Cloud Audit
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations.
$ npx skills add google/skills --skill google-cloud-scc-remediation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install google/skills google-cloud-scc-remediation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/google-cloud-scc-remediation .claude/skills/google-cloud-scc-remediation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "google-cloud-scc-remediation" agent skill from https://github.com/google/skills/tree/main/skills/cloud/google-cloud-scc-remediation into .claude/skills/google-cloud-scc-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-scc-remediation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/google/skills/tree/main/skills/cloud/google-cloud-scc-remediationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add google/skills --skill google-cloud-scc-remediation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install google/skills google-cloud-scc-remediation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cloud/google-cloud-scc-remediation .agents/skills/google-cloud-scc-remediation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "google-cloud-scc-remediation" agent skill from https://github.com/google/skills/tree/main/skills/cloud/google-cloud-scc-remediation into .agents/skills/google-cloud-scc-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-scc-remediation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill google-cloud-scc-remediation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install google/skills google-cloud-scc-remediation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cloud/google-cloud-scc-remediation .cursor/skills/google-cloud-scc-remediation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "google-cloud-scc-remediation" agent skill from https://github.com/google/skills/tree/main/skills/cloud/google-cloud-scc-remediation into .cursor/skills/google-cloud-scc-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-scc-remediation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/google/skills.git --path skills/cloud/google-cloud-scc-remediation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add google/skills --skill google-cloud-scc-remediation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install google/skills google-cloud-scc-remediation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cloud/google-cloud-scc-remediation .gemini/skills/google-cloud-scc-remediation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "google-cloud-scc-remediation" agent skill from https://github.com/google/skills/tree/main/skills/cloud/google-cloud-scc-remediation into .gemini/skills/google-cloud-scc-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-scc-remediation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install google/skills google-cloud-scc-remediationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add google/skills --skill google-cloud-scc-remediation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cloud/google-cloud-scc-remediation .github/skills/google-cloud-scc-remediation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "google-cloud-scc-remediation" agent skill from https://github.com/google/skills/tree/main/skills/cloud/google-cloud-scc-remediation into .github/skills/google-cloud-scc-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-scc-remediation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill google-cloud-scc-remediation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install google/skills google-cloud-scc-remediation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cloud/google-cloud-scc-remediation .opencode/skills/google-cloud-scc-remediation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "google-cloud-scc-remediation" agent skill from https://github.com/google/skills/tree/main/skills/cloud/google-cloud-scc-remediation into .opencode/skills/google-cloud-scc-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-cloud-scc-remediation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
google-cloud-scc-remediationRemediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations.
Google Cloud Scc Remediation is an agent skill from google/skills, published by the product's own GitHub organization. Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations. Use when asked to fix, remediate, or mitigate a Security Command Center finding or address attack paths. Don't use for general IAM policy querying without a Security Command Center finding. For runtime threat detections, this skill provides containment and investigation guidance rather than automated configuration fixes.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/remediation_iam.md`, `references/remediation_misconfig.md` and `references/remediation_vuln.md`).
It sits in Security, covering Cloud security. It works with Google Cloud. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 5120a76. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gcloudFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.cloud.google.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
USER_MANAGED_SERVICE_ACCOUNT_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Google Cloud Scc Remediation loads about 3k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 129 tokens; SKILL.md has 1,106 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from google/skills at commit 5120a76, republished under its Apache-2.0 licence (© google). 1,106 words, ~3,041 tokens.
.claude/skills/google-cloud-scc-remediation/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.A unified remediation skill for Google Cloud Security Command Center findings. It handles both single-domain findings and multi-domain Toxic Combinations.
Security Command Center remediations modify infrastructure, access policies, or workload deployments.
Mandatory Consent Gate: NEVER execute mutating gcloud, terraform, or
API commands without first presenting a structured remediation plan and the
exact command/config diff to the user. STOP after presenting the plan and
ALWAYS ask: "Do you approve executing this remediation plan?" before
execution. Automatic mutation of security policies or resource
configurations can cause unintended outages, lockouts, or compliance
violations.
Confirm the Target Project: Before executing, confirm that the active
gcloud account and project match the project of the finding's resource.
Every mutating command MUST specify the target explicitly, with --project
or a full resource path, rather than relying on the default gcloud
project.
Verification & Rollback Required: Every proposed remediation plan MUST explicitly include, for each mutating step:
gcloud ... describe or list), andUse the commands from the loaded playbook where they exist. If the playbook lacks a verification or rollback command for a step, derive the command and label it as not sourced from a playbook.
Dependency & Impact Checks: Every remediation plan MUST state what could break as a result of each change and ask the user to confirm nothing depends on it. For example:
CRITICAL WORKFLOW RULE: Do NOT execute any mutating commands in the same turn that you present the remediation plan. You MUST end your turn immediately after asking for approval and wait for the user's next message.
Narrowly Scoped Changes: Always propose the narrowest possible fix that resolves the finding. When more than one fix would work, prefer reversible changes over irreversible ones (for example, disable a key before deleting it), resource-level changes over project, folder, or organization-level changes, and changes that affect only the finding's resource over changes that affect other resources. Do not bundle fixes for unrelated issues noticed along the way; mention them to the user separately.
Do not load all reference playbooks into memory at once. Analyze the Security
Command Center finding's category, findingClass, or attack path, then read
ONLY the relevant reference document(s).
Match on the finding's category first, and fall back to findingClass
only when no category matches. Routing on findingClass alone misroutes IAM
findings: Security Health Analytics IAM findings are MISCONFIGURATION class,
and IAM recommender findings are Vulnerability class, so neither would ever
reach the IAM playbook.
| Match On | Values | Target Reference Playbook |
|---|---|---|
category | PRIMITIVE_ROLES_USED, | references/remediation_iam.md |
: (Security Health : OVER_PRIVILEGED_SERVICE_ACCOUNT_USER, : : | ||
: Analytics) : ADMIN_SERVICE_ACCOUNT, : : | ||
: : SERVICE_ACCOUNT_ROLE_SEPARATION, : : | ||
: : KMS_ROLE_SEPARATION, : : | ||
: : USER_MANAGED_SERVICE_ACCOUNT_KEY, : : | ||
: : SERVICE_ACCOUNT_KEY_NOT_ROTATED : : | ||
category | IAM_ROLE_HAS_EXCESSIVE_PERMISSIONS, | references/remediation_iam.md |
: (IAM recommender) : UNUSED_IAM_ROLE, : : | ||
: : SERVICE_AGENT_GRANTED_BASIC_ROLE, : : | ||
: : SERVICE_AGENT_ROLE_REPLACED_WITH_BASIC_ROLE : : | ||
category | PUBLIC_BUCKET_ACL, PUBLIC_IP_ADDRESS, | references/remediation_misconfig.md |
: (Security Health : OPEN_FIREWALL, OPEN_SSH_PORT, : : | ||
: Analytics) : OPEN_RDP_PORT, KMS_KEY_NOT_ROTATED : : | ||
category | OS_VULNERABILITY, SOFTWARE_VULNERABILITY, | references/remediation_vuln.md |
: : GKE_RUNTIME_OS_VULNERABILITY (CVEs, OS : : | ||
| : : patch, container base image upgrade, : : | ||
| : : vulnerable package, GKE node pool upgrade). : : | ||
| : : Note: Web Security Scanner (WSS) findings : : | ||
| : : fall through to no match below. : : | ||
findingClass | TOXIC_COMBINATION — attack path | Sequential Load: Identify each exposed facet in the attack path and load |
| : : exposure, multi-domain attack vector : the matching reference playbooks sequentially. : | ||
| no match | Any other category or finding class | See Findings Without Dedicated Playbooks below. Do not force a finding |
| : : : into a playbook that does not cover it. : |
When presented with Security Command Center findings that do not have automated configuration remediation playbooks—such as runtime threat detections (e.g., Cloud Run Threat Detection, Agent Platform Threat Detection, Event Threat Detection, Container Threat Detection):
google-cloud-scc-query skill. Verify the finding name,
affected resource (resourceName), category, and attack exposure score.goog-terraform-provisioned label). If it is, draft the
change to the Terraform configuration rather than a gcloud command.
Otherwise, draft the exact CLI (gcloud) or IAM binding change needed to
close the exposure without disrupting business workloads.© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/cloud/google-cloud-scc-remediation of google/skills.
Open the folder on GitHubat commit 5120a76
Google Cloud Scc Remediation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Google Cloud Scc Remediation this skillgoogle/skills | 21k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Cloud Auditbriiirussell/cybersecurity-skills | 413 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Auditing Cloud With Cis Benchmarksmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Performing GCP Security Assessment With Forsetimukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Configuring Firewallsancoleman/ai-design-components | 526 | — | ~3.5k | Automated safety check: Notes | MIT |
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
mukul975/Anthropic-Cybersecurity-Skills
Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…
mukul975/Anthropic-Cybersecurity-Skills
Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…
mukul975/Anthropic-Cybersecurity-Skills
Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage…
ancoleman/ai-design-components
Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.
trilwu/secskills
Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…
google/skills
Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.
google/skills
Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.
google/skills
Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.
google/skills
Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.
google/skills
Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.
google/skills
Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.
Works with
Categories
Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations. Google Cloud Scc Remediation is an agent skill from google/skills, published by the product's own GitHub organization. Remediates Google Cloud Security Command Center findings, including IAM permission fixes, cloud resource misconfigurations, vulnerabilities, and Toxic Combinations.
Google Cloud Scc Remediation fits situations like: mitigate a Security Command Center finding; address attack paths; general IAM policy querying without a Security Command Center finding.
Run `npx skills add google/skills --skill google-cloud-scc-remediation -a claude-code`. Or copy the skill folder (skills/cloud/google-cloud-scc-remediation in google/skills) into .claude/skills/google-cloud-scc-remediation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add google/skills --skill google-cloud-scc-remediation -a codex`. Or copy the skill folder (skills/cloud/google-cloud-scc-remediation in google/skills) into .agents/skills/google-cloud-scc-remediation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill google-cloud-scc-remediation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-cloud-scc-remediation, .gemini/skills/google-cloud-scc-remediation, .github/skills/google-cloud-scc-remediation and .opencode/skills/google-cloud-scc-remediation in your project.
Going by SKILL.md and its folder, Google Cloud Scc Remediation needs the command-line tools its instructions call (gcloud) and credentials named USER_MANAGED_SERVICE_ACCOUNT_KEY. Our summary lists: A credential in USER_MANAGED_SERVICE_ACCOUNT_KEY.
SKILL.md names 1 domain. As links in the text: docs.cloud.google.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Google Cloud Scc Remediation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Google Cloud Scc Remediation: Cloud Audit (briiirussell/cybersecurity-skills, 413 stars), Auditing Cloud With Cis Benchmarks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Performing GCP Security Assessment With Forseti (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,069 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on October 9, 2026.
Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.