Official agent skill

Google Cloud Networking Observability

by google in google/skills

Investigates Google Cloud networking issues by analyzing GCP logs, metrics, and diagnostics.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Google Cloud Networking Observability

skills CLI
$ npx skills add google/skills --skill google-cloud-networking-observability -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills google-cloud-networking-observability --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/google-cloud-networking-observability .claude/skills/google-cloud-networking-observability && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
google-cloud-networking-observability
GitHub stars
21k
Token cost
~2k tokens
SKILL.md length
904 words
Files
9 (incl. references)
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Investigates Google Cloud networking issues by analyzing GCP logs, metrics, and diagnostics.

  • Works in 4 steps: Log Source Preference → Tool Selection & Discovery → Schema Verification & Error Recovery → …
  • Investigating dropped network traffic
  • SKILL.md covers 🛑 Core Directive: Results First, Log & Telemetry Overview, Procedures and Boundaries (CRITICAL)
  • Calls gcloud

What it does

Google Cloud Networking Observability is an agent skill from google/skills, published by the product's own GitHub organization. Investigates Google Cloud networking issues by analyzing GCP logs, metrics, and diagnostics. Use when investigating dropped network traffic, packet drops, drop reasons, VPC Flow Logs (including Private Service Connect / PSC, serverless / App Engine Direct VPC, and cost estimation), NAT, firewall, or threat logs, querying latency and throughput metrics, or running Connectivity Tests for path diagnostics. Don't use for generic VM management or non-observability tasks.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `references/cloud-nat-analysis.md`, `references/connectivity-tests.md` and `references/firewall-analysis.md`).

It sits in DevOps & Cloud, covering Observability and Serverless. It works with Google Cloud. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Investigating dropped network traffic
  • VPC Flow Logs (including Private Service Connect / PSC
  • Serverless / App Engine Direct VPC
  • Cost estimation)

Example prompts

  • “Use the google-cloud-networking-observability skill to investigate Google Cloud networking issues by analyzing GCP logs, metrics, and diagnostics”
  • “/google-cloud-networking-observability”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Log Source Preference
  2. Tool Selection & Discovery
  3. Schema Verification & Error Recovery
  4. Analysis Guides (Read Only When Needed)

What it can do on your machine

Read from SKILL.md and the folder at commit 7d97937. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • console.cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Cloud Networking Observability loads about 2k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 127 tokens; SKILL.md has 904 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~127
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 7d97937, republished under its Apache-2.0 licence (© google). 904 words, ~2,025 tokens.

Download SKILL.mdSave it as .claude/skills/google-cloud-networking-observability/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
google-cloud-networking-observability
description
Investigates Google Cloud networking issues by analyzing GCP logs, metrics, and diagnostics. Use when investigating dropped network traffic, packet drops, drop reasons, VPC Flow Logs (including Private Service Connect / PSC, serverless / App Engine Direct VPC, and cost estimation), NAT, firewall, or threat logs, querying latency and throughput metrics, or running Connectivity Tests for path diagnostics. Don't use for generic VM management or non-observability tasks.
metadata.version
1.0.3
metadata.category
Compute

Google Cloud Networking Observability Expert

🛑 Core Directive: Results First

  1. Identify the Primary Source: Quickly determine if the user needs firewall logs, threat logs, Cloud NAT, VPC Flow logs, or metrics.
  2. Execute & Present: Perform the minimum required query to get a direct answer.
  3. Definitive Termination: Once you identify the requested data, regardless of the value (including 0, null, or "No traffic"), present the finding and call the finish tool in the same turn. Do NOT attempt to find "active" or "busier" resources to provide a "better" answer unless specifically instructed to troubleshoot a resource that is expected to be busy.

Log & Telemetry Overview

  • Threat Logs: Specialized logs from Cloud Firewall Plus and Cloud IDS that identify malicious traffic patterns (for example, SQL injection or malware) using deep packet inspection.
  • VPC Flow Logs: Capture sample IP traffic to and from network interfaces. Use for traffic analysis, volume trends, top talkers, dropped traffic, and packet loss.
  • Firewall Logs: Record connection attempts matched by firewall rules. Use to identify "DENY" events or verify "ALLOW" rules.
  • Cloud NAT Logs: Audit NAT translations. Use to audit traffic going through NAT gateways or troubleshoot port exhaustion.
  • Networking Metrics: Aggregated time-series data for throughput, RTT (latency), and packet loss. Use for historical trends and performance monitoring.
  • Connectivity Tests: Static analysis tool for path diagnostics. Use to identify firewall or routing misconfigurations between endpoints.

Procedures

0. Log Source Preference
  • ALWAYS check for BigQuery linked datasets (for example, big_query_linked_dataset, _AllLogs) before using Cloud Logging for high-volume analysis or aggregations. This is the preferred method for finding trends or top-blocking rules.
  • Schema & Sample Discovery: Before writing complex aggregations or filter queries in BigQuery or Cloud Logging, first inspect a single sample log record (LIMIT 1 in SQL or --limit=1 in gcloud logging read) to verify the exact payload schema and field paths.
  • Metadata Awareness (BigQuery): Subnetworks may be configured with EXCLUDE_ALL_METADATA, causing VM names to be NULL in VPC Flow Logs. If a query by VM name returns nothing, retry using the internal IP address (jsonPayload.connection.src_ip).
1. Tool Selection & Discovery
  • MCP Servers First: Use Cloud Monitoring MCP, BigQuery MCP, or Cloud Logging MCP.
  • Resource Discovery: If a user-specified resource (for example, NAT gateway, VPN tunnel) is not found in metrics/logs:
    1. Use run_shell_command with gcloud to list resources in the project.
    2. Search Cloud Logging MCP for the resource name to find correct labels.
  • CLI Fallback: Use gcloud or bq only if MCP servers are unavailable. DO NOT use gcloud monitoring; it is restricted. Immediately use the curl templates in metrics-analysis.md.
2. Schema Verification & Error Recovery

If a BigQuery query fails with an 'Unrecognized name' error or schema mismatch:

  1. Validate Schema: Run bq show --schema --format=json {project_id}:{dataset_id}.{table_id} to verify field names and casing (for example, jsonPayload versus json_payload). 2. Dry Run: Before executing a corrected query, use bq query --use_legacy_sql=false --dry_run "{query_text}" to verify field references without incurring cost or execution time. 3. Retry: Apply identified fixes to the original query and execute.
3. Analysis Guides (Read Only When Needed)

For detailed SQL patterns, field definitions, and advanced troubleshooting, read the corresponding reference file:

CRITICAL: If the user asks for Cost Estimation, you MUST strictly use references/vpc-flow-logs-cost-estimation.md. Do NOT read or use references/vpc-flow-analysis.md for cost estimation tasks.

Show full SKILL.md (335 more words)Show less

Boundaries (CRITICAL)

  • ALWAYS present the direct answer as soon as it is identified.
  • NEVER run more than 2 exploratory queries before showing results.
  • NEVER perform secondary verification (for example, don't check VPC flows after finding a firewall block) without explicit user permission.
  • ALWAYS print the generated SQL for review before execution.
  • ALWAYS include a link to the Flow Analyzer in the Google Cloud Console.
  • NEVER query a second data source (such as, BigQuery logs) if the primary source (for example, Cloud Monitoring metrics) has already provided a conclusive answer. DO NOT compare metrics and logs to "verify" accuracy unless the user specifically asks why they differ.
  • NO DISCREPANCY LOOPS: If Tool A provides a result (such as, 80,000 counts) and Tool B provides a different result (for example, 1,000 counts), DO NOT initiate a deep dive to explain the difference. Present the result from the primary tool and STOP.
  • ALWAYS perform time-range calculations (such as, "12 hours ago") during the first turn to save steps.
  • Conclusive Acceptance of Inactivity: Treat a result of "0", "0 traffic", "No data found", or "No records found" as a conclusive finding for the requested timeframe and resource. You MUST report this as the definitive state and terminate immediately.
  • Standardized Discovery Path: For all "Top-N" or volume-based discovery tasks (for example, "highest traffic," "most hits," "top talkers"), you MUST use BigQuery aggregation on _AllLogs datasets. Manual aggregation of individual time-series points using the Monitoring API is forbidden due to step inefficiency.
  • Ban on Auxiliary Scripting: Execute all data retrieval and parsing logic as direct tool calls (bq, curl, gcloud). Do NOT write or execute local shell scripts (.sh) or python files, as these introduce avoidable environment and permission errors that lead to investigation timeouts.
  • Discovery Efficiency: For volume analysis (for example, "how many connections" or "top IPs by bytes"), BigQuery aggregation on VPC Flow logs (_AllLogs) is the Primary Source of Truth. If BigQuery data is available, it is conclusive. Do NOT query Monitoring API to "double check" BigQuery counts.

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (references) in skills/cloud/google-cloud-networking-observability of google/skills.

  • SKILL.md
  • references/cloud-nat-analysis.md
  • references/connectivity-tests.md
  • references/firewall-analysis.md
  • references/mcp-usage.md
  • references/metrics-analysis.md
  • references/threat-analysis.md
  • references/vpc-flow-analysis.md
  • references/vpc-flow-logs-cost-estimation.md

Open the folder on GitHubat commit 7d97937

Compare with similar skills

Google Cloud Networking Observability next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Cloud Networking Observability compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Cloud Networking Observability this skillgoogle/skills21k—~2kAutomated safety check: PassApache-2.0
Agent Advisoraws/agent-toolkit-for-aws2.8k—~4.9kAutomated safety check: PassApache-2.0
Logfire Infrastructurepydantic/skills140—~1.8kAutomated safety check: PassMIT
Cloud Devopsdavila7/claude-code-templates32k4 repos~1.4kAutomated safety check: PassMIT
GCP Cloud Architectalirezarezvani/claude-skills28k—~3.2kAutomated safety check: PassMIT
Gcloud Usagefcakyon/claude-codex-settings1.2k—~871Automated safety check: PassApache-2.0

Similar skills

  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Logfire Infrastructure

    pydantic/skills

    Official

    Monitor hosts, Docker containers, Kubernetes clusters, database/queue/cache servers, and cloud-provider metrics with Pydantic Logfire — no application code required.

    140 GitHub stars~1.8k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Cloud Devops

    davila7/claude-code-templates

    Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.

    32k GitHub starsUsed in 4 repos~1.4k tokens
    DevOps & CloudAuto-check passed
  • GCP Cloud Architect

    alirezarezvani/claude-skills

    Design GCP architectures for startups and enterprises. An agent skill from alirezarezvani/claude-skills.

    28k GitHub stars~3.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Gcloud Usage

    fcakyon/claude-codex-settings

    This skill should be used when user asks about "GCloud logs", "Cloud Logging queries", "Google Cloud metrics", "GCP observability", "trace analysis", or "debugging production issues on GCP".

    1.2k GitHub stars~871 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Dt Obs Network Flows

    Dynatrace/dynatrace-for-ai

    Network flow analysis in Dynatrace across three sources: OneAgent flows (host/process/pod-to-peer connections in the defaultnetworkflows Grail bucket), NetFlow/IPFIX/sFlow (via an OpenTelemetry…

    161 GitHub starsUsed in 1 repo~2k tokens
    DevOps & CloudAuto-check passed

More from google/skills

All 147 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated today
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated today
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Google Cloud Networking Observability

What does Google Cloud Networking Observability do?

Investigates Google Cloud networking issues by analyzing GCP logs, metrics, and diagnostics. Google Cloud Networking Observability is an agent skill from google/skills, published by the product's own GitHub organization. Investigates Google Cloud networking issues by analyzing GCP logs, metrics, and diagnostics.

When should I use Google Cloud Networking Observability?

Google Cloud Networking Observability fits situations like: investigating dropped network traffic; VPC Flow Logs (including Private Service Connect / PSC; serverless / App Engine Direct VPC; cost estimation).

How do I install Google Cloud Networking Observability in Claude Code?

Run `npx skills add google/skills --skill google-cloud-networking-observability -a claude-code`. Or copy the skill folder (skills/cloud/google-cloud-networking-observability in google/skills) into .claude/skills/google-cloud-networking-observability in your project. Claude Code loads it when a task matches its description.

How do I install Google Cloud Networking Observability in Codex?

Run `npx skills add google/skills --skill google-cloud-networking-observability -a codex`. Or copy the skill folder (skills/cloud/google-cloud-networking-observability in google/skills) into .agents/skills/google-cloud-networking-observability in your project. Codex loads it when a task matches its description.

Can I use Google Cloud Networking Observability in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill google-cloud-networking-observability -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-cloud-networking-observability, .gemini/skills/google-cloud-networking-observability, .github/skills/google-cloud-networking-observability and .opencode/skills/google-cloud-networking-observability in your project.

What does Google Cloud Networking Observability need to run?

Going by SKILL.md and its folder, Google Cloud Networking Observability needs the command-line tools its instructions call (gcloud). Our summary lists: Python 3.

Does Google Cloud Networking Observability access the network?

SKILL.md names 1 domain. As links in the text: console.cloud.google.com. This is read from the text; nothing was executed.

Is Google Cloud Networking Observability safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Google Cloud Networking Observability use?

Google Cloud Networking Observability is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Cloud Networking Observability use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.3k tokens, read only when the agent opens those files.

What are the alternatives to Google Cloud Networking Observability?

Skills that share tags, products or a category with Google Cloud Networking Observability: Agent Advisor (aws/agent-toolkit-for-aws, 2.8k stars), Logfire Infrastructure (pydantic/skills, 140 stars), Cloud Devops (davila7/claude-code-templates, 32k stars) and GCP Cloud Architect (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Cloud Networking Observability?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,032 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on October 8, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.