. TRPCClientError typin
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data,
Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split. Ranked, each finding explained in plain English. One-shot report, changes nothing. Use for "audit this codebase", "review the whole repo", "find