Agent skill

Google Cloud Networking Observability

by davila7 in davila7/claude-code-templates

Investigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics.

MITAuto-check passedDevOps & Cloud

Install Google Cloud Networking Observability

skills CLI
$ npx skills add davila7/claude-code-templates --skill google-cloud-networking-observability -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davila7/claude-code-templates google-cloud-networking-observability --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-tool/components/skills/development/google-cloud-networking-observability .claude/skills/google-cloud-networking-observability && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
google-cloud-networking-observability
GitHub stars
32k
Token cost
~1.8k tokens
SKILL.md length
830 words
Files
8 (incl. references)
Skills in repo
477
Repo updated
First seen
Licence
MIT

At a glance

Investigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics.

  • Works in 4 steps: Log Source Preference → Tool Selection & Discovery → Schema Verification & Error Recovery → …
  • Investigating VPC Flow Logs
  • SKILL.md covers Core Directive: Results First, Log & Telemetry Overview, Procedures and Boundaries (CRITICAL)
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Google Cloud Networking Observability is an agent skill from davila7/claude-code-templates. Investigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics. Use when investigating VPC Flow Logs, NAT, firewall, or threat logs, querying latency and throughput metrics, or running Connectivity Tests for path diagnostics.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/cloud-nat-analysis.md`, `references/connectivity-tests.md` and `references/firewall-analysis.md`).

It sits in DevOps & Cloud, covering Observability. It works with Google Cloud. The repository describes itself as: CLI tool for configuring and monitoring Claude Code. The licence is MIT.

When your agent uses it

  • Investigating VPC Flow Logs
  • Querying latency and throughput metrics
  • Running Connectivity Tests for path diagnostics

Example prompts

  • “Use the google-cloud-networking-observability skill to investigate Google Cloud networking issues by analyzing logs, metrics, and diagnostics”
  • “/google-cloud-networking-observability”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Log Source Preference
  2. Tool Selection & Discovery
  3. Schema Verification & Error Recovery
  4. Analysis Guides (Read Only When Needed)

What it can do on your machine

Read from SKILL.md and the folder at commit 14680ec. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • console.cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Cloud Networking Observability loads about 1.8k tokens when it runs, and up to ~7.7k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 830 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davila7/claude-code-templates at commit 14680ec, republished under its MIT licence (© davila7). 830 words, ~1,798 tokens.

Download SKILL.mdSave it as .claude/skills/google-cloud-networking-observability/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
google-cloud-networking-observability
description
Investigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics. Use when investigating VPC Flow Logs, NAT, firewall, or threat logs, querying latency and throughput metrics, or running Connectivity Tests for path diagnostics.
source
google/skills (Apache 2.0)

Google Cloud Networking Observability Expert

Core Directive: Results First

  1. Identify the Primary Source: Quickly determine if the user needs firewall logs, threat logs, Cloud NAT, VPC Flow logs, or metrics.
  2. Execute & Present: Perform the minimum required query to get a direct answer.
  3. Definitive Termination: Once you identify the requested data, regardless of the value (including 0, null, or "No traffic"), present the finding and call the finish tool in the same turn. Do NOT attempt to find "active" or "busier" resources to provide a "better" answer unless specifically instructed to troubleshoot a resource that is expected to be busy.

Log & Telemetry Overview

  • Threat Logs: Specialized logs from Cloud Firewall Plus and Cloud IDS that identify malicious traffic patterns (for example, SQL injection or malware) using deep packet inspection.
  • VPC Flow Logs: Capture sample IP traffic to and from network interfaces. Use for traffic analysis, volume trends, and top talkers.
  • Firewall Logs: Record connection attempts matched by firewall rules. Use to identify "DENY" events or verify "ALLOW" rules.
  • Cloud NAT Logs: Audit NAT translations. Use to audit traffic going through NAT gateways or troubleshoot port exhaustion.
  • Networking Metrics: Aggregated time-series data for throughput, RTT (latency), and packet loss. Use for historical trends and performance monitoring.
  • Connectivity Tests: Static analysis tool for path diagnostics. Use to identify firewall or routing misconfigurations between endpoints.

Procedures

0. Log Source Preference
  • ALWAYS check for BigQuery linked datasets (for example, big_query_linked_dataset, _AllLogs) before using Cloud Logging for high-volume analysis or aggregations. This is the preferred method for finding trends or top-blocking rules.
  • Metadata Awareness (BigQuery): Subnetworks may be configured with EXCLUDE_ALL_METADATA, causing VM names to be NULL in VPC Flow Logs. If a query by VM name returns nothing, retry using the internal IP address (jsonPayload.connection.src_ip).
1. Tool Selection & Discovery
  • MCP Servers First: Use Cloud Monitoring MCP, BigQuery MCP, or Cloud Logging MCP.
  • Resource Discovery: If a user-specified resource (for example, NAT gateway, VPN tunnel) is not found in metrics/logs:
    1. Use run_shell_command with gcloud to list resources in the project.
    2. Search Cloud Logging MCP for the resource name to find correct labels.
  • CLI Fallback: Use gcloud or bq only if MCP servers are unavailable. DO NOT use gcloud monitoring; it is restricted. Immediately use the curl templates in metrics-analysis.md.
2. Schema Verification & Error Recovery

If a BigQuery query fails with an 'Unrecognized name' error or schema mismatch:

  1. Validate Schema: Run bq show --schema --format=json {project_id}:{dataset_id}.{table_id} to verify field names and casing (for example, jsonPayload versus json_payload). 2. Dry Run: Before executing a corrected query, use bq query --use_legacy_sql=false --dry_run "{query_text}" to verify field references without incurring cost or execution time. 3. Retry: Apply identified fixes to the original query and execute.
3. Analysis Guides (Read Only When Needed)

For detailed SQL patterns, field definitions, and advanced troubleshooting, read the corresponding reference file:

Show full SKILL.md (335 more words)Show less

Boundaries (CRITICAL)

  • ALWAYS present the direct answer as soon as it is identified.
  • NEVER run more than 2 exploratory queries before showing results.
  • NEVER perform secondary verification (for example, don't check VPC flows after finding a firewall block) without explicit user permission.
  • ALWAYS print the generated SQL for review before execution.
  • ALWAYS include a link to the Flow Analyzer in the Google Cloud Console.
  • NEVER query a second data source (such as, BigQuery logs) if the primary source (for example, Cloud Monitoring metrics) has already provided a conclusive answer. DO NOT compare metrics and logs to "verify" accuracy unless the user specifically asks why they differ.
  • NO DISCREPANCY LOOPS: If Tool A provides a result (such as, 80,000 counts) and Tool B provides a different result (for example, 1,000 counts), DO NOT initiate a deep dive to explain the difference. Present the result from the primary tool and STOP.
  • ALWAYS perform time-range calculations (such as, "12 hours ago") during the first turn to save steps.
  • Conclusive Acceptance of Inactivity: Treat a result of "0", "0 traffic", "No data found", or "No records found" as a conclusive finding for the requested timeframe and resource. You MUST report this as the definitive state and terminate immediately.
  • Standardized Discovery Path: For all "Top-N" or volume-based discovery tasks (for example, "highest traffic," "most hits," "top talkers"), you MUST use BigQuery aggregation on _AllLogs datasets. Manual aggregation of individual time-series points using the Monitoring API is forbidden due to step inefficiency.
  • Ban on Auxiliary Scripting: Execute all data retrieval and parsing logic as direct tool calls (bq, curl, gcloud). Do NOT write or execute local shell scripts (.sh) or python files, as these introduce avoidable environment and permission errors that lead to investigation timeouts.
  • Discovery Efficiency: For volume analysis (for example, "how many connections" or "top IPs by bytes"), BigQuery aggregation on VPC Flow logs (_AllLogs) is the Primary Source of Truth. If BigQuery data is available, it is conclusive. Do NOT query Monitoring API to "double check" BigQuery counts.

© davila7, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in cli-tool/components/skills/development/google-cloud-networking-observability of davila7/claude-code-templates.

  • SKILL.md
  • references/cloud-nat-analysis.md
  • references/connectivity-tests.md
  • references/firewall-analysis.md
  • references/mcp-usage.md
  • references/metrics-analysis.md
  • references/threat-analysis.md
  • references/vpc-flow-analysis.md

Open the folder on GitHubat commit 14680ec

Compare with similar skills

Google Cloud Networking Observability next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Cloud Networking Observability compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Cloud Networking Observability this skilldavila7/claude-code-templates32k—~1.8kAutomated safety check: PassMIT
Agent Platform Alert Configurationgoogle/skills21k—~4.2kAutomated safety check: PassApache-2.0
Agent Advisoraws/agent-toolkit-for-aws2.8k—~4.9kAutomated safety check: PassApache-2.0
Logfire Infrastructurepydantic/skills140—~1.8kAutomated safety check: PassMIT
Cloud Monitoring PromQL Generatorgoogle/skills21k—~2.6kAutomated safety check: PassApache-2.0
Gcloud Usagefcakyon/claude-codex-settings1.2k—~871Automated safety check: PassApache-2.0

Similar skills

  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Logfire Infrastructure

    pydantic/skills

    Official

    Monitor hosts, Docker containers, Kubernetes clusters, database/queue/cache servers, and cloud-provider metrics with Pydantic Logfire — no application code required.

    140 GitHub stars~1.8k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Official

    Generates valid PromQL queries for Cloud Monitoring metrics from metric descriptors and resource parameters, with a validator script and error-recovery notes.

    21k GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Gcloud Usage

    fcakyon/claude-codex-settings

    This skill should be used when user asks about "GCloud logs", "Cloud Logging queries", "Google Cloud metrics", "GCP observability", "trace analysis", or "debugging production issues on GCP".

    1.2k GitHub stars~871 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Dt Obs Network Flows

    Dynatrace/dynatrace-for-ai

    Network flow analysis in Dynatrace across three sources: OneAgent flows (host/process/pod-to-peer connections in the defaultnetworkflows Grail bucket), NetFlow/IPFIX/sFlow (via an OpenTelemetry…

    161 GitHub starsUsed in 1 repo~2k tokens
    DevOps & CloudAuto-check passed

More from davila7/claude-code-templates

All 477 skills in this repo
  • Perplexity Web Search

    davila7/claude-code-templates

    Runs web-grounded searches through Perplexity's Sonar models over OpenRouter for current events, recent literature and cited facts beyond the model's training cutoff.

    32k GitHub starsUsed in 12 repos~3.5k tokens
    Auto-check: notes
  • Neuropixels Data Analysis

    davila7/claude-code-templates

    Analyzes Neuropixels recordings from SpikeGLX or Open Ephys through preprocessing, drift correction, Kilosort4 spike sorting, quality metrics and curation.

    32k GitHub starsUsed in 10 repos~2.8k tokens
    Auto-check passed
  • Scientific Venue Templates

    davila7/claude-code-templates

    Supplies LaTeX templates and formatting rules for journals, conferences, posters, and grant proposals, then can check a draft against them.

    32k GitHub starsUsed in 9 repos~5.1k tokens
    Auto-check: notes
  • Brand Voice Content Creator

    davila7/claude-code-templates

    Analyzes a brand's existing writing to lock in a consistent voice, then builds SEO blog posts and platform-specific social content around it.

    32k GitHub starsUsed in 3 repos~1.9k tokens
    Auto-check passed
  • CAPA Officer

    davila7/claude-code-templates

    Guides corrective and preventive action (CAPA) work in a quality management system, from initiation and root cause analysis through effectiveness verification.

    32k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    32k GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed

Works with

Categories

Questions about Google Cloud Networking Observability

What does Google Cloud Networking Observability do?

Investigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics. Google Cloud Networking Observability is an agent skill from davila7/claude-code-templates. Investigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics.

When should I use Google Cloud Networking Observability?

Google Cloud Networking Observability fits situations like: investigating VPC Flow Logs; querying latency and throughput metrics; running Connectivity Tests for path diagnostics.

How do I install Google Cloud Networking Observability in Claude Code?

Run `npx skills add davila7/claude-code-templates --skill google-cloud-networking-observability -a claude-code`. Or copy the skill folder (cli-tool/components/skills/development/google-cloud-networking-observability in davila7/claude-code-templates) into .claude/skills/google-cloud-networking-observability in your project. Claude Code loads it when a task matches its description.

How do I install Google Cloud Networking Observability in Codex?

Run `npx skills add davila7/claude-code-templates --skill google-cloud-networking-observability -a codex`. Or copy the skill folder (cli-tool/components/skills/development/google-cloud-networking-observability in davila7/claude-code-templates) into .agents/skills/google-cloud-networking-observability in your project. Codex loads it when a task matches its description.

Can I use Google Cloud Networking Observability in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davila7/claude-code-templates --skill google-cloud-networking-observability -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-cloud-networking-observability, .gemini/skills/google-cloud-networking-observability, .github/skills/google-cloud-networking-observability and .opencode/skills/google-cloud-networking-observability in your project.

What does Google Cloud Networking Observability need to run?

SKILL.md names no scripts, command-line tools or credentials: Google Cloud Networking Observability is instructions for the agent only. Our summary lists: Python 3.

Does Google Cloud Networking Observability access the network?

SKILL.md names 1 domain. As links in the text: console.cloud.google.com. This is read from the text; nothing was executed.

Is Google Cloud Networking Observability safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Google Cloud Networking Observability use?

Google Cloud Networking Observability is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Cloud Networking Observability use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.9k tokens, read only when the agent opens those files.

What are the alternatives to Google Cloud Networking Observability?

Skills that share tags, products or a category with Google Cloud Networking Observability: Agent Platform Alert Configuration (google/skills, 21k stars), Agent Advisor (aws/agent-toolkit-for-aws, 2.8k stars), Logfire Infrastructure (pydantic/skills, 140 stars) and Cloud Monitoring PromQL Generator (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Cloud Networking Observability?

davila7 (a GitHub user) maintains it in davila7/claude-code-templates, which has 32,463 GitHub stars. The repository holds 477 skills in this directory. The repository was last updated on October 8, 2026.

Source: davila7/claude-code-templates on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.