Official agent skill

Google Cloud Filestore Nfs Browser

by google in google/skills

Inspects, searches, and reads files and POSIX metadata on Filestore (NFS) instances on Google Cloud without local NFS client packages or root privileges.

OfficialApache-2.0Auto-check passedAgent Workflows

Install Google Cloud Filestore Nfs Browser

skills CLI
$ npx skills add google/skills --skill google-cloud-filestore-nfs-browser -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills google-cloud-filestore-nfs-browser --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/google-cloud-filestore-nfs-browser .claude/skills/google-cloud-filestore-nfs-browser && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
google-cloud-filestore-nfs-browser
GitHub stars
21k
Token cost
~3k tokens
SKILL.md length
1,010 words
Files
14 (incl. scripts, references)
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Inspects, searches, and reads files and POSIX metadata on Filestore (NFS) instances on Google Cloud without local NFS client packages or root privileges.

  • Works in 5 steps: Discovery & Instance Targeting → Directory Tree Exploration (tree) → File Pattern & Content Grep (search) → …
  • Browsing Filestore shares
  • SKILL.md covers Quick Start, Attribution, Conceptual & Informational… and Handling "No-Command"…, plus 6 more sections
  • Runs Python and Shell scripts from its folder; calls python3 and gcloud

What it does

Google Cloud Filestore Nfs Browser is an agent skill from google/skills, published by the product's own GitHub organization. Inspects, searches, and reads files and POSIX metadata on Filestore (NFS) instances on Google Cloud without local NFS client packages or root privileges. Use when browsing Filestore shares, searching files, reading remote logs, or inspecting file attributes; don't use for Cloud Storage buckets, Cloud NetApp Volumes, Persistent Disks, or modifying/deleting files.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 16 other files, including scripts and reference files (for example `references/architecture.md`, `references/iap-jump-host.md` and `references/nfs-bridge-setup.md`).

It sits in Agent Workflows. It works with Google Cloud and Cloud Run. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Browsing Filestore shares
  • Searching files
  • Reading remote logs
  • Inspecting file attributes

Example prompts

  • “/google-cloud-filestore-nfs-browser”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Discovery & Instance Targeting
  2. Directory Tree Exploration (tree)
  3. File Pattern & Content Grep (search)
  4. Chunked File Reading (read)
  5. File Metadata & Attribute Inspection (stat)

What it can do on your machine

Read from SKILL.md and the folder at commit 5120a76. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 8 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Cloud Filestore Nfs Browser loads about 3k tokens when it runs, and up to ~7.2k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 1,010 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from google/skills at commit 5120a76, republished under its Apache-2.0 licence (© google). 1,010 words, ~3,024 tokens.

Download SKILL.mdSave it as .claude/skills/google-cloud-filestore-nfs-browser/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
google-cloud-filestore-nfs-browser
description
Inspects, searches, and reads files and POSIX metadata on Filestore (NFS) instances on Google Cloud without local NFS client packages or root privileges. Use when browsing Filestore shares, searching files, reading remote logs, or inspecting file attributes; don't use for Cloud Storage buckets, Cloud NetApp Volumes, Persistent Disks, or modifying/deleting files.
metadata.version
1.0.1
metadata.category
Storage

Filestore NFS File Browser

Enables autonomous agents and cloud engineers to inspect, search, and read files located on Filestore (NFS) instances without needing local NFS client packages (nfs-common), root privileges, or manual VPC network mounting.

Quick Start

  1. Ensure gcloud is installed and authenticated. See gcloud installation guide if needed.

  2. Enable essential APIs:

    bash
    gcloud services enable file.googleapis.com compute.googleapis.com run.googleapis.com --quiet
  3. Discover instances and choose an execution engine (see Execution Engine Selection below).

  4. Run inspection actions using the self-contained runner scripts/nfs_browser.py included within this skill package.

Attribution

Tag every Cloud Filestore command or API request provided or executed. Prefix gcloud commands with the metrics environment targeting this skill:

bash
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-nfs-browser)" \
gcloud filestore instances list ...

On direct HTTP calls to the REST API, append the User-Agent:

User-Agent: gcs-skills/1.0 (skill:google-cloud-filestore-nfs-browser)

Conceptual & Informational Queries (CRITICAL)

For purely conceptual, educational, or architectural questions (e.g., "How do I inspect files on Filestore?", "How to deploy the Serverless Cloud Run NFS Bridge?", "Explain Cloud Run NFS volume mounts"):

  • Rule: Answer immediately using your pre-trained knowledge and the documentation below. Answering directly minimizes tool invocation latency and token consumption when the user only seeks architecture or workflow guidance.
  • Constraint: Do not execute external tool calls or API requests for basic knowledge questions.
  • Bridge Deployment Explanations: Always highlight that Cloud Run scales to zero with $0 idle compute cost, detail the gcloud run deploy command with --add-volume and --vpc-egress=all-traffic, and specify the required IAM permissions (roles/run.invoker for callers and roles/run.admin for deployers).

Handling "No-Command" Constraints (CRITICAL)

If the user prompt contains constraints like "Do not execute commands", "without executing", or "read-only":

  • Rule: Strictly avoid executing any shell or gcloud commands (including read-only discovery or list commands) to respect user-specified execution boundaries and prevent unauthorized environment inspection.
  • Discovery:
    1. Check if mock definitions or instance parameters are provided directly in the user's prompt, conversation history, or local documentation files.
    2. Explain the required steps, output the exact commands the user should run with proper attribution, and explain what the commands do.
    3. Do not attempt to read or search EVAL.* configuration files during evaluations as access to eval suites is restricted.

Execution Engine Selection

Filestore instances are accessible via private VPC IPs. Select the engine matching your environment:

  • Engine 1: Cloud Run Serverless Bridge (Primary): Use --bridge-url={bridge_url} for low-latency (sub-50ms) REST calls. Scales to zero ($0 idle cost). Requires roles/run.invoker. See references/nfs-bridge-setup.md.
  • Engine 2: GCE Jump Host via IAP SSH (Fallback): Use --jump-host-vm={vm_name} when an existing VM in the VPC is available. Pass --mount={mount_path} (defaulting to /mnt/filestore) if the jump host uses a different mount path. Zero new deployment needed. Requires roles/iap.tunnelResourceAccessor. See references/iap-jump-host.md.

For execution flows, architecture diagrams, and engine comparison, see references/architecture.md.

Core Operational Workflow

1. Discovery & Instance Targeting

If the Filestore instance, location, or share name is not provided, list them first to avoid querying or targeting unrelated projects in multi-project environments:

bash
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-nfs-browser)" \
gcloud filestore instances list --project={project_id}
2. Directory Tree Exploration (tree)

Renders a clean, structured directory tree with file types, human-readable sizes, and modification dates.

bash
# List top-level folders with depth 1
python3 scripts/nfs_browser.py tree \
  --project={project_id} \
  --instance={instance_id} \
  --path=/ \
  --depth=1

# List subfolder recursively with depth 2 and pagination cap
python3 scripts/nfs_browser.py tree \
  --project={project_id} \
  --instance={instance_id} \
  --path=/backup/logs/ \
  --depth=2 \
  --max-entries=100

Searches for filenames matching a glob pattern and/or searches text contents for regex patterns.

bash
# Search for all tar.gz backup archives
python3 scripts/nfs_browser.py search \
  --project={project_id} \
  --instance={instance_id} \
  --path=/backups/ \
  --pattern="*.tar.gz"

# Grep for error patterns inside log files
python3 scripts/nfs_browser.py search \
  --project={project_id} \
  --instance={instance_id} \
  --path=/app/logs/ \
  --pattern="*.log" \
  --grep="FATAL|Exception|OutOfMemory" \
  --max-results=25
4. Chunked File Reading (read)

Safely reads text file chunks to protect the LLM context window against token blowup. Always default to a safe chunk size (e.g., --head 50 or --tail 50) when the user does not specify an explicit range. Unbounded reads are automatically capped to a safe limit of 100 lines. Always explicitly explain that chunked reading protects the LLM context window from overflow and token exhaustion.

bash
# Read the last 50 lines (tail) of a log file
python3 scripts/nfs_browser.py read \
  --project={project_id} \
  --instance={instance_id} \
  --path=/backup/logs/app.log \
  --tail=50

# Read lines 100 to 200 of a config file
python3 scripts/nfs_browser.py read \
  --project={project_id} \
  --instance={instance_id} \
  --path=/config/settings.yaml \
  --lines=100:200

# Read the first 30 lines (head)
python3 scripts/nfs_browser.py read \
  --project={project_id} \
  --instance={instance_id} \
  --path=/var/log/syslog \
  --head=30
5. File Metadata & Attribute Inspection (stat)

Inspects POSIX permissions (0644), UID/GID, byte sizes, and timestamps.

bash
python3 scripts/nfs_browser.py stat \
  --project={project_id} \
  --instance={instance_id} \
  --path=/backup/database_dump.tar.gz
Show full SKILL.md (417 more words)Show less

Context Window & LLM Safety Rules

  1. Strictly Read-Only Guarantee: This skill is strictly read-only. It provides no write, edit, delete, or truncate capabilities.
  2. Never Dump Entire Large Files: Always request a slice (--lines), head (--head 50), or tail (--tail 50) and explicitly explain that chunked reading protects the LLM context window against token overflow and client timeouts.
  3. Handle Pagination: Tree listings are capped at 100 entries per response. When truncated, the tool outputs a clear [TRUNCATED] notice so the agent can target specific subpaths.
  4. Binary Protection: Non-text files (e.g. .tar.gz, .iso, .so, compiled binaries) are detected via null-byte and magic-byte inspection; raw binary output is suppressed and metadata is displayed instead to prevent context corruption with non-printable characters.
  5. See references/token-safety-guardrails.md for full token guardrail details.

Expected Errors & Recovery Strategies

| Error Type / | Root Cause | Recovery Strategy |

: Symptom : : : | :------------------ | :----------------- | :------------------------------------------ | | FileNotFoundError: | Path does not | Run tree --path=/ --depth=2 to discover | : File not found : exist on the NFS : valid directory hierarchies. : : : export. : : | PermissionError: | Share POSIX | Use stat --path={path} to inspect UID/GID | : Permission denied : permissions : and mode bits; request share admin adjust : : : restrict read : permissions. : : : access. : : | HTTPException: 403 | Path parameter | Use clean paths (e.g. /logs/app.log) | : Access denied\: : contains ../ or : anchored to the NFS mount root. : : path traversal : a symlink : : : : attempting escape : : : : outside mount : : : : point. : : | Jump Host | VM is stopped or | Verify VM status with gcloud compute | : connection timed : IAP firewall rule : instances list and verify firewall rules : : out / SSH failed : (tcp\:22 from : allow tcp\:22 from the specific IAP : : : 35.235.240.0/20) : netblock 35.235.240.0/20 (e.g., gcloud : : : is missing. : compute firewall-rules list : : : : --filter="sourceRanges\:35.235.240.0/20"). : | Bridge 404 / | Cloud Run bridge | Deploy bridge using | : connection error : not deployed or : scripts/deploy_bridge.sh or fall back to : : : URL invalid. : GCE IAP Jump Host via --jump-host. :

Reference Directory

For progressive disclosure of deeper topics, consult the references/ directory:

Bundled Scripts & Components

The skill package bundles the following scripts and service components:

  • scripts/nfs_browser.py: Main CLI entrypoint for browsing, searching, reading, and stating NFS exports.
  • scripts/formatters.py: Output formatters for human-readable terminal rendering and token-safe summaries.
  • scripts/jump_host_engine.py: Remote SSH jump host execution engine via Google Cloud IAP tunnel.
  • scripts/nfs_browser_test.py: Comprehensive unit test suite covering formatters, HTTP bridge, and SSH jump host engines.
  • scripts/deploy_bridge.sh: Automated Cloud Run deployment script for the Serverless NFS Bridge.
  • scripts/bridge_server/main.py: FastAPI Cloud Run server implementation for direct NFS mounts.
  • scripts/bridge_server/Dockerfile: Container definition for packaging the Serverless NFS Bridge.
  • scripts/bridge_server/requirements.txt: Python dependencies for the Cloud Run bridge service.

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (scripts, references) in skills/cloud/google-cloud-filestore-nfs-browser of google/skills.

  • SKILL.md
  • references/architecture.md
  • references/iap-jump-host.md
  • references/nfs-bridge-setup.md
  • references/token-safety-guardrails.md
  • references/troubleshooting.md
  • scripts/bridge_server/Dockerfile
  • scripts/bridge_server/main.py
  • scripts/bridge_server/requirements.txt
  • scripts/deploy_bridge.sh
  • scripts/formatters.py
  • scripts/jump_host_engine.py
  • scripts/nfs_browser.py
  • scripts/nfs_browser_test.py

Open the folder on GitHubat commit 5120a76

Compare with similar skills

Google Cloud Filestore Nfs Browser next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Cloud Filestore Nfs Browser compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Cloud Filestore Nfs Browser this skillgoogle/skills21k—~3kAutomated safety check: PassApache-2.0
Google Cloud Agent SDK Masterjeremylongshore/tons-of-skills-marketplace2.8k—~1.4kAutomated safety check: PassMIT
Devopsnicepkg/auto-company1942 repos~814Automated safety check: PassMIT
Retail Product Search Agentgoogle/adk-recipes10k—~3kAutomated safety check: PassApache-2.0
Broccoli Oss GCP Deploybesimple-oss/broccoli286—~4.1kAutomated safety check: PassMIT
Canaryatelier-fashion/adlc-toolkit171—~2.2kAutomated safety check: PassMIT

Similar skills

  • Google Cloud Agent SDK Master

    jeremylongshore/tons-of-skills-marketplace

    Build, evaluate, deploy, publish, or modernize Google ADK agent applications with Google's maintained agents-cli workflow.

    2.8k GitHub stars~1.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    194 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • Retail Product Search Agent

    google/adk-recipes

    Official

    Builds a retail product search agent on Google Cloud, from catalog ingestion into BigQuery and Vector Search to ADK scaffolding, evaluation and Cloud Run deployment.

    10k GitHub stars~3k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Broccoli Oss GCP Deploy

    besimple-oss/broccoli

    Deploy this repository to a new Google Cloud project using the repo's existing Cloud Run, Cloud Run Jobs, Cloud SQL, Secret Manager, and Artifact Registry scripts.

    286 GitHub stars~4.1k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Canary

    atelier-fashion/adlc-toolkit

    Canary deployment with smoke tests — deploy to a zero-traffic revision, run health checks, and promote on success.

    171 GitHub stars~2.2k tokensUpdated 11 days ago
    DevOps & CloudAuto-check passed
  • Drawio GCP

    sparklabx/drawio-ai-kit

    A skill your agent uses when the user asks for a GCP or Google Cloud architecture diagram — VPC/networking, GKE, Cloud Run, landing zone, multi-region, or any diagram built with GCP service icons.

    654 GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from google/skills

All 147 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated today
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated today
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Google Cloud Filestore Nfs Browser

What does Google Cloud Filestore Nfs Browser do?

Inspects, searches, and reads files and POSIX metadata on Filestore (NFS) instances on Google Cloud without local NFS client packages or root privileges. Google Cloud Filestore Nfs Browser is an agent skill from google/skills, published by the product's own GitHub organization. Inspects, searches, and reads files and POSIX metadata on Filestore (NFS) instances on Google Cloud without local NFS client packages or root privileges.

When should I use Google Cloud Filestore Nfs Browser?

Google Cloud Filestore Nfs Browser fits situations like: browsing Filestore shares; searching files; reading remote logs; inspecting file attributes.

How do I install Google Cloud Filestore Nfs Browser in Claude Code?

Run `npx skills add google/skills --skill google-cloud-filestore-nfs-browser -a claude-code`. Or copy the skill folder (skills/cloud/google-cloud-filestore-nfs-browser in google/skills) into .claude/skills/google-cloud-filestore-nfs-browser in your project. Claude Code loads it when a task matches its description.

How do I install Google Cloud Filestore Nfs Browser in Codex?

Run `npx skills add google/skills --skill google-cloud-filestore-nfs-browser -a codex`. Or copy the skill folder (skills/cloud/google-cloud-filestore-nfs-browser in google/skills) into .agents/skills/google-cloud-filestore-nfs-browser in your project. Codex loads it when a task matches its description.

Can I use Google Cloud Filestore Nfs Browser in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill google-cloud-filestore-nfs-browser -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-cloud-filestore-nfs-browser, .gemini/skills/google-cloud-filestore-nfs-browser, .github/skills/google-cloud-filestore-nfs-browser and .opencode/skills/google-cloud-filestore-nfs-browser in your project.

What does Google Cloud Filestore Nfs Browser need to run?

Going by SKILL.md and its folder, Google Cloud Filestore Nfs Browser needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (python3 and gcloud). Our summary lists: Python 3; A Bash shell.

Does Google Cloud Filestore Nfs Browser access the network?

SKILL.md names 1 domain. As links in the text: cloud.google.com. This is read from the text; nothing was executed.

Is Google Cloud Filestore Nfs Browser safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Google Cloud Filestore Nfs Browser use?

Google Cloud Filestore Nfs Browser is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Cloud Filestore Nfs Browser use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.2k tokens, read only when the agent opens those files.

What are the alternatives to Google Cloud Filestore Nfs Browser?

Skills that share tags, products or a category with Google Cloud Filestore Nfs Browser: Google Cloud Agent SDK Master (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Devops (nicepkg/auto-company, 194 stars), Retail Product Search Agent (google/adk-recipes, 10k stars) and Broccoli Oss GCP Deploy (besimple-oss/broccoli, 286 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Cloud Filestore Nfs Browser?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,069 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on October 9, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.