Cloud Audit
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.
$ npx skills add google/skills --skill iam-helper-for-privileged-access-management -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install google/skills iam-helper-for-privileged-access-management --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/iam-helper-for-privileged-access-management .claude/skills/iam-helper-for-privileged-access-management && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "iam-helper-for-privileged-access-management" agent skill from https://github.com/google/skills/tree/main/skills/cloud/iam-helper-for-privileged-access-management into .claude/skills/iam-helper-for-privileged-access-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iam-helper-for-privileged-access-management", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/google/skills/tree/main/skills/cloud/iam-helper-for-privileged-access-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add google/skills --skill iam-helper-for-privileged-access-management -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install google/skills iam-helper-for-privileged-access-management --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cloud/iam-helper-for-privileged-access-management .agents/skills/iam-helper-for-privileged-access-management && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "iam-helper-for-privileged-access-management" agent skill from https://github.com/google/skills/tree/main/skills/cloud/iam-helper-for-privileged-access-management into .agents/skills/iam-helper-for-privileged-access-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iam-helper-for-privileged-access-management", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill iam-helper-for-privileged-access-management -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install google/skills iam-helper-for-privileged-access-management --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cloud/iam-helper-for-privileged-access-management .cursor/skills/iam-helper-for-privileged-access-management && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "iam-helper-for-privileged-access-management" agent skill from https://github.com/google/skills/tree/main/skills/cloud/iam-helper-for-privileged-access-management into .cursor/skills/iam-helper-for-privileged-access-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iam-helper-for-privileged-access-management", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/google/skills.git --path skills/cloud/iam-helper-for-privileged-access-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add google/skills --skill iam-helper-for-privileged-access-management -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install google/skills iam-helper-for-privileged-access-management --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cloud/iam-helper-for-privileged-access-management .gemini/skills/iam-helper-for-privileged-access-management && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "iam-helper-for-privileged-access-management" agent skill from https://github.com/google/skills/tree/main/skills/cloud/iam-helper-for-privileged-access-management into .gemini/skills/iam-helper-for-privileged-access-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iam-helper-for-privileged-access-management", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install google/skills iam-helper-for-privileged-access-managementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add google/skills --skill iam-helper-for-privileged-access-management -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cloud/iam-helper-for-privileged-access-management .github/skills/iam-helper-for-privileged-access-management && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "iam-helper-for-privileged-access-management" agent skill from https://github.com/google/skills/tree/main/skills/cloud/iam-helper-for-privileged-access-management into .github/skills/iam-helper-for-privileged-access-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iam-helper-for-privileged-access-management", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill iam-helper-for-privileged-access-management -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install google/skills iam-helper-for-privileged-access-management --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cloud/iam-helper-for-privileged-access-management .opencode/skills/iam-helper-for-privileged-access-management && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "iam-helper-for-privileged-access-management" agent skill from https://github.com/google/skills/tree/main/skills/cloud/iam-helper-for-privileged-access-management into .opencode/skills/iam-helper-for-privileged-access-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iam-helper-for-privileged-access-management", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
iam-helper-for-privileged-access-managementManages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.
This skill guides the agent through Privileged Access Manager (PAM) work in Google Cloud, where on-demand, time-bound, audited access replaces permanent IAM role bindings. Administrators define entitlements covering the resource (project, folder or organization), the IAM role, an optional condition, eligible requesters and approvers. Requesters then open grants against them, approvers act on those grants, and a grant ends automatically once its duration has passed.
The skill is organized in three modes: interactive access elevation, standalone entitlement create, read, update and delete, and an approver workflow. It follows a plan-validate-execute pattern with a confirmation strategy before changes, and covers approval workflow settings in the entitlement YAML manifest and the maximum request duration. Bundled files include an entitlement template, requester and approver references and shell scripts that list the entitlement hierarchy and search eligible entitlements. It is not meant for permanent IAM bindings, IAM permission error troubleshooting or general resource provisioning.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4b940dd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
gcloudbashFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
cloud.google.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Google Cloud PAM Helper loads about 3.2k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 1,188 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from google/skills at commit 4b940dd, republished under its Apache-2.0 licence (© google). 1,188 words, ~3,179 tokens.
.claude/skills/iam-helper-for-privileged-access-management/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.This skill provides step-by-step guidance for planning, validating, and executing Privileged Access Manager (PAM) entitlement CRUD operations, approval workflow configurations, access elevations, and grant approval/denial workflows.
Privileged Access Manager (PAM) replaces permanent or ambient IAM role assignments with on-demand, time-bound, and audited access elevations. Rather than appending permanent IAM policy bindings, PAM uses:
privilegedAccess)The privilegedAccess block in an entitlement defines the precise access scope that will be granted. An access scope comprises three essential components:
roleBindings.role) to be assigned.roleBindings.conditionExpression) restricting when or where the role applies.approvalWorkflow)When sensitive environments require human approval before temporary access is
activated, configure the approvalWorkflow block in the entitlement YAML
manifest (entitlement.yaml).
approvalWorkflow:
manualApprovals:
# Optional: requires approver to supply a justification string
requireApproverJustification: true
steps:
- approvalsNeeded: 1
approverEmailRecipients:
- approver@example.com
approvers:
- principals:
- user:db-lead@my-company.com # or group:sre-leads@my-company.comapprovalWorkflow whenever the user prompt
specifies that manual approval or an approver (user or group) is required.approvalWorkflow, the grant transitions to APPROVAL_AWAITED.
Requesters must await an Approver's decision (Mode 3).maxRequestDuration)maxRequestDuration defines the maximum single access elevation timeframe a requester
may ask for when placing a grant request.
maxRequestDuration according to the
user's specific request (e.g. 8 hours / 28800s, 1 hour / 3600s, 24 hours / 86400s).4 hours (14400s).maxRequestDuration as a string in seconds
in the entitlement YAML (e.g., "14400s", "28800s").Adhere strictly to these workflow guards:
For all modifying actions (Mode 1 Step 3, Mode 2 Create, Update, Delete, Mode 3 Approve, Deny):
gcloud command.When the user requests temporary access elevation as a Requester, load and
follow the detailed instructions in
references/requester.md.
Follow these steps for entitlement configurations.
roles/privilegedaccessmanager.admin: Required to create, update, and
delete entitlement configurations (Mode 1 Step 3 and Mode 2 CRUD).roles/iam.securityAdminroles/resourcemanager.folderAdminroles/resourcemanager.projectIamAdminroles/privilegedaccessmanager.viewer: Required to list and describe
entitlements across scopes.(Rule: For all Standalone Entitlement CRUD commands below, use the flag
matching where the entitlement is defined: pass --project=PROJECT_ID,
--folder=FOLDER_ID, or --organization=ORGANIZATION_ID).
ENTITLEMENT_ID exists:gcloud pam entitlements describe ENTITLEMENT_ID \
--location=global \
--project=PROJECT_IDENTITLEMENT_ID
already exists. Would you like to view its details or update it instead?
(View / Update / Exit)"compute-admin for roles/compute.admin). Note:roleBindings.conditionExpression for each role binding.roles/viewer, roles/editor, roles/owner) are NOT supported. Instead, use their v2 basic role equivalents (e.g., roles/basic.viewer, roles/basic.editor, roles/basic.owner). Ensure you select a valid predefined, custom, or v2 basic role.maxRequestDuration based on user specification (e.g. "28800s" for 8
hours, "3600s" for 1 hour). If unspecified by the user, default to
"14400s" (4 hours). If manual approval is specified by policy or requested
by the user, configure the approvalWorkflow block in entitlement.yaml.
Preserve requesterJustificationConfig: {unstructured: {}}.ENTITLEMENT_ID. Do
you approve this creation? (Yes/No)"gcloud pam entitlements create ENTITLEMENT_ID \
--location=global \
--entitlement-file=entitlement.yaml \
--project=PROJECT_IDRun these read operations autonomously:
List all entitlements at a single scope:
gcloud pam entitlements list \
--location=global \
--project=PROJECT_IDTo list all entitlements defined across the entire resource hierarchy (project, ancestor folders, and organization), use the hierarchy listing script:
bash scripts/list_entitlements_hierarchy.sh --project=PROJECT_ID(Or pass --folder=FOLDER_ID or --organization=ORGANIZATION_ID).
Describe target entitlement:
gcloud pam entitlements describe ENTITLEMENT_ID \
--location=global \
--project=PROJECT_IDRun the export command to generate the current config (which includes the etag):
gcloud pam entitlements export ENTITLEMENT_ID \
--location=global \
--project=PROJECT_ID > {scratch}/updated_entitlement.yamlIf missing, offer to run list or exit.
Edit the exported {scratch}/updated_entitlement.yaml file to apply the requested changes (e.g., updating
maxRequestDuration, approvalWorkflow, or eligibleUsers). Do not alter the etag.
Prompt: "You are about to update the PAM Entitlement ENTITLEMENT_ID. Do
you approve this update? (Yes/No)"
Execute:
gcloud pam entitlements update ENTITLEMENT_ID \
--location=global \
--entitlement-file={scratch}/updated_entitlement.yaml \
--project=PROJECT_IDVerify existence using describe. If missing, offer list/exit.
Safety Check: An entitlement cannot be deleted if there are open grants.
Before deleting, search for any ACTIVE or SCHEDULED grants:
gcloud pam grants list \
--entitlement=ENTITLEMENT_ID \
--location=global \
--project=PROJECT_ID \
--filter="state:(ACTIVE, SCHEDULED)"If any open grants are found, prompt the user for permission to revoke them: "There are active or scheduled grants on this entitlement. Do you authorize me to revoke them so the entitlement can be deleted? (Yes/No)"
If Yes, revoke them:
gcloud pam grants revoke GRANT_ID \
--entitlement=ENTITLEMENT_ID \
--location=global \
--project=PROJECT_ID \
--reason="Revoking to delete entitlement"Prompt: "You are about to permanently delete the PAM Entitlement
ENTITLEMENT_ID. Do you approve this deletion? (Yes/No)"
Execute:
gcloud pam entitlements delete ENTITLEMENT_ID \
--location=global \
--project=PROJECT_IDWhen an Approver needs to review, approve, or reject pending grant requests,
load and follow the detailed instructions in
references/approver.md.
For further information on working with Privileged Access Manager, refer to:
© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references, assets) in skills/cloud/iam-helper-for-privileged-access-management of google/skills.
Open the folder on GitHubat commit 4b940dd
Google Cloud PAM Helper next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Google Cloud PAM Helper this skillgoogle/skills | 21k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Cloud Auditbriiirussell/cybersecurity-skills | 413 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Container Securityhardw00t/ai-security-arsenal | 105 | — | ~2.8k | Automated safety check: Pass | None | |
| Auditing Cloud With Cis Benchmarksmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Zero Trust With Beyondcorpmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~732 | Automated safety check: Pass | Apache-2.0 |
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
hardw00t/ai-security-arsenal
Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…
mukul975/Anthropic-Cybersecurity-Skills
Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…
mukul975/Anthropic-Cybersecurity-Skills
Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…
mukul975/Anthropic-Cybersecurity-Skills
Configures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network…
mukul975/Anthropic-Cybersecurity-Skills
Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage…
google/skills
Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.
google/skills
Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.
google/skills
Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.
google/skills
Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.
google/skills
Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.
google/skills
Analyzes BigQuery slot use, query costs and execution bottlenecks from INFORMATION_SCHEMA to diagnose slow queries, slot contention and unpartitioned scans.
Works with
Categories
Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants. This skill guides the agent through Privileged Access Manager (PAM) work in Google Cloud, where on-demand, time-bound, audited access replaces permanent IAM role bindings. Administrators define entitlements covering the resource (project, folder or organization), the IAM role, an optional condition, eligible requesters and approvers.
Google Cloud PAM Helper fits situations like: requesting temporary elevated access through PAM; creating or updating a PAM entitlement for a project or folder; approving or denying pending PAM grants; finding which entitlements you are eligible to request.
Run `npx skills add google/skills --skill iam-helper-for-privileged-access-management -a claude-code`. Or copy the skill folder (skills/cloud/iam-helper-for-privileged-access-management in google/skills) into .claude/skills/iam-helper-for-privileged-access-management in your project. Claude Code loads it when a task matches its description.
Run `npx skills add google/skills --skill iam-helper-for-privileged-access-management -a codex`. Or copy the skill folder (skills/cloud/iam-helper-for-privileged-access-management in google/skills) into .agents/skills/iam-helper-for-privileged-access-management in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill iam-helper-for-privileged-access-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iam-helper-for-privileged-access-management, .gemini/skills/iam-helper-for-privileged-access-management, .github/skills/iam-helper-for-privileged-access-management and .opencode/skills/iam-helper-for-privileged-access-management in your project.
Going by SKILL.md and its folder, Google Cloud PAM Helper needs a shell for the scripts in its folder and the command-line tools its instructions call (gcloud and bash). Our summary lists: Access to Google Cloud Privileged Access Manager; Permissions that match your role as administrator, requester or approver.
SKILL.md names 1 domain. As links in the text: cloud.google.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Google Cloud PAM Helper is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Google Cloud PAM Helper: Cloud Audit (briiirussell/cybersecurity-skills, 413 stars), Container Security (hardw00t/ai-security-arsenal, 105 stars), Auditing Cloud With Cis Benchmarks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,097 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.
Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.