Official agent skill

Google Cloud Waf Security

by google in google/skills

Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF).

OfficialApache-2.0Auto-check passedSecurity

Install Google Cloud Waf Security

skills CLI
$ npx skills add google/skills --skill google-cloud-waf-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills google-cloud-waf-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/google-cloud-waf-security .claude/skills/google-cloud-waf-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
google-cloud-waf-security
GitHub stars
21k
Used in
1 other repo
Token cost
~4.2k tokens
SKILL.md length
2,061 words
Files
1
Skills in repo
145
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF).

  • Works in 5 steps: Understand the context: Ask targeted… → Analyze and identify gaps: Evaluate the… → Formulate recommendations: Provide… → …
  • Evaluate workloads
  • SKILL.md covers Overview, Workflow, Core principles and Relevant Google Cloud products, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Google Cloud Waf Security is an agent skill from google/skills, published by the product's own GitHub organization. Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate workloads, identify security requirements, and provide actionable recommendations for IAM, network security, data protection, and operational security.

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cloud architecture, Network security and Privacy and GDPR. It works with Google Cloud. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Evaluate workloads
  • Identify security requirements
  • Provide actionable recommendations for IAM
  • Network security

Example prompts

  • “Use the google-cloud-waf-security skill to generate security-focused guidance for Google Cloud workloads based on the design principles and…”
  • “/google-cloud-waf-security”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Understand the context: Ask targeted questions from the **Workload
  2. Analyze and identify gaps: Evaluate the workload against the **Core
  3. Formulate recommendations: Provide actionable, prioritized guidance
  4. Explain the recommendations: Align all recommendations with the
  5. Iterate and refine: Help the user adapt the recommendations to their

What it can do on your machine

Read from SKILL.md and the folder at commit 8a1ac05. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Cloud Waf Security loads about 4.2k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 2,061 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 8a1ac05, republished under its Apache-2.0 licence (© google). 2,061 words, ~4,190 tokens.

Download SKILL.mdSave it as .claude/skills/google-cloud-waf-security/SKILL.md (or your agent's skills folder).
name
google-cloud-waf-security
description
Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate workloads, identify security requirements, and provide actionable recommendations for IAM, network security, data protection, and operational security.
metadata.version
1.0.0
metadata.category
WellArchitectedFramework

Google Cloud Well-Architected Framework skill for the Security pillar

Overview

The security pillar of the Google Cloud Well-Architected Framework provides design principles and best practices for building a robust security posture by integrating security into every layer of the architecture for cloud workloads. It focuses on maintaining confidentiality and integrity of data and systems while ensuring compliance and privacy. It provides a structured approach to risk management, threat defense, and identity control, enabling you to operate cloud workloads securely and at scale.

Workflow

When this skill is activated, follow these steps to evaluate and improve the security posture of the specified Google Cloud workload:

  1. Understand the context: Ask targeted questions from the Workload assessment questions list to gather information about the user's current architecture, security requirements, and constraints.
  2. Analyze and identify gaps: Evaluate the workload against the Core principles and the Validation checklist to identify security vulnerabilities, missing controls, or deviations from best practices.
  3. Formulate recommendations: Provide actionable, prioritized guidance based on the Google Cloud Well-Architected Framework. Recommend specific products from Relevant Google Cloud products to address the identified gaps.
  4. Explain the recommendations: Align all recommendations with the appropriate Core principles and state the benefits that each recommendation provides.
  5. Iterate and refine: Help the user adapt the recommendations to their specific requirements and constraints.

Core principles

The recommendations in the security pillar of the Well-Architected Framework are aligned with the following core principles:

Relevant Google Cloud products

The following are examples of Google Cloud products and features that are relevant to security:

  • Identity and access management

    • Cloud Identity: Manage user lifecycles, authentication, and identity federation.
    • Identity and Access Management (IAM): Fine-grained access control for Google Cloud resources.
    • Identity-Aware Proxy (IAP): Secure access to applications without a VPN.
    • Chrome Enterprise Premium: Endpoint security and context-aware access.
    • IAM Recommender: Provide policy intelligence.
  • Network security

    • Google Cloud Armor: DDoS protection and Web Application Firewall (WAF).
    • VPC Service Controls: Define security perimeters to prevent data exfiltration.
    • Cloud Next-Generation Firewall (NGFW): Advanced threat protection for network traffic.
    • Shared VPC: Centralized network management across projects.
    • Cloud Interconnect and IPsec VPN: Secure, private connectivity. -Private Service Connect: Provide private access to managed services
  • Data security

    • Cloud Key Management Service (KMS): Manage encryption keys.
    • Sensitive Data Protection (formerly Cloud DLP): Discover and redact sensitive data.
    • Confidential Computing: Encrypt data in use (memory).
  • Security operations (SecOps)

    • Google SecOps (Chronicle): Threat detection and security analytics.
    • Security Command Center (SCC): Centralized vulnerability and threat management.
    • Cloud Logging and Cloud Monitoring: Visibility into system activity.
    • BigQuery: Storing exported logs for analysis.
  • Automation and supply chain

    • Cloud Build: Secure CI/CD pipelines.
    • Artifact Analysis: Vulnerability scanning for container images.
    • Binary Authorization: Deploy-time policy enforcement.
    • Assured open source software: Use secured OSS packages.

Workload assessment questions

Ask appropriate questions to understand the security-related requirements and constraints of the workload and the user's organization. Choose questions from the following list:

  • Security by design:

    • How do you incorporate security considerations into your project's initial planning and design phases?
    • How do you define and document security requirements for new applications and services?
    • How do you ensure that security is integrated into your development lifecycle?
    • What tools and techniques do you use to perform threat modeling during the design phase?
    • How do you manage and prioritize security vulnerabilities discovered during the design and development process?
    • How do you handle security updates and patches for your applications and infrastructure?
    • How do you document and communicate security design decisions to your team and stakeholders?
    • How do you ensure that security configurations are consistently applied across your environments?
    • How do you validate the effectiveness of your security controls and measures?
    • How do you handle security exceptions and deviations from your security design?
  • Zero trust:

    • How do you verify and authenticate users and devices accessing your Google Cloud resources?
    • How do you implement the principle of least privilege for access control?
    • How do you monitor and control network traffic within your Google Cloud environment?
    • How do you secure data in transit and at rest in your Google Cloud environment?
    • How do you implement continuous monitoring and logging of user and device activity?
    • How do you handle and respond to security incidents and breaches in a Zero Trust environment?
    • How do you manage and update security policies and controls in a Zero Trust environment?
    • How do you ensure that third-party applications and services comply with your Zero Trust principles?
    • How do you handle remote access and BYOD devices in a Zero Trust environment?
    • How do you educate and train your employees on Zero Trust principles and practices?
  • Shift-left security:

    • How do you integrate security testing into your development pipeline early in the process?
    • What types of security testing do you perform during the development phase?
    • How do you provide developers with feedback on security vulnerabilities and best practices?
    • How do you empower developers to take ownership of security in their code?
    • How do you ensure that security requirements are clearly defined and communicated to developers?
    • How do you measure the effectiveness of your Shift Left security initiatives?
    • How do you handle security dependencies and third-party libraries in your code?
    • How do you manage and update security configurations in your development environment?
    • How do you handle security exceptions and deviations from your security policies in development?
    • How do you promote a culture of security awareness and responsibility among developers?
  • Preemptive cyber defense:

    • How do you proactively identify and mitigate potential security threats before they impact your systems?
    • What tools and techniques do you use for continuous security monitoring and analysis?
    • How do you respond to and remediate security alerts and incidents?
    • How do you simulate and test your incident response plans?
    • How do you stay up-to-date with the latest security threats and vulnerabilities?
    • How do you handle and mitigate DDoS attacks against your applications and services?
    • How do you protect your sensitive data from insider threats?
    • How do you ensure that your security controls are effective against advanced persistent threats (APTs)?
    • How do you handle security vulnerabilities in your supply chain?
    • How do you adapt your security posture to evolving threats and technologies?
  • Security of AI workloads:

    • How do you ensure the security of your AI models and data?
    • How do you address potential biases and ethical concerns in your AI models?
    • How do you protect your AI models from adversarial attacks and data poisoning?
    • How do you ensure the privacy of data used in your AI models?
    • How do you explain and interpret the decisions made by your AI models?
    • How do you manage and control access to your AI models and data?
    • How do you ensure compliance with regulations and standards related to AI and ML?
    • How do you monitor and detect anomalies in the behavior of your AI models?
    • How do you handle and respond to security incidents involving your AI models?
    • How do you educate and train your employees on the secure and responsible use of AI and ML?
  • AI for security:

    • How do you leverage AI and ML to enhance your security posture?
    • What types of AI models do you use for security purposes?
    • How do you train and validate your AI models for security applications?
    • How do you ensure the accuracy and reliability of AI-based security systems?
    • How do you handle false positives and false negatives from AI-based security systems?
    • How do you integrate AI-based security systems with your existing security infrastructure?
    • How do you manage and update your AI models for security applications?
    • How do you explain and interpret the decisions made by your AI models for security applications?
    • How do you ensure the ethical and responsible use of AI and ML for security purposes?
    • How do you measure the effectiveness of AI and ML in improving your security posture?
  • Regulatory compliance and privacy:

    • What regulatory compliance frameworks and privacy standards do you need to adhere to?
    • How do you assess and manage compliance risks in your Google Cloud environment?
    • How do you ensure the privacy of sensitive data stored and processed in Google Cloud?
    • How do you handle data subject requests (DSRs) related to privacy regulations?
    • How do you document and track compliance activities and evidence?
    • How do you ensure that third-party vendors and partners comply with your regulatory and privacy requirements?
    • How do you handle data breaches and security incidents related to compliance regulations?
    • How do you stay up-to-date with changes in regulatory compliance and privacy standards?
    • How do you educate and train your employees on regulatory compliance and privacy requirements?
    • How do you demonstrate and prove compliance to auditors and regulators?
Show full SKILL.md (227 more words)Show less

Validation checklist

Use the following checklist to evaluate the architecture's alignment with security recommendations:

  • Security by design:

    • Are system components selected based on their security features and hardening?
    • Is defense-in-depth implemented at the network, host, and application layers?
    • Are safe libraries and application frameworks used to prevent common vulnerabilities?
    • Is a risk assessment performed using industry standards?
  • Zero trust:

    • Is Cloud Identity used as a centralized identity provider for managing user lifecycles and federation?
    • Is access control enforced based on user identity and context (device, location)?
    • Are private connectivity methods (Cloud Interconnect, VPN) used for internal traffic?
    • Are default networks disabled in all projects?
    • Are VPC Service Controls perimeters established around sensitive data?
  • Shift-left security:

    • Is infrastructure provisioned using Infrastructure as Code (e.g., Terraform)?
    • Are automated security scans integrated into the CI/CD pipeline?
    • Is there a process for scanning and patching vulnerabilities in dependencies?
    • Is Binary Authorization used to ensure only trusted images are deployed?
  • Preemptive cyber defense:

    • Is threat intelligence integrated into security operations?
    • Is security logging enabled and centralized for all critical resources?
    • Are automated responses configured for common security threats?
    • Are defenses validated through periodic testing or red-teaming?
  • AI security and governance:

    • Are AI pipelines secured against tampering and data poisoning?
    • Is differential privacy or data masking used for training data where appropriate?
    • Are Vertex Explainable AI and fairness indicators used for model governance?

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cloud/google-cloud-waf-security of google/skills.

Open the folder on GitHubat commit 8a1ac05

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in google/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Google Cloud Waf Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Cloud Waf Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Cloud Waf Security this skillgoogle/skills21k1 repos~4.2kAutomated safety check: PassApache-2.0
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Performing Ssl Tls Inspection Configurationmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: NotesApache-2.0
Cloud Cost Optimizationwshobson/agents40k13 repos~1.7kAutomated safety check: PassMIT
Dangling DNS Finderanirudhbiyani/findmytakeover180—~1.8kAutomated safety check: PassGPL-3.0
Terraform Module Librarywshobson/agents40k10 repos~1.3kAutomated safety check: PassMIT

Similar skills

  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Ssl Tls Inspection Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Configure SSL/TLS break-and-inspect on next-generation firewalls and forward proxies to decrypt, inspect, and re-encrypt HTTPS traffic for malware and exfiltration detection, including deploying…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 13 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Dangling DNS Finder

    anirudhbiyani/findmytakeover

    Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.

    180 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Build reusable, tested Terraform modules for AWS, Azure, GCP and OCI, with a standard file layout, an AWS VPC example, versioning rules and Terratest checks.

    40k GitHub starsUsed in 10 repos~1.3k tokens
    DevOps & CloudAuto-check passed
  • Creates DrawIO XML diagrams of Google Cloud architectures from text or images, and analyzes existing .drawio files to list their GCP components.

    1.8k GitHub stars~3.7k tokensUpdated 20 days ago
    DevOps & CloudAuto-check passed

More from google/skills

All 145 skills in this repo
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5.1k tokensUpdated today
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated today
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Official

    Analyzes BigQuery slot use, query costs and execution bottlenecks from INFORMATION_SCHEMA to diagnose slow queries, slot contention and unpartitioned scans.

    21k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Works with

Questions about Google Cloud Waf Security

What does Google Cloud Waf Security do?

Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Google Cloud Waf Security is an agent skill from google/skills, published by the product's own GitHub organization. Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF).

When should I use Google Cloud Waf Security?

Google Cloud Waf Security fits situations like: evaluate workloads; identify security requirements; provide actionable recommendations for IAM; network security.

How do I install Google Cloud Waf Security in Claude Code?

Run `npx skills add google/skills --skill google-cloud-waf-security -a claude-code`. Or copy the skill folder (skills/cloud/google-cloud-waf-security in google/skills) into .claude/skills/google-cloud-waf-security in your project. Claude Code loads it when a task matches its description.

How do I install Google Cloud Waf Security in Codex?

Run `npx skills add google/skills --skill google-cloud-waf-security -a codex`. Or copy the skill folder (skills/cloud/google-cloud-waf-security in google/skills) into .agents/skills/google-cloud-waf-security in your project. Codex loads it when a task matches its description.

Can I use Google Cloud Waf Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill google-cloud-waf-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-cloud-waf-security, .gemini/skills/google-cloud-waf-security, .github/skills/google-cloud-waf-security and .opencode/skills/google-cloud-waf-security in your project.

What does Google Cloud Waf Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Google Cloud Waf Security is instructions for the agent only.

Does Google Cloud Waf Security access the network?

SKILL.md names 1 domain. As links in the text: docs.cloud.google.com. This is read from the text; nothing was executed.

Is Google Cloud Waf Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Google Cloud Waf Security use?

Google Cloud Waf Security is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Cloud Waf Security use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Google Cloud Waf Security?

Skills that share tags, products or a category with Google Cloud Waf Security: Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Ssl Tls Inspection Configuration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Cloud Cost Optimization (wshobson/agents, 40k stars) and Dangling DNS Finder (anirudhbiyani/findmytakeover, 180 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Cloud Waf Security?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 20,994 GitHub stars. The repository holds 145 skills in this directory. The repository was last updated on October 6, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.