Official agent skill

Google Cloud Storage Bucket Architect

by google in google/skills

Creates Cloud Storage on Google Cloud (also known colloquially as GCS) buckets.

OfficialApache-2.0Auto-check passedBackend & APIs

Install Google Cloud Storage Bucket Architect

skills CLI
$ npx skills add google/skills --skill google-cloud-storage-bucket-architect -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills google-cloud-storage-bucket-architect --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/google-cloud-storage-bucket-architect .claude/skills/google-cloud-storage-bucket-architect && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
google-cloud-storage-bucket-architect
GitHub stars
21k
Token cost
~2.6k tokens
SKILL.md length
1,002 words
Files
20 (incl. references)
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Creates Cloud Storage on Google Cloud (also known colloquially as GCS) buckets.

  • Works in 3 steps: Start at Phase 1 (Preflight/Project… → Proceed to Phase 2 (Draft Bucket Create… → Proceed to Phase 3 (Output Based on User…
  • A user wants to create
  • SKILL.md covers Philosophy, Attribution, Phase Summary Table and Workflow Execution, plus 2 more sections
  • Calls gcloud

What it does

Google Cloud Storage Bucket Architect is an agent skill from google/skills, published by the product's own GitHub organization. Creates Cloud Storage on Google Cloud (also known colloquially as GCS) buckets. Analyzes the workload (sensitive data, media hosting, ingestion, web hosting, archiving, backup, logging, analytics, AI/ML, or general-purpose), validates project-level security settings, and designs a secure-by-default, cost-effective configuration (location, storage class, uniform bucket-level access, public access prevention, soft delete, lifecycle) before creating it. Use whenever a user wants to create, make, set up, provision…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including reference files (for example `references/archiving_compliance.md`, `references/backup_dr.md` and `references/gcloud.md`).

It sits in Backend & APIs, covering Infrastructure as code, File uploads and storage and REST APIs. It works with Google Cloud, Terraform, C++ and Java. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • A user wants to create
  • Spin up a bucket
  • Needs object storage for an app
  • Dataset — even a simple

Example prompts

  • “simple”
  • “default”
  • “Use the google-cloud-storage-bucket-architect skill to create Cloud Storage on Google Cloud (also known colloquially as GCS) buckets”
  • “/google-cloud-storage-bucket-architect”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Start at Phase 1 (Preflight/Project Checks): Assess project-level
  2. Proceed to Phase 2 (Draft Bucket Create Plan): Identify the use case and
  3. Proceed to Phase 3 (Output Based on User Intent): Generate the final

What it can do on your machine

Read from SKILL.md and the folder at commit 5120a76. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Cloud Storage Bucket Architect loads about 2.6k tokens when it runs, and up to ~63k if it reads all its reference files. Until then it costs about 257 tokens; SKILL.md has 1,002 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~257
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~63k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 5120a76, republished under its Apache-2.0 licence (© google). 1,002 words, ~2,607 tokens.

Download SKILL.mdSave it as .claude/skills/google-cloud-storage-bucket-architect/SKILL.md (or your agent's skills folder). This skill also uses 19 other files; get the full folder from GitHub.
name
google-cloud-storage-bucket-architect
description
Creates Cloud Storage on Google Cloud (also known colloquially as GCS) buckets. Analyzes the workload (sensitive data, media hosting, ingestion, web hosting, archiving, backup, logging, analytics, AI/ML, or general-purpose), validates project-level security settings, and designs a secure-by-default, cost-effective configuration (location, storage class, uniform bucket-level access, public access prevention, soft delete, lifecycle) before creating it. Use whenever a user wants to create, make, set up, provision, or spin up a bucket, or needs object storage for an app, service, pipeline, or dataset — even a "simple" or "default" bucket, or when bucket creation is one step in a larger workflow. Outputs or executes the creation via gcloud, the JSON/REST API, Terraform, or SDK client libraries (C++, Java, Python, Go). Don't use for anything other than creating new buckets — for uploads, downloads, access changes, or reconfiguring existing buckets, use google-cloud-storage-basics.
license
Apache-2.0
metadata.version
1.0.2
metadata.publisher
google
metadata.tags
gcs, storage, architect, bucket-creation
metadata.category
Storage
metadata.support_tier
primary

Cloud Storage Bucket Architect

You are a Use-Case Driven Cloud Storage Bucket Architect agent on Google Cloud. Your job is to help users design and create Cloud Storage buckets that are secure, cost-effective, and optimized for their specific use cases. You validate project-level settings to ensure baseline security and provide the configuration in the user's preferred format, or execute the creation if authorized.

[!IMPORTANT]

You MUST ground your recommendations in the specific use case of the user. Always prefer secure-by-default configurations (UBLA enabled, restricted CSEK, soft-delete enabled) unless the user explicitly requests otherwise.

[!CAUTION]

CRITICAL: Never execute mutating commands, including bucket creation/update/deletion (e.g., gcloud, REST API calls), without first presenting the exact configuration/command and obtaining explicit confirmation from the user.

Philosophy

Creating Cloud Storage buckets involves many architectural choices (storage class, location, security settings, lifecycle policies). Instead of just creating a default bucket, you analyze the user's workload requirements and apply industry best practices and Google's internal expertise to draft a tailored architecture plan. You also check project-level constraints to warn the user about potential security gaps or policy violations.

[!NOTE]

For help with location-related questions about Cloud Storage, refer to the public documentation for Cloud Storage: Storage Locations

Attribution

Tag every Cloud Storage command you run or provide to the user while using this skill, so usage can be attributed. The tag identifies only the skill and its version; it carries no user data. Do not use attribution for SDK or Terraform snippets.

  • gcloud: Prefix every gcloud invocation you execute or output (including project checks, bucket name checks, creation/update commands, and any auxiliary gcloud commands in recommendations) with the metrics environment variables. The only exception is gcloud auth print-access-token when used inside a REST curl command, because REST already records attribution through the User-Agent header. Set the prefix inline on each gcloud command; shell state may not persist between commands. Use this append form verbatim. It keeps any attribution the host environment already set (for example an IDE plugin tagging agent activity through the same variable) and adds the skill tag after it, so neither value clobbers the other:

    bash
    CLOUDSDK_METRICS_ENVIRONMENT="${CLOUDSDK_METRICS_ENVIRONMENT:+$CLOUDSDK_METRICS_ENVIRONMENT }gcs-skills gcs-skills/1.0 (skill:google-cloud-storage-bucket-architect)" \
    gcloud <command> [flags]

    Do not use gcloud config set for this: it would persist beyond the current task and mislabel unrelated usage.

  • REST (cURL): Set the User-Agent header verbatim:

    User-Agent: gcs-skills/1.0 (skill:google-cloud-storage-bucket-architect)

Phase Summary Table

PhaseInputsOutputsReference
1. Preflight/Project ChecksProject IDDefault project security checksreferences/phase_project_checks.md
2. Draft Bucket Create PlanUser use case, requirementsRecommended bucket configuration plan with bucket name availability statusreferences/phase_draft_plan.md
3. Output Based on User IntentPlan, preferred formatCommand/Snippet for bucket creationreferences/phase_output.md

Workflow Execution

[!IMPORTANT]

Do not skip phases: You must complete Phase N before proceeding to Phase N+1. Decisions should be made based on relevant findings grounded in the reference files for each phase. Do not optimize or deviate. Even if the user requests ONLY the final code/commands, or asks for them "immediately", you MUST still perform and display the Phase 1 assessment and Phase 2 plan in your response.

When invoked, the agent MUST follow this exact sequence:

  1. Start at Phase 1 (Preflight/Project Checks): Assess project-level settings by following references/phase_project_checks.md and follow its output format before proceeding.

  2. Proceed to Phase 2 (Draft Bucket Create Plan): Identify the use case and draft the bucket's configuration by following references/phase_draft_plan.md. This phase includes running the read-only, attributed bucket name availability check described in the reference; a taken name must be resolved before the plan is presented. As described in the reference, stop and wait for confirmation from the user that the plan looks good before proceeding, unless the user has already explicitly requested the final commands or code snippet in their initial prompt.

  3. Proceed to Phase 3 (Output Based on User Intent): Generate the final output by following references/phase_output.md but DO NOT execute any commands.

    As described in the reference, the preferred output format should be clear (gcloud, API (REST), Terraform, or SDK).

    • For gcloud and REST, offer to execute the creation and only proceed after explicit confirmation.
    • For Terraform and SDK, display the snippet for the user to integrate.
Show full SKILL.md (315 more words)Show less

Error Handling

ProblemCauseFix
Execution failure during creationNetwork issue, permission error during API callReport the error details to the user and suggest manual execution with the generated command/snippet.
Creation fails with 409 or "already exists" errorThe bucket name became taken after the check, or the check was not verifiedPropose a different name, re-run the availability check, and regenerate the output.

References

Phases
Bucket Use Cases
Provisioning & Output Formats
SDK Language-Specific Guides
  • C++ SDK Guide: Code examples and patterns for the Cloud Storage C++ client library.
  • Go SDK Guide: Code examples and patterns for the Cloud Storage Go client library.
  • Java SDK Guide: Code examples and patterns for the Cloud Storage Java client library.
  • Python SDK Guide: Code examples and patterns for the Cloud Storage Python client library.

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 19 other files (references) in skills/cloud/google-cloud-storage-bucket-architect of google/skills.

  • SKILL.md
  • references/archiving_compliance.md
  • references/backup_dr.md
  • references/gcloud.md
  • references/log_storage.md
  • references/media_hosting.md
  • references/phase_draft_plan.md
  • references/phase_output.md
  • references/phase_project_checks.md
  • references/rest.md
  • references/sdk.md
  • references/sdk_cpp.md
  • references/sdk_go.md
  • references/sdk_java.md
  • references/sdk_python.md
  • references/sensitive_data.md
  • references/static_website.md
  • references/storage_for_ai.md
  • references/terraform.md
  • references/ugc_ingestion.md

Open the folder on GitHubat commit 5120a76

Compare with similar skills

Google Cloud Storage Bucket Architect next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Cloud Storage Bucket Architect compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Cloud Storage Bucket Architect this skillgoogle/skills21k—~2.6kAutomated safety check: PassApache-2.0
Neo4j Aura Provisioning Skillneo4j-contrib/neo4j-skills114—~3.7kAutomated safety check: NotesMIT
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Kibana Connectorsaspectrr/deer405—~2kAutomated safety check: PassMIT
Msk Operationsaws/tools-for-devops-agent102—~6.6kAutomated safety check: PassApache-2.0
Datadog Data Source GeneratorDataDog/terraform-provider-datadog468—~2.7kAutomated safety check: PassMPL-2.0

Similar skills

  • Neo4j Aura Provisioning Skill

    neo4j-contrib/neo4j-skills

    Provisions and manages Neo4j Aura instances via CLI (aura-cli v1.7+) or REST API.

    114 GitHub stars~3.7k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Kibana Connectors

    aspectrr/deer

    Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform.

    405 GitHub stars~2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Msk Operations

    aws/tools-for-devops-agent

    Official

    Amazon MSK Provisioned operations, troubleshooting, and health assessment for Standard and Express brokers.

    102 GitHub stars~6.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Datadog Data Source Generator

    DataDog/terraform-provider-datadog

    Official

    Generates a Datadog Terraform provider data source from an OpenAPI operation with tfgen and opens a review-ready GitHub PR with a risk scan and testing guide.

    468 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Rsid SDK

    realsenseai/RealSenseID

    RealSenseID face authentication SDK reference. An agent skill from realsenseai/RealSenseID.

    122 GitHub stars~4.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from google/skills

All 147 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated today
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated today
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Questions about Google Cloud Storage Bucket Architect

What does Google Cloud Storage Bucket Architect do?

Creates Cloud Storage on Google Cloud (also known colloquially as GCS) buckets. Google Cloud Storage Bucket Architect is an agent skill from google/skills, published by the product's own GitHub organization. Creates Cloud Storage on Google Cloud (also known colloquially as GCS) buckets.

When should I use Google Cloud Storage Bucket Architect?

Google Cloud Storage Bucket Architect fits situations like: A user wants to create; spin up a bucket; needs object storage for an app; dataset — even a simple.

How do I install Google Cloud Storage Bucket Architect in Claude Code?

Run `npx skills add google/skills --skill google-cloud-storage-bucket-architect -a claude-code`. Or copy the skill folder (skills/cloud/google-cloud-storage-bucket-architect in google/skills) into .claude/skills/google-cloud-storage-bucket-architect in your project. Claude Code loads it when a task matches its description.

How do I install Google Cloud Storage Bucket Architect in Codex?

Run `npx skills add google/skills --skill google-cloud-storage-bucket-architect -a codex`. Or copy the skill folder (skills/cloud/google-cloud-storage-bucket-architect in google/skills) into .agents/skills/google-cloud-storage-bucket-architect in your project. Codex loads it when a task matches its description.

Can I use Google Cloud Storage Bucket Architect in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill google-cloud-storage-bucket-architect -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-cloud-storage-bucket-architect, .gemini/skills/google-cloud-storage-bucket-architect, .github/skills/google-cloud-storage-bucket-architect and .opencode/skills/google-cloud-storage-bucket-architect in your project.

What does Google Cloud Storage Bucket Architect need to run?

Going by SKILL.md and its folder, Google Cloud Storage Bucket Architect needs the command-line tools its instructions call (gcloud). Our summary lists: Python 3.

Does Google Cloud Storage Bucket Architect access the network?

SKILL.md names 1 domain. As links in the text: cloud.google.com. This is read from the text; nothing was executed.

Is Google Cloud Storage Bucket Architect safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Google Cloud Storage Bucket Architect use?

Google Cloud Storage Bucket Architect is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Cloud Storage Bucket Architect use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 60k tokens, read only when the agent opens those files.

What are the alternatives to Google Cloud Storage Bucket Architect?

Skills that share tags, products or a category with Google Cloud Storage Bucket Architect: Neo4j Aura Provisioning Skill (neo4j-contrib/neo4j-skills, 114 stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), Kibana Connectors (aspectrr/deer, 405 stars) and Msk Operations (aws/tools-for-devops-agent, 102 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Cloud Storage Bucket Architect?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,069 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on October 9, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.