skills/ google/skills

google-cloud-waf-security

Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate workloads, identify security requirements, and provide actionable recommendations for IAM, network securi

0
Installs
—
Rating
—
Success rate
1
Files scanned
Scan passedsecurity
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

1 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 bdb1c5f2f67223da… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Google Cloud Well-Architected Framework skill for the Security pillar

Overview

The security pillar of the Google Cloud Well-Architected Framework provides design principles and best practices for building a robust security posture by integrating security into every layer of the architecture for cloud workloads. It focuses on maintaining confidentiality and integrity of data and systems while ensuring compliance and privacy. It provides a structured approach to risk management, threat defense, and identity control, enabling you to operate cloud workloads securely and at scale.

Workflow

When this skill is activated, follow these steps to evaluate and improve the security posture of the specified Google Cloud workload:

  1. Understand the context: Ask targeted questions from the Workload assessment questions list to gather information about the user's current architecture, security requirements, and constraints.
  2. Analyze and identify gaps: Evaluate the workload against the Core principles and the Validation checklist to identify security vulnerabilities, missing controls, or deviations from best practices.
  3. Formulate recommendations: Provide actionable, prioritized guidance based on the Google Cloud Well-Architected Framework. Recommend specific products from Relevant Google Cloud products to address the identified gaps.
  4. Explain the recommendations: Align all recommendations with the appropriate Core principles and state the benefits that each recommendation provides.
  5. Iterate and refine: Help the user adapt the recommendations to their specific requirements and constraints.

Core principles

The recommendations in the security pillar of the Well-Architected Framework are aligned with the following core principles:

Relevant Google Cloud products

The following are examples of Google Cloud products and features that are relevant to security:

  • Identity and access management

    • Cloud Identity: Manage user lifecycles, authentication, and identity federation.
    • Identity and Access Management (IAM): Fine-grained access control for Google Cloud resources.
    • Identity-Aware Proxy (IAP): Secure access to applications without a VPN.
    • Chrome Enterprise Premium: Endpoint security and context-aware access.
    • IAM Recommender: Provide policy intelligence.
  • Network security

    • Google Cloud Armor: DDoS protection and Web Application Firewall (WAF).
    • VPC Service Controls: Define security perimeters to prevent data exfiltration.
    • Cloud Next-Generation Firewall (NGFW): Advanced threat protection for network traffic.
    • Shared VPC: Centralized network management across projects.
    • Cloud Interconnect and IPsec VPN: Secure, private connectivity. -Private Service Connect: Provide private access to managed services
  • Data security

    • Cloud Key Management Service (KMS): Manage encryption keys.
    • Sensitive Data Protection (formerly Cloud DLP): Discover and redact sensitive data.
    • Confidential Computing: Encrypt data in use (memory).
  • Security operations (SecOps)

    • Google SecOps (Chronicle): Threat detection and security analytics.
    • Security Command Center (SCC): Centralized vulnerability and threat management.
    • Cloud Logging and Cloud Monitoring: Visibility into system activity.
    • BigQuery: Storing exported logs for analysis.
  • Automation and supply chain

    • Cloud Build: Secure CI/CD pipelines.
    • Artifact Analysis: Vulnerability scanning for container images.
    • Binary Authorization: Deploy-time policy enforcement.
    • Assured open source software: Use secured OSS packages.

Workload assessment questions

Ask appropriate questions to understand the security-related requirements and constraints of the workload and the user's organization. Choose questions from the following list:

  • Security by design:

    • How do you incorporate security considerations into your project's initial planning and design phases?
    • How do you define and document security requirements for new applications and services?
    • How do you ensure that security is integrated into your development lifecycle?
    • What tools and techniques do you use to perform threat modeling during the design phase?
    • How do you manage and prioritize security vulnerabilities discovered during the design and development process?
    • How do you handle security updates and patches for your applications and infrastructure?
    • How do you document and communicate security design decisions to your team and stakeholders?
    • How do you ensure that security configurations are consistently applied across your environments?
    • How do you validate the effectiveness of your security controls and measures?
    • How do you handle security exceptions and deviations from your security design?
  • Zero trust:

    • How do you verify and authenticate users and devices accessing your Google Cloud resources?
    • How do you implement the principle of least privilege for access control?
    • How do you monitor and control network traffic within your Google Cloud environment?
    • How do you secure data in transit and at rest in your Google Cloud environment?
    • How do you implement continuous monitoring and logging of user and device activity?
    • How do you handle and respond to security incidents and breaches in a Zero Trust environment?
    • How do you manage and update security policies and controls in a Zero Trust environment?
    • How do you ensure that third-party applications and services comply with your Zero Trust principles?
    • How do you handle remote access and BYOD devices in a Zero Trust environment?
    • How do you educate and train your employees on Zero Trust principles and practices?
  • Shift-left security:

    • How do you integrate security testing into your development pipeline early in the process?
    • What types of security testing do you perform during the development phase?
    • How do you provide developers with feedback on security vulnerabilities and best practices?
    • How do you empower developers to take ownership of security in their code?
    • How do you ensure that security requirements are clearly defined and communicated to developers?
    • How do you measure the effectiveness of your Shift Left security initiatives?
    • How do you handle security dependencies and third-party libraries in your code?
    • How do you manage and update security configurations in your development environment?
    • How do you handle security exceptions and deviations from your security policies in development?
    • How do you promote a culture of security awareness and responsibility among developers?
  • Preemptive cyber defense:

    • How do you proactively identify and mitigate potential security threats before they impact your systems?
    • What tools and techniques do you use for continuous security monitoring and analysis?
    • How do you respond to and remediate security alerts and incidents?
    • How do you simulate and test your incident response plans?
    • How do you stay up-to-date with the latest security threats and vulnerabilities?
    • How do you handle and mitigate DDoS attacks against your applications and services?
    • How do you protect your sensitive data from insider threats?
    • How do you ensure that your security controls are effective against advanced persistent threats (APTs)?
    • How do you handle security vulnerabilities in your supply chain?
    • How do you adapt your security posture to evolving threats and technologies?
  • Security of AI workloads:

    • How do you ensure the security of your AI models and data?
    • How do you address potential biases and ethical concerns in your AI models?
    • How do you protect your AI models from adversarial attacks and data poisoning?
    • How do you ensure the privacy of data used in your AI models?
    • How do you explain and interpret the decisions made by your AI models?
    • How do you manage and control access to your AI models and data?
    • How do you ensure compliance with regulations and standards related to AI and ML?
    • How do you monitor and detect anomalies in the behavior of your AI models?
    • How do you handle and respond to security incidents involving your AI models?
    • How do you educate and train your employees on the secure and responsible use of AI and ML?
  • AI for security:

    • How do you leverage AI and ML to enhance your security posture?
    • What types of AI models do you use for security purposes?
    • How do you train and validate your AI models for security applications?
    • How do you ensure the accuracy and reliability of AI-based security systems?
    • How do you handle false positives and false negatives from AI-based security systems?
    • How do you integrate AI-based security systems with your existing security infrastructure?
    • How do you manage and update your AI models for security applications?
    • How do you explain and interpret the decisions made by your AI models for security applications?
    • How do you ensure the ethical and responsible use of AI and ML for security purposes?
    • How do you measure the effectiveness of AI and ML in improving your security posture?
  • Regulatory compliance and privacy:

    • What regulatory compliance frameworks and privacy standards do you need to adhere to?
    • How do you assess and manage compliance risks in your Google Cloud environment?
    • How do you ensure the privacy of sensitive data stored and processed in Google Cloud?
    • How do you handle data subject requests (DSRs) related to privacy regulations?
    • How do you document and track compliance activities and evidence?
    • How do you ensure that third-party vendors and partners comply with your regulatory and privacy requirements?
    • How do you handle data breaches and security incidents related to compliance regulations?
    • How do you stay up-to-date with changes in regulatory compliance and privacy standards?
    • How do you educate and train your employees on regulatory compliance and privacy requirements?
    • How do you demonstrate and prove compliance to auditors and regulators?

Validation checklist

Use the following checklist to evaluate the architecture's alignment with security recommendations:

  • Security by design:

    • Are system components selected based on their security features and hardening?
    • Is defense-in-depth implemented at the network, host, and application layers?
    • Are safe libraries and application frameworks used to prevent common vulnerabilities?
    • Is a risk assessment performed using industry standards?
  • Zero trust:

    • Is Cloud Identity used as a centralized identity provider for managing user lifecycles and federation?
    • Is access control enforced based on user identity and context (device, location)?
    • Are private connectivity methods (Cloud Interconnect, VPN) used for internal traffic?
    • Are default networks disabled in all projects?
    • Are VPC Service Controls perimeters established around sensitive data?
  • Shift-left security:

    • Is infrastructure provisioned using Infrastructure as Code (e.g., Terraform)?
    • Are automated security scans integrated into the CI/CD pipeline?
    • Is there a process for scanning and patching vulnerabilities in dependencies?
    • Is Binary Authorization used to ensure only trusted images are deployed?
  • Preemptive cyber defense:

    • Is threat intelligence integrated into security operations?
    • Is security logging enabled and centralized for all critical resources?
    • Are automated responses configured for common security threats?
    • Are defenses validated through periodic testing or red-teaming?
  • AI security and governance:

    • Are AI pipelines secured against tampering and data poisoning?
    • Is differential privacy or data masking used for training data where appropriate?
    • Are Vertex Explainable AI and fairness indicators used for model governance?

Files

1
16.4 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from google/skills8

agent-platform-alert-configuration

Configures best-practice alerting policies for AI agents using OpenTelemetry (OTel) metrics, generating output as Terraform (.tf) configuration files. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, token usage, and quality metrics. Don't use for st

Needs review 0
agent-platform-deploy

Deploy open models or custom weights from Model Garden to Agent Platform endpoints, check the status of an in-progress deployment operation, or clean up resources by undeploying models and deleting endpoints. Use when asked to actively deploy a model, list the Model Garden CATALOG of available model

Scan passed 0
agent-platform-endpoint-management

Manages Agent Platform serving endpoints. Use when you need to create, list, describe, update, or delete serving endpoints for model deployment on Agent Platform. Also use when troubleshooting endpoint permission, quota, or resource busy errors. Don't use for deploying models to endpoints or for run

Scan passed 0
agent-platform-eval-flywheel

Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when generating synthetic user scenarios, evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results be

Scan passed 0
agent-platform-inference

Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when asked to perform inference, ask a model a question, run a test prompt, execute chat completions, or generate c

Scan passed 0
agent-platform-migrate-from-ai-studio

Guides agents and users through migrating from Gemini API in Google AI Studio to Gemini Enterprise Agent Platform (formerly Vertex AI). Use this skill when moving applications to Google Cloud, to leverage Cloud credits, or to unify inferencing with other Cloud infrastructure (IAM, billing, telemetry

Scan passed 0
agent-platform-model-registry

Agent Platform Model Registry Management. Use when you need to upload, list, describe, update, or delete machine learning models (and their versions) in the Agent Platform Model Registry. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform models.

Scan passed 0
agent-platform-prompt-management

Manages and orchestrates prompts in Agent Platform. Use when you need to create, list, retrieve, version, or delete managed prompts in Agent Platform. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform prompts.

Scan passed 0

Related security skillsscan passed

laravel-security

Laravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations. Use when reviewing Laravel auth, Eloquent safety, CSRF, XSS, API security, or deployment configuration.

Scan passed 0
cso

Security audit: supported static findings; qualified profiles add reproduction and repair candidates. (gstack)

Scan passed 0
claude-security

Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the use

Scan passed 0
client-setup

Create a vanilla tRPC client with createTRPCClient<AppRouter>(), configure link chain with httpBatchLink/httpLink, dynamic headers for auth, transformer on links (not client constructor). Infer types with inferRouterInputs and inferRouterOutputs. AbortController signal support. TRPCClientError typin

Scan passed 0
security-and-hardening

Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data,

Scan passed 0
ponytail-audit

Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split. Ranked, each finding explained in plain English. One-shot report, changes nothing. Use for "audit this codebase", "review the whole repo", "find

Scan passed 0