iam-helper-for-policy-management
Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2). Manages access control across Resource Manager resources (Organization, Folder, Project) and individual resources. Use when creating, updating, listing, or deleting IAM allow policies or deny po
- 0
- Installs
- —
- Rating
- —
- Success rate
- 3
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 62b42000e67d05cf… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
IAM Helper for Policy Management
Orchestrates the lifecycle and management of IAM allow and deny policies across IAM v1 (allow policies) and IAM v2 (deny policies).
Core Concepts & Paradigms
IAM operates across two policy paradigms:
- IAM v1 (Allow Policies): Grants roles to principals (users, service accounts, groups, domains) on specific resources. Supports Resource Manager resources (organizations, folders, projects) as well as individual resources across supported Google Cloud services.
- IAM v2 (Deny Policies): Sets explicit organization-, folder-, or project-level guardrails that prevent specified principals from using designated permissions, regardless of any allow policies granted. Evaluated before allow policies.
Workflow & Decision Tree
When receiving a policy management request, determine whether the operation is Read-Only or Mutating, and whether it targets IAM v1 (Allow Policies) or IAM v2 (Deny Policies):
1. Read-Only Operations (Autonomous Execution)
Read-only actions include the following:
- IAM v1 Allow Policies:
get-iam-policyon project/folder/organization, orgcloud iam list-testable-permissions //cloudresourcemanager.googleapis.com/projects/PROJECT_ID. - IAM v2 Deny Policies:
gcloud iam policies listorgcloud iam policies getwith--attachment-pointand--kind=denypolicies.
For read-only actions, execute the command autonomously to inspect state, and present the query results clearly to the user.
2. Mutating Operations (Plan & Confirm Protocol)
Mutating operations include the following:
- IAM v1 Allow Policies:
add-iam-policy-binding,remove-iam-policy-binding, orset-iam-policyacross project, folder, organization, or resource levels (see references/v1-allow-policies.md). - IAM v2 Deny Policies:
create,update, ordeletedeny policies on attachment points (cloudresourcemanager.googleapis.com/projects/PROJECT_ID,cloudresourcemanager.googleapis.com/folders/FOLDER_ID, orcloudresourcemanager.googleapis.com/organizations/ORG_ID) using YAML/JSON policy files (see references/v2-deny-policies.md).
For mutating operations, follow the Plan & Confirm Protocol below. DO NOT execute mutating commands autonomously without prior user approval.
Execution & Safety Protocol
- Plan and Confirm (No Autonomous Mutation): Mutating allow and deny
policy changes modify live security perimeters and access controls. You MUST
NOT execute mutating
gcloudcommands directly via tool calls without explicit prior confirmation from the user. When asked to apply a mutating change, do the following:- Formulate the Command: Generate the exact, fully constructed
gcloudcommand (including all parameters such as--member,--role,--attachment-point,--kind=denypolicies, and--policy-file). - Warn of Impact & Propagation: Issue a general warning that the change could impact access in a live environment and takes time to propagate across Google Cloud global infrastructure.
- Request User Confirmation: Prompt the user for approval before applying the changes to the live environment.
- Formulate the Command: Generate the exact, fully constructed
- Post-Execution Verification: After the user approves and the mutating policy change is executed, run the corresponding verification command (see references/v1-allow-policies.md and references/v2-deny-policies.md for exact verification steps) to verify that the active state matches expectations before reporting completion.
- Security Guardrail (Public & Blanket Access Refusal): Never grant
allUsersorallAuthenticatedUsersbasic roles (roles/owner,roles/editor,roles/viewer,roles/admin,roles/writer, androles/reader) or broad permissions. Explicitly refuse blanket public access requests, explain the severe security risks of public project ownership/access, and propose scoped, least-privileged role bindings for specific authenticated identities instead.
Supporting Links
Files
3- SKILL.md
e430fec71b5.3 KB - references/v1-allow-policies.md
09f15a59c36.1 KB - references/v2-deny-policies.md
b5f37822317.6 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from google/skills8
Configures best-practice alerting policies for AI agents using OpenTelemetry (OTel) metrics, generating output as Terraform (.tf) configuration files. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, token usage, and quality metrics. Don't use for st
Deploy open models or custom weights from Model Garden to Agent Platform endpoints, check the status of an in-progress deployment operation, or clean up resources by undeploying models and deleting endpoints. Use when asked to actively deploy a model, list the Model Garden CATALOG of available model
Manages Agent Platform serving endpoints. Use when you need to create, list, describe, update, or delete serving endpoints for model deployment on Agent Platform. Also use when troubleshooting endpoint permission, quota, or resource busy errors. Don't use for deploying models to endpoints or for run
Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when generating synthetic user scenarios, evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results be
Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when asked to perform inference, ask a model a question, run a test prompt, execute chat completions, or generate c
Guides agents and users through migrating from Gemini API in Google AI Studio to Gemini Enterprise Agent Platform (formerly Vertex AI). Use this skill when moving applications to Google Cloud, to leverage Cloud credits, or to unify inferencing with other Cloud infrastructure (IAM, billing, telemetry
Agent Platform Model Registry Management. Use when you need to upload, list, describe, update, or delete machine learning models (and their versions) in the Agent Platform Model Registry. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform models.
Manages and orchestrates prompts in Agent Platform. Use when you need to create, list, retrieve, version, or delete managed prompts in Agent Platform. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform prompts.