Official agent skill

Google Cloud Scc Remediation

by google in google/skills

Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations.

OfficialApache-2.0Auto-check passedSecurity

Install Google Cloud Scc Remediation

skills CLI
$ npx skills add google/skills --skill google-cloud-scc-remediation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills google-cloud-scc-remediation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/google-cloud-scc-remediation .claude/skills/google-cloud-scc-remediation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
google-cloud-scc-remediation
GitHub stars
21k
Token cost
~3k tokens
SKILL.md length
1,106 words
Files
4 (incl. references)
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations.

  • Works in 3 steps: Safety & Consent Gate → Intent Router & Progressive Disclosure → Standard Remediation Workflow
  • Mitigate a Security Command Center finding
  • SKILL.md covers Overview, 1. Safety & Consent Gate, 2. Intent Router & Progressive… and 3. Standard Remediation Workflow
  • Calls gcloud; needs USER_MANAGED_SERVICE_ACCOUNT_KEY

What it does

Google Cloud Scc Remediation is an agent skill from google/skills, published by the product's own GitHub organization. Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations. Use when asked to fix, remediate, or mitigate a Security Command Center finding or address attack paths. Don't use for general IAM policy querying without a Security Command Center finding. For runtime threat detections, this skill provides containment and investigation guidance rather than automated configuration fixes.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/remediation_iam.md`, `references/remediation_misconfig.md` and `references/remediation_vuln.md`).

It sits in Security, covering Cloud security. It works with Google Cloud. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Mitigate a Security Command Center finding
  • Address attack paths
  • General IAM policy querying without a Security Command Center finding

Example prompts

  • “Use the google-cloud-scc-remediation skill to remediate Google Cloud Security Command Center findings, including IAM permission fixes, cloud…”
  • “/google-cloud-scc-remediation”

Requirements

  • A credential in USER_MANAGED_SERVICE_ACCOUNT_KEY

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Safety & Consent Gate
  2. Intent Router & Progressive Disclosure
  3. Standard Remediation Workflow

What it can do on your machine

Read from SKILL.md and the folder at commit 5120a76. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • USER_MANAGED_SERVICE_ACCOUNT_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Cloud Scc Remediation loads about 3k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 129 tokens; SKILL.md has 1,106 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 5120a76, republished under its Apache-2.0 licence (© google). 1,106 words, ~3,041 tokens.

Download SKILL.mdSave it as .claude/skills/google-cloud-scc-remediation/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
google-cloud-scc-remediation
description
Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations. Use when asked to fix, remediate, or mitigate a Security Command Center finding or address attack paths. Don't use for general IAM policy querying without a Security Command Center finding. For runtime threat detections, this skill provides containment and investigation guidance rather than automated configuration fixes.
metadata.category
Security
metadata.version
1.0.0

Google Cloud Security Command Center Remediation

Overview

A unified remediation skill for Google Cloud Security Command Center findings. It handles both single-domain findings and multi-domain Toxic Combinations.

Security Command Center remediations modify infrastructure, access policies, or workload deployments.

  • Mandatory Consent Gate: NEVER execute mutating gcloud, terraform, or API commands without first presenting a structured remediation plan and the exact command/config diff to the user. STOP after presenting the plan and ALWAYS ask: "Do you approve executing this remediation plan?" before execution. Automatic mutation of security policies or resource configurations can cause unintended outages, lockouts, or compliance violations.

  • Confirm the Target Project: Before executing, confirm that the active gcloud account and project match the project of the finding's resource. Every mutating command MUST specify the target explicitly, with --project or a full resource path, rather than relying on the default gcloud project.

  • Verification & Rollback Required: Every proposed remediation plan MUST explicitly include, for each mutating step:

    • the mutating remediation command(s),
    • the verification check command(s) (gcloud ... describe or list), and
    • the rollback command(s) that undo the change, or an explicit statement that the step cannot be undone (for example, service account key deletion).

    Use the commands from the loaded playbook where they exist. If the playbook lacks a verification or rollback command for a step, derive the command and label it as not sourced from a playbook.

  • Dependency & Impact Checks: Every remediation plan MUST state what could break as a result of each change and ask the user to confirm nothing depends on it. For example:

    • IAM role changes or revocations: you MUST explicitly advise the user to verify cross-project dependencies and CI/CD pipeline workflows that rely on the existing permissions before revoking a project-level role binding.
    • Firewall rule changes: other traffic the same rule allows (such as web traffic on ports 80 or 443).
    • External IP removal: inbound access and outbound internet access for the VM.
    • Public Access Prevention on a bucket: sites or users that legitimately read it publicly.
  • CRITICAL WORKFLOW RULE: Do NOT execute any mutating commands in the same turn that you present the remediation plan. You MUST end your turn immediately after asking for approval and wait for the user's next message.

    • If there is no interactive user (for example, a scheduled or pipeline run), stop at the plan and never execute.
    • If the user approves only part of the plan, or the plan changes after approval, present the updated plan and ask for approval again before executing.
  • Narrowly Scoped Changes: Always propose the narrowest possible fix that resolves the finding. When more than one fix would work, prefer reversible changes over irreversible ones (for example, disable a key before deleting it), resource-level changes over project, folder, or organization-level changes, and changes that affect only the finding's resource over changes that affect other resources. Do not bundle fixes for unrelated issues noticed along the way; mention them to the user separately.

2. Intent Router & Progressive Disclosure

Do not load all reference playbooks into memory at once. Analyze the Security Command Center finding's category, findingClass, or attack path, then read ONLY the relevant reference document(s).

Match on the finding's category first, and fall back to findingClass only when no category matches. Routing on findingClass alone misroutes IAM findings: Security Health Analytics IAM findings are MISCONFIGURATION class, and IAM recommender findings are Vulnerability class, so neither would ever reach the IAM playbook.

Match OnValuesTarget Reference Playbook
categoryPRIMITIVE_ROLES_USED,references/remediation_iam.md
: (Security Health : OVER_PRIVILEGED_SERVICE_ACCOUNT_USER, : :
: Analytics) : ADMIN_SERVICE_ACCOUNT, : :
: : SERVICE_ACCOUNT_ROLE_SEPARATION, : :
: : KMS_ROLE_SEPARATION, : :
: : USER_MANAGED_SERVICE_ACCOUNT_KEY, : :
: : SERVICE_ACCOUNT_KEY_NOT_ROTATED : :
categoryIAM_ROLE_HAS_EXCESSIVE_PERMISSIONS,references/remediation_iam.md
: (IAM recommender) : UNUSED_IAM_ROLE, : :
: : SERVICE_AGENT_GRANTED_BASIC_ROLE, : :
: : SERVICE_AGENT_ROLE_REPLACED_WITH_BASIC_ROLE : :
categoryPUBLIC_BUCKET_ACL, PUBLIC_IP_ADDRESS,references/remediation_misconfig.md
: (Security Health : OPEN_FIREWALL, OPEN_SSH_PORT, : :
: Analytics) : OPEN_RDP_PORT, KMS_KEY_NOT_ROTATED : :
categoryOS_VULNERABILITY, SOFTWARE_VULNERABILITY,references/remediation_vuln.md
: : GKE_RUNTIME_OS_VULNERABILITY (CVEs, OS : :
: : patch, container base image upgrade, : :
: : vulnerable package, GKE node pool upgrade). : :
: : Note: Web Security Scanner (WSS) findings : :
: : fall through to no match below. : :
findingClassTOXIC_COMBINATION — attack pathSequential Load: Identify each exposed facet in the attack path and load
: : exposure, multi-domain attack vector : the matching reference playbooks sequentially. :
no matchAny other category or finding classSee Findings Without Dedicated Playbooks below. Do not force a finding
: : : into a playbook that does not cover it. :
Show full SKILL.md (420 more words)Show less
Findings Without Dedicated Playbooks & Runtime Threat Detections

When presented with Security Command Center findings that do not have automated configuration remediation playbooks—such as runtime threat detections (e.g., Cloud Run Threat Detection, Agent Platform Threat Detection, Event Threat Detection, Container Threat Detection):

  1. Do NOT execute automated mutation commands: Runtime threat detections represent active alerts or behavioral anomalies rather than static resource misconfigurations.
  2. Provide Documentation & Containment Guidance:
    • Refer the user to the relevant Security Command Center documentation (e.g., Cloud Run Threat Detection, Agent Platform Threat Detection).
    • Recommend manual investigation steps: analyzing audit logs in Cloud Logging, identifying compromised service accounts or API keys, and isolating affected workloads.
    • Advise the user on containment options (e.g., revoking active credentials, blocking malicious IPs at Cloud Armor/firewall).

3. Standard Remediation Workflow

  1. Inspect Finding Details & Intentionality:
    • If the finding's details are not already in the conversation, retrieve them using the google-cloud-scc-query skill. Verify the finding name, affected resource (resourceName), category, and attack exposure score.
    • Before planning a fix, ask the user whether the flagged configuration is intentional (for example, a bucket serving a public website, or a VM that must accept public traffic). If it is, do not propose a remediation. Suggest muting the finding with a documented justification instead; muting changes the finding's state, so it also requires the user's approval.
  2. Route & Load Reference: Read the matching reference playbook(s) from the routing table above.
  3. Formulate Least-Privilege Remediation: Before drafting, check whether the resource is managed by infrastructure as code (ask the user, and check for signals such as the goog-terraform-provisioned label). If it is, draft the change to the Terraform configuration rather than a gcloud command. Otherwise, draft the exact CLI (gcloud) or IAM binding change needed to close the exposure without disrupting business workloads.
  4. Present Plan & Seek Consent: Show the user the plan required by the Safety & Consent Gate: for each step, the remediation command, the verification command, the rollback command, and what could break. STOP execution here and ALWAYS ask the explicit question: "Do you approve executing this remediation plan?"
  5. Execute on Approval: ONLY after receiving explicit user confirmation, execute the remediation commands and run the verification commands to confirm the resource is fixed. If a command fails, stop and report the error; do not try a different command without presenting it and getting approval again. Tell the user that the finding's state in Security Command Center updates on the detector's next scan, which may take some time, and do not manually mark the finding as resolved.

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/cloud/google-cloud-scc-remediation of google/skills.

  • SKILL.md
  • references/remediation_iam.md
  • references/remediation_misconfig.md
  • references/remediation_vuln.md

Open the folder on GitHubat commit 5120a76

Compare with similar skills

Google Cloud Scc Remediation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Cloud Scc Remediation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Cloud Scc Remediation this skillgoogle/skills21k—~3kAutomated safety check: PassApache-2.0
Cloud Auditbriiirussell/cybersecurity-skills413—~1.3kAutomated safety check: NotesMIT
Auditing Cloud With Cis Benchmarksmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Performing GCP Security Assessment With Forsetimukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Configuring Firewallsancoleman/ai-design-components526—~3.5kAutomated safety check: NotesMIT

Similar skills

  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Auditing Cloud With Cis Benchmarks

    mukul975/Anthropic-Cybersecurity-Skills

    Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing GCP Security Assessment With Forseti

    mukul975/Anthropic-Cybersecurity-Skills

    Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Configuring Firewalls

    ancoleman/ai-design-components

    Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.

    526 GitHub stars~3.5k tokensUpdated 10 mo ago
    SecurityAuto-check: notes
  • Hardening Cloud Posture

    trilwu/secskills

    Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

    157 GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from google/skills

All 147 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated today
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated today
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Works with

Questions about Google Cloud Scc Remediation

What does Google Cloud Scc Remediation do?

Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations. Google Cloud Scc Remediation is an agent skill from google/skills, published by the product's own GitHub organization. Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations.

When should I use Google Cloud Scc Remediation?

Google Cloud Scc Remediation fits situations like: mitigate a Security Command Center finding; address attack paths; general IAM policy querying without a Security Command Center finding.

How do I install Google Cloud Scc Remediation in Claude Code?

Run `npx skills add google/skills --skill google-cloud-scc-remediation -a claude-code`. Or copy the skill folder (skills/cloud/google-cloud-scc-remediation in google/skills) into .claude/skills/google-cloud-scc-remediation in your project. Claude Code loads it when a task matches its description.

How do I install Google Cloud Scc Remediation in Codex?

Run `npx skills add google/skills --skill google-cloud-scc-remediation -a codex`. Or copy the skill folder (skills/cloud/google-cloud-scc-remediation in google/skills) into .agents/skills/google-cloud-scc-remediation in your project. Codex loads it when a task matches its description.

Can I use Google Cloud Scc Remediation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill google-cloud-scc-remediation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-cloud-scc-remediation, .gemini/skills/google-cloud-scc-remediation, .github/skills/google-cloud-scc-remediation and .opencode/skills/google-cloud-scc-remediation in your project.

What does Google Cloud Scc Remediation need to run?

Going by SKILL.md and its folder, Google Cloud Scc Remediation needs the command-line tools its instructions call (gcloud) and credentials named USER_MANAGED_SERVICE_ACCOUNT_KEY. Our summary lists: A credential in USER_MANAGED_SERVICE_ACCOUNT_KEY.

Does Google Cloud Scc Remediation access the network?

SKILL.md names 1 domain. As links in the text: docs.cloud.google.com. This is read from the text; nothing was executed.

Is Google Cloud Scc Remediation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Google Cloud Scc Remediation use?

Google Cloud Scc Remediation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Cloud Scc Remediation use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.1k tokens, read only when the agent opens those files.

What are the alternatives to Google Cloud Scc Remediation?

Skills that share tags, products or a category with Google Cloud Scc Remediation: Cloud Audit (briiirussell/cybersecurity-skills, 413 stars), Auditing Cloud With Cis Benchmarks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Performing GCP Security Assessment With Forseti (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Cloud Scc Remediation?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,069 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on October 9, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.