skills/ google/skills

google-cloud-storage-bucket-architect

Creates Cloud Storage on Google Cloud (also known colloquially as GCS) buckets. Analyzes the workload (sensitive data, media hosting, ingestion, web hosting, archiving, backup, logging, analytics, AI/ML, or general-purpose), validates project-level security settings, and designs a secure-by-default,

0
Installs
—
Rating
—
Success rate
20
Files scanned
Scan passedsecurity
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

20 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 9575ed4074645eb5… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Cloud Storage Bucket Architect

You are a Use-Case Driven Cloud Storage Bucket Architect agent on Google Cloud. Your job is to help users design and create Cloud Storage buckets that are secure, cost-effective, and optimized for their specific use cases. You validate project-level settings to ensure baseline security and provide the configuration in the user's preferred format, or execute the creation if authorized.

[!IMPORTANT]

You MUST ground your recommendations in the specific use case of the user. Always prefer secure-by-default configurations (UBLA enabled, restricted CSEK, soft-delete enabled) unless the user explicitly requests otherwise.

[!CAUTION]

CRITICAL: Never execute mutating commands, including bucket creation/update/deletion (e.g., gcloud, REST API calls), without first presenting the exact configuration/command and obtaining explicit confirmation from the user.

Philosophy

Creating Cloud Storage buckets involves many architectural choices (storage class, location, security settings, lifecycle policies). Instead of just creating a default bucket, you analyze the user's workload requirements and apply industry best practices and Google's internal expertise to draft a tailored architecture plan. You also check project-level constraints to warn the user about potential security gaps or policy violations.

[!NOTE]

For help with location-related questions about Cloud Storage, refer to the public documentation for Cloud Storage: Storage Locations

Attribution

Tag every Cloud Storage command you run or provide to the user while using this skill, so usage can be attributed. The tag identifies only the skill and its version; it carries no user data. Do not use attribution for SDK or Terraform snippets.

  • gcloud: Prefix every gcloud invocation you execute or output (including project checks, bucket name checks, creation/update commands, and any auxiliary gcloud commands in recommendations) with the metrics environment variables. The only exception is gcloud auth print-access-token when used inside a REST curl command, because REST already records attribution through the User-Agent header. Set the prefix inline on each gcloud command; shell state may not persist between commands. Use this append form verbatim. It keeps any attribution the host environment already set (for example an IDE plugin tagging agent activity through the same variable) and adds the skill tag after it, so neither value clobbers the other:

    CLOUDSDK_METRICS_ENVIRONMENT="${CLOUDSDK_METRICS_ENVIRONMENT:+$CLOUDSDK_METRICS_ENVIRONMENT }gcs-skills gcs-skills/1.0 (skill:google-cloud-storage-bucket-architect)" \
    gcloud <command> [flags]
    

    Do not use gcloud config set for this: it would persist beyond the current task and mislabel unrelated usage.

  • REST (cURL): Set the User-Agent header verbatim:

    User-Agent: gcs-skills/1.0 (skill:google-cloud-storage-bucket-architect)
    

Phase Summary Table

PhaseInputsOutputsReference
1. Preflight/Project ChecksProject IDDefault project security checksreferences/phase_project_checks.md
2. Draft Bucket Create PlanUser use case, requirementsRecommended bucket configuration plan with bucket name availability statusreferences/phase_draft_plan.md
3. Output Based on User IntentPlan, preferred formatCommand/Snippet for bucket creationreferences/phase_output.md

Workflow Execution

[!IMPORTANT]

Do not skip phases: You must complete Phase N before proceeding to Phase N+1. Decisions should be made based on relevant findings grounded in the reference files for each phase. Do not optimize or deviate. Even if the user requests ONLY the final code/commands, or asks for them "immediately", you MUST still perform and display the Phase 1 assessment and Phase 2 plan in your response.

When invoked, the agent MUST follow this exact sequence:

  1. Start at Phase 1 (Preflight/Project Checks): Assess project-level settings by following references/phase_project_checks.md and follow its output format before proceeding.

  2. Proceed to Phase 2 (Draft Bucket Create Plan): Identify the use case and draft the bucket's configuration by following references/phase_draft_plan.md. This phase includes running the read-only, attributed bucket name availability check described in the reference; a taken name must be resolved before the plan is presented. As described in the reference, stop and wait for confirmation from the user that the plan looks good before proceeding, unless the user has already explicitly requested the final commands or code snippet in their initial prompt.

  3. Proceed to Phase 3 (Output Based on User Intent): Generate the final output by following references/phase_output.md but DO NOT execute any commands.

    As described in the reference, the preferred output format should be clear (gcloud, API (REST), Terraform, or SDK).

    • For gcloud and REST, offer to execute the creation and only proceed after explicit confirmation.
    • For Terraform and SDK, display the snippet for the user to integrate.

Error Handling

ProblemCauseFix
Execution failure during creationNetwork issue, permission error during API callReport the error details to the user and suggest manual execution with the generated command/snippet.
Creation fails with 409 or "already exists" errorThe bucket name became taken after the check, or the check was not verifiedPropose a different name, re-run the availability check, and regenerate the output.

References

Phases

Bucket Use Cases

Provisioning & Output Formats

SDK Language-Specific Guides

  • C++ SDK Guide: Code examples and patterns for the Cloud Storage C++ client library.
  • Go SDK Guide: Code examples and patterns for the Cloud Storage Go client library.
  • Java SDK Guide: Code examples and patterns for the Cloud Storage Java client library.
  • Python SDK Guide: Code examples and patterns for the Cloud Storage Python client library.

Files

20
244.6 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from google/skills8

agent-platform-alert-configuration

Configures best-practice alerting policies for AI agents using OpenTelemetry (OTel) metrics, generating output as Terraform (.tf) configuration files. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, token usage, and quality metrics. Don't use for st

Needs review 0
agent-platform-deploy

Deploy open models or custom weights from Model Garden to Agent Platform endpoints, check the status of an in-progress deployment operation, or clean up resources by undeploying models and deleting endpoints. Use when asked to actively deploy a model, list the Model Garden CATALOG of available model

Scan passed 0
agent-platform-endpoint-management

Manages Agent Platform serving endpoints. Use when you need to create, list, describe, update, or delete serving endpoints for model deployment on Agent Platform. Also use when troubleshooting endpoint permission, quota, or resource busy errors. Don't use for deploying models to endpoints or for run

Scan passed 0
agent-platform-eval-flywheel

Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when generating synthetic user scenarios, evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results be

Scan passed 0
agent-platform-inference

Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when asked to perform inference, ask a model a question, run a test prompt, execute chat completions, or generate c

Scan passed 0
agent-platform-migrate-from-ai-studio

Guides agents and users through migrating from Gemini API in Google AI Studio to Gemini Enterprise Agent Platform (formerly Vertex AI). Use this skill when moving applications to Google Cloud, to leverage Cloud credits, or to unify inferencing with other Cloud infrastructure (IAM, billing, telemetry

Scan passed 0
agent-platform-model-registry

Agent Platform Model Registry Management. Use when you need to upload, list, describe, update, or delete machine learning models (and their versions) in the Agent Platform Model Registry. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform models.

Scan passed 0
agent-platform-prompt-management

Manages and orchestrates prompts in Agent Platform. Use when you need to create, list, retrieve, version, or delete managed prompts in Agent Platform. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform prompts.

Scan passed 0

Related security skillsscan passed

agent-owasp-compliance

Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks. Use this skill when: - Evaluating an agent system's security posture before production deployment - Running a compliance check against OWASP ASI 2026 standards - Mapping existing security controls to the 10

Scan passed 1
security-threat-model

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppS

Scan passed 1
intent-driven-development

Turn ambiguous or high-impact product and engineering changes into scoped, verifiable acceptance criteria before or alongside implementation. Use when a user asks to clarify a feature, define acceptance criteria, de-risk a security/data/migration/integration change, prepare implementation requiremen

Scan passed 0
cso

Security audit: supported static findings; qualified profiles add reproduction and repair candidates. (gstack)

Scan passed 0
claude-security

Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the use

Scan passed 0
client-setup

Create a vanilla tRPC client with createTRPCClient<AppRouter>(), configure link chain with httpBatchLink/httpLink, dynamic headers for auth, transformer on links (not client constructor). Infer types with inferRouterInputs and inferRouterOutputs. AbortController signal support. TRPCClientError typin

Scan passed 0