Official agent skill

Iam Helper For Troubleshooting

by google in google/skills

Diagnoses, remediates, and manages Identity and Access Management (IAM) access issues on Google Cloud.

OfficialApache-2.0Auto-check passedBackend & APIs

Install Iam Helper For Troubleshooting

skills CLI
$ npx skills add google/skills --skill iam-helper-for-troubleshooting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills iam-helper-for-troubleshooting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/iam-helper-for-troubleshooting .claude/skills/iam-helper-for-troubleshooting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iam-helper-for-troubleshooting
GitHub stars
21k
Token cost
~1.3k tokens
SKILL.md length
521 words
Files
7 (incl. scripts, references)
Skills in repo
150
Repo updated
First seen
Licence
Apache-2.0

At a glance

Diagnoses, remediates, and manages Identity and Access Management (IAM) access issues on Google Cloud.

  • Works in 3 steps: Follow Mode 1 (Requester Flow) if → Follow Mode 2 (Resolver Flow) if → Default Behavior
  • Tasks that involve GraphQL
  • SKILL.md covers Mode Selection Guide, Safety Guardrails & Approval… and Supporting Links & Resources
  • Runs Python scripts from its folder

What it does

Iam Helper For Troubleshooting is an agent skill from google/skills, published by the product's own GitHub organization. Diagnoses, remediates, and manages Identity and Access Management (IAM) access issues on Google Cloud. Supports two distinct operational modes: (1) Requester Flow for developers encountering access denials (capturing error context, self-service PAM JIT activations, elevated developer self-remediation, or logging structured tickets), and (2) Resolver Flow for privileged administrators (authoritative Policy Troubleshooter analysis, deny policy exemptions, least-privilege role discovery, and PAM/IAM provisioning).

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/guardrails.md`, `references/mcp-usage.md` and `references/requester.md`).

It sits in Backend & APIs, covering GraphQL and Help center and FAQ content. It works with Google Cloud. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve GraphQL
  • Tasks that involve Help center and FAQ content

Example prompts

  • “/iam-helper-for-troubleshooting”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Follow Mode 1 (Requester Flow) if
  2. Follow Mode 2 (Resolver Flow) if
  3. Default Behavior

What it can do on your machine

Read from SKILL.md and the folder at commit 4b940dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.cloud.google.com
    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Iam Helper For Troubleshooting loads about 1.3k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 137 tokens; SKILL.md has 521 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~137
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from google/skills at commit 4b940dd, republished under its Apache-2.0 licence (© google). 521 words, ~1,347 tokens.

Download SKILL.mdSave it as .claude/skills/iam-helper-for-troubleshooting/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
iam-helper-for-troubleshooting
description
Diagnoses, remediates, and manages Identity and Access Management (IAM) access issues on Google Cloud. Supports two distinct operational modes: (1) Requester Flow for developers encountering access denials (capturing error context, self-service PAM JIT activations, elevated developer self-remediation, or logging structured tickets), and (2) Resolver Flow for privileged administrators (authoritative Policy Troubleshooter analysis, deny policy exemptions, least-privilege role discovery, and PAM/IAM provisioning).
metadata.version
1.0.1
metadata.category
Security

IAM Access Troubleshooter & Remediation Orchestrator on Google Cloud

You are an expert Google Cloud Security and IAM assistant. You diagnose access denial errors and orchestrate the appropriate resolution path depending on the caller's persona and privileges.

Mode Selection Guide

Identify the caller's context to select the appropriate operational mode:

ModeTarget Persona / ContextPrimary ActionsReference Guide
Mode 1: Requester FlowDeveloper, Service Account, or requester blocked by an access denialCaptures Error ID, runs self-diagnosis, self-activates PAM JIT grants, self-remediates (if elevated), or logs structured tickets.references/requester.md
Mode 2: Resolver FlowSecurity Admin, Cloud IAM Admin, or agent handling an escalated access ticketAuthoritatively evaluates allow/deny policies, creates deny exemptions, discovers minimal roles, and provisions PAM/IAM access.references/resolver.md
Routing Rules
  1. Follow Mode 1 (Requester Flow) if:

    • You are executing an end-user development task, encounter a 403 / Error ID, and need to perform self-service PAM activation or produce an internal escalation ticket for an administrator.
    • 📖 Reference Guide: Read and follow references/requester.md for detailed execution steps.
  2. Follow Mode 2 (Resolver Flow) if:

    • The user asks you to troubleshoot access, investigate a missing permission, find candidate roles, or resolve an access denial on a Google Cloud resource.
    • 📖 Reference Guide: Read and follow references/resolver.md for detailed execution steps.
  3. Default Behavior:

    • Default to Mode 2 (Resolver Flow) for troubleshooting access denials and missing permissions across Google Cloud resources. Read and follow references/resolver.md for detailed execution steps.

Show full SKILL.md (286 more words)Show less

Safety Guardrails & Approval Policy

All access modifications and role provisioning operations are governed by the approval tiers and safety boundaries defined in references/guardrails.md:

  • Human-in-the-Loop (HITL): All role provisioning operations (read-only, mutating, and administrative roles) require explicit human approval before execution. High-risk administrative roles require an explicit high-risk warning.
  • Access Already Granted Rule: When policy evaluation determines accessState: GRANTED (or access is already granted via inherited allow policies), inform the user that the IAM permission configuration is correct and terminate the troubleshooting flow immediately. Do NOT search for roles, suggest role queries, or propose role bindings.
  • Role Discovery Gating: Always ask the user for confirmation before executing queries to list or search candidate roles. Only list roles after receiving user confirmation in a subsequent turn.
  • Unknown Access State / Group Expansion Rule: When policy evaluation returns accessState: UNKNOWN or UNKNOWN_INFO (due to missing permissions to expand group memberships like roles/browser), explain that access is unknown due to missing group expansion permissions (roles/browser), and terminate the troubleshooting flow immediately. Do NOT run secondary queries or probe alternative policies.
  • Anti-Loop & Permission Denied: If troubleshooting commands encounter PERMISSION_DENIED on the caller's identity (HTTP 403), stop immediately without querying roles or running alternative commands. If the user requested replying with "Permission Denied" or the role name, reply immediately with "Permission Denied".

[!NOTE] Organizations cloning this skill should customize references/guardrails.md to define their specific approval tiers and policies.


© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/cloud/iam-helper-for-troubleshooting of google/skills.

  • SKILL.md
  • references/guardrails.md
  • references/mcp-usage.md
  • references/requester.md
  • references/resolver.md
  • scripts/least_privileged_role.py
  • scripts/troubleshooting_error_id.py

Open the folder on GitHubat commit 4b940dd

Compare with similar skills

Iam Helper For Troubleshooting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iam Helper For Troubleshooting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iam Helper For Troubleshooting this skillgoogle/skills21k—~1.3kAutomated safety check: PassApache-2.0
Apollo Deploy Integrationjeremylongshore/tons-of-skills-marketplace2.8k—~1.8kAutomated safety check: PassMIT
Debug DashboardBlackBeltTechnology/pi-agent-dashboard316—~1.6kAutomated safety check: PassMIT
Apollo OutreachOpenClaudia/openclaudia-skills713—~1.4kAutomated safety check: NotesMIT
Certmanager Dns01 Gke Private Clusterdivinevideo/divine-mobile266—~1.8kAutomated safety check: PassMPL-2.0
Shopifyasgeirtj/system_prompts_leaks69k—~2kAutomated safety check: PassCC0-1.0

Similar skills

  • Apollo Deploy Integration

    jeremylongshore/tons-of-skills-marketplace

    Deploy Apollo.io integrations to production. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Debug Dashboard

    BlackBeltTechnology/pi-agent-dashboard

    Diagnose problems in the running pi-agent-dashboard system: server.log, /api/health, bridge WebSocket connectivity, vitest triage, known-issue FAQ entries.

    316 GitHub stars~1.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Apollo Outreach

    OpenClaudia/openclaudia-skills

    Research and enrich B2B leads using the Apollo.io API. An agent skill from OpenClaudia/openclaudia-skills.

    713 GitHub stars~1.4k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Certmanager Dns01 Gke Private Cluster

    divinevideo/divine-mobile

    Fix cert-manager DNS01 ACME challenges stuck in "pending" state with "DNS record not yet propagated" inside GKE private clusters, even when TXT records exist in Cloudflare DNS.

    266 GitHub stars~1.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Shopify

    asgeirtj/system_prompts_leaks

    Set up and operate a Shopify store with Shopify's official MCP server (the installed shopify command, NOT the npm Shopify CLI).

    69k GitHub stars~2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Apollo Lead Finder

    gooseworks-ai/goose-skills

    Two-phase Apollo.io prospecting: free People Search to discover ICP-matching leads, then selective enrichment to reveal emails/phones (credits per contact).

    1.2k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check: notes

More from google/skills

All 150 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated yesterday
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated yesterday
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Iam Helper For Troubleshooting

What does Iam Helper For Troubleshooting do?

Diagnoses, remediates, and manages Identity and Access Management (IAM) access issues on Google Cloud. Iam Helper For Troubleshooting is an agent skill from google/skills, published by the product's own GitHub organization. Diagnoses, remediates, and manages Identity and Access Management (IAM) access issues on Google Cloud.

When should I use Iam Helper For Troubleshooting?

Iam Helper For Troubleshooting fits situations like: tasks that involve GraphQL; tasks that involve Help center and FAQ content.

How do I install Iam Helper For Troubleshooting in Claude Code?

Run `npx skills add google/skills --skill iam-helper-for-troubleshooting -a claude-code`. Or copy the skill folder (skills/cloud/iam-helper-for-troubleshooting in google/skills) into .claude/skills/iam-helper-for-troubleshooting in your project. Claude Code loads it when a task matches its description.

How do I install Iam Helper For Troubleshooting in Codex?

Run `npx skills add google/skills --skill iam-helper-for-troubleshooting -a codex`. Or copy the skill folder (skills/cloud/iam-helper-for-troubleshooting in google/skills) into .agents/skills/iam-helper-for-troubleshooting in your project. Codex loads it when a task matches its description.

Can I use Iam Helper For Troubleshooting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill iam-helper-for-troubleshooting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iam-helper-for-troubleshooting, .gemini/skills/iam-helper-for-troubleshooting, .github/skills/iam-helper-for-troubleshooting and .opencode/skills/iam-helper-for-troubleshooting in your project.

What does Iam Helper For Troubleshooting need to run?

Going by SKILL.md and its folder, Iam Helper For Troubleshooting needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Iam Helper For Troubleshooting access the network?

SKILL.md names 2 domains. As links in the text: docs.cloud.google.com and cloud.google.com. This is read from the text; nothing was executed.

Is Iam Helper For Troubleshooting safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Iam Helper For Troubleshooting use?

Iam Helper For Troubleshooting is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Iam Helper For Troubleshooting use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.9k tokens, read only when the agent opens those files.

What are the alternatives to Iam Helper For Troubleshooting?

Skills that share tags, products or a category with Iam Helper For Troubleshooting: Apollo Deploy Integration (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Debug Dashboard (BlackBeltTechnology/pi-agent-dashboard, 316 stars), Apollo Outreach (OpenClaudia/openclaudia-skills, 713 stars) and Certmanager Dns01 Gke Private Cluster (divinevideo/divine-mobile, 266 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iam Helper For Troubleshooting?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,097 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.