Official agent skill

Workload Manager Basics

by google in google/skills

A skill your agent uses to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the REST API.

OfficialApache-2.0Auto-check passedBackend & APIs

Install Workload Manager Basics

skills CLI
$ npx skills add google/skills --skill workload-manager-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills workload-manager-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/workload-manager-basics .claude/skills/workload-manager-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
workload-manager-basics
GitHub stars
21k
Token cost
~1.7k tokens
SKILL.md length
528 words
Files
9 (incl. references)
Skills in repo
145
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the REST API.

  • Works in 4 steps: Enable the Workload Manager API → Authenticate locally using Application… → Ensure the Workload Manager service… → …
  • Manage Google Cloud Workload Manager evaluations
  • SKILL.md covers Use This Flow, Core API Constraints, Prerequisites and Quick Client Library Example, plus 3 more sections
  • Calls gcloud and python3

What it does

Workload Manager Basics is an agent skill from google/skills, published by the product's own GitHub organization. Use this skill to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the REST API. Use when you need to inspect workload best-practice rules, create and run evaluations for Google Cloud general best practices, SAP, SQL Server, or custom organizational rules, review violations, export results to BigQuery, or automate Workload Manager through client libraries because no service-specific public CLI or MCP server is available. Don't…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `references/client-library-usage.md`, `references/core-concepts.md` and `references/general-best-practices.md`).

It sits in Backend & APIs, covering REST APIs and Data warehousing. It works with Google Cloud, Model Context Protocol, Google BigQuery and Microsoft SQL Server. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Manage Google Cloud Workload Manager evaluations
  • Scanned resources
  • Validation results by using public client libraries and the REST API
  • You need to inspect workload best-practice rules

Example prompts

  • “/workload-manager-basics”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Enable the Workload Manager API
  2. Authenticate locally using Application Default Credentials (ADC) before
  3. Ensure the Workload Manager service agent has the required roles granted in
  4. Grant the least-privileged role needed for the task. Start with

What it can do on your machine

Read from SKILL.md and the folder at commit 8a1ac05. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.cloud.google.com
    • pypi.org
    • discuss.google.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Workload Manager Basics loads about 1.7k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 161 tokens; SKILL.md has 528 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~161
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 8a1ac05, republished under its Apache-2.0 licence (© google). 528 words, ~1,739 tokens.

Download SKILL.mdSave it as .claude/skills/workload-manager-basics/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
workload-manager-basics
description
Use this skill to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the REST API. Use when you need to inspect workload best-practice rules, create and run evaluations for Google Cloud general best practices, SAP, SQL Server, or custom organizational rules, review violations, export results to BigQuery, or automate Workload Manager through client libraries because no service-specific public CLI or MCP server is available. Don't use for general Google Compute Engine instance management, VPC configuration, or standard IAM auditing.
metadata.version
1.0.0
metadata.category
CloudObservabilityAndMonitoring

Workload Manager Basics

Workload Manager validates enterprise workloads against Google Cloud best practices and recommendations. The public client libraries are centered on evaluations: define a resource scope, choose built-in or custom rules, run an evaluation, then inspect results and scanned resources.

Use This Flow

mermaid
flowchart LR
    Rules["List rules"] --> Eval["Create or update evaluation"]
    Resources["Project, folder, or org scope"] --> Eval
    Eval --> Run["Run evaluation"]
    Run --> Results["Inspect evaluation results"]
    Results --> Remediate["Remediate findings"]
    Results --> Export["Optional BigQuery export"]

Core API Constraints

To ensure compatibility, security, and successful integration:

  • Public Surface Only: You MUST strictly interact with Workload Manager using the official public google-cloud-workloadmanager client library or the public REST API (workloadmanager.googleapis.com/v1).
  • No Internal or Undocumented APIs: Do NOT attempt to use internal RPC protocols, private service backends, or undocumented discovery mechanisms. They are not supported for public integrations and will fail.
  • No Service-Specific CLI: There is no public gcloud workload-manager CLI command group. Use gcloud only for authentication, IAM role assignment, and fetching raw REST tokens.
  • Sandbox Execution Robustness (Auth/Mock Fallbacks): When gcloud authentication or Workload Manager API calls fail in sandboxed or restricted environments (e.g., due to Context Aware Access token blocks, missing API enablement, or mock resources returning 404/403), immediately fall back to presenting example code and static findings from your references instead of entering retry loops. Present the correct client library code structure or REST API payload example, clearly explain the auth or resource limitation, and list typical rules or mock findings statically to satisfy the request.

Prerequisites

  1. Enable the Workload Manager API:

    bash
    gcloud services enable workloadmanager.googleapis.com --quiet
  2. Authenticate locally using Application Default Credentials (ADC) before using client libraries:

    bash
    gcloud auth application-default login
  3. Ensure the Workload Manager service agent has the required roles granted in your project (mandatory for API/client library usage, see IAM & Security).

  4. Grant the least-privileged role needed for the task. Start with roles/workloadmanager.viewer for read-only access to evaluation resources and use roles/workloadmanager.evaluationAdmin or roles/workloadmanager.admin only when creating, updating, running, or deleting evaluations.

Quick Client Library Example

Use the Python client library for the first working automation path:

bash
python3 -m pip install --upgrade google-cloud-workloadmanager
python
from google.cloud import workloadmanager_v1

project_id = "PROJECT_ID"
location = "LOCATION"
parent = f"projects/{project_id}/locations/{location}"

client = workloadmanager_v1.WorkloadManagerClient()

rules = client.list_rules(
    request=workloadmanager_v1.ListRulesRequest(
        parent=parent,
        evaluation_type=workloadmanager_v1.Evaluation.EvaluationType.OTHER,
    )
)

for rule in rules.rules:
    print(rule.name, rule.display_name, rule.severity)
Show full SKILL.md (213 more words)Show less

Reference Directory

  • Core Concepts: Evaluations, rules, results, scanned resources, supported workload types, and API shape.

  • General Best Practices: Google Cloud general best-practice posture checks, OTHER evaluation guidance, custom Rego rules, and scale/automation patterns.

  • Client Libraries: Python and Go client library examples for listing rules, creating evaluations, running evaluations, and reading findings.

  • REST Usage: Direct REST examples for the public Workload Manager API and operations polling.

  • Public CLI Status: No documented service-specific gcloud workload-manager command group; use gcloud only for auth, IAM, API enablement, and REST tokens.

  • Public MCP Status: No documented public Workload Manager MCP server; use client libraries or REST API instead.

  • Setup Prerequisites: Terraform examples only for adjacent prerequisites such as API enablement, IAM, BigQuery export datasets, and KMS keys. This is not Workload Manager resource management.

  • IAM & Security: Workload Manager roles, least-privilege guidance, service agents, data handling, and CMEK notes.

If product behavior or API fields are not covered here, check the current Workload Manager product documentation and client library reference before implementing.

Authoritative References

Additional Context

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (references) in skills/cloud/workload-manager-basics of google/skills.

  • SKILL.md
  • references/client-library-usage.md
  • references/core-concepts.md
  • references/general-best-practices.md
  • references/iam-security.md
  • references/public-cli-status.md
  • references/public-mcp-status.md
  • references/rest-usage.md
  • references/setup-prerequisites.md

Open the folder on GitHubat commit 8a1ac05

Compare with similar skills

Workload Manager Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Workload Manager Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Workload Manager Basics this skillgoogle/skills21k—~1.7kAutomated safety check: PassApache-2.0
Imaging Data CommonsK-Dense-AI/scientific-agent-skills48k1 repos~7.8kAutomated safety check: PassMIT
Deploying On GCPancoleman/ai-design-components526—~3.9kAutomated safety check: PassMIT
Io ConnectorsKilo-Org/kilo-marketplace189—~1.3kAutomated safety check: PassApache-2.0
GCP Patternsvibeeval/vibecosystem531—~1.4kAutomated safety check: PassMIT
Semantic Analystsidequery/sidemantic129—~982Automated safety check: PassAGPL-3.0

Similar skills

  • Imaging Data Commons

    K-Dense-AI/scientific-agent-skills

    Queries and downloads public cancer imaging data from NCI Imaging Data Commons.

    48k GitHub starsUsed in 1 repo~7.8k tokens
    DatabasesAuto-check passed
  • Deploying On GCP

    ancoleman/ai-design-components

    Implement applications using Google Cloud Platform (GCP) services.

    526 GitHub stars~3.9k tokensUpdated 10 mo ago
    DatabasesAuto-check passed
  • Io Connectors

    Kilo-Org/kilo-marketplace

    Guides development and usage of I/O connectors in Apache Beam.

    189 GitHub stars~1.3k tokensUpdated 8 days ago
    Testing & QAAuto-check passed
  • GCP Patterns

    vibeeval/vibecosystem

    Cloud Run deployment, BigQuery optimization, Pub/Sub patterns, IAM best practices

    531 GitHub stars~1.4k tokensUpdated 1 mo ago
    DatabasesAuto-check passed
  • Semantic Analyst

    sidequery/sidemantic

    Answer analytical, KPI, metric, trend, cohort, and business-performance questions through a Sidemantic semantic layer.

    129 GitHub stars~982 tokensUpdated today
    DatabasesAuto-check passed
  • GCP Audit Logs

    sickn33/agentic-awesome-skills

    Configure GCP Cloud Audit Logs for compliance. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.8k tokens
    DatabasesAuto-check passed

More from google/skills

All 145 skills in this repo
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5.1k tokensUpdated today
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated today
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Official

    Analyzes BigQuery slot use, query costs and execution bottlenecks from INFORMATION_SCHEMA to diagnose slow queries, slot contention and unpartitioned scans.

    21k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Questions about Workload Manager Basics

What does Workload Manager Basics do?

A skill your agent uses to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the REST API. Workload Manager Basics is an agent skill from google/skills, published by the product's own GitHub organization. Use this skill to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the REST API.

When should I use Workload Manager Basics?

Workload Manager Basics fits situations like: manage Google Cloud Workload Manager evaluations; scanned resources; validation results by using public client libraries and the REST API; you need to inspect workload best-practice rules.

How do I install Workload Manager Basics in Claude Code?

Run `npx skills add google/skills --skill workload-manager-basics -a claude-code`. Or copy the skill folder (skills/cloud/workload-manager-basics in google/skills) into .claude/skills/workload-manager-basics in your project. Claude Code loads it when a task matches its description.

How do I install Workload Manager Basics in Codex?

Run `npx skills add google/skills --skill workload-manager-basics -a codex`. Or copy the skill folder (skills/cloud/workload-manager-basics in google/skills) into .agents/skills/workload-manager-basics in your project. Codex loads it when a task matches its description.

Can I use Workload Manager Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill workload-manager-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/workload-manager-basics, .gemini/skills/workload-manager-basics, .github/skills/workload-manager-basics and .opencode/skills/workload-manager-basics in your project.

What does Workload Manager Basics need to run?

Going by SKILL.md and its folder, Workload Manager Basics needs the command-line tools its instructions call (gcloud and python3). Our summary lists: Python 3.

Does Workload Manager Basics access the network?

SKILL.md names 3 domains. As links in the text: docs.cloud.google.com, pypi.org and discuss.google.dev. This is read from the text; nothing was executed.

Is Workload Manager Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Workload Manager Basics use?

Workload Manager Basics is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Workload Manager Basics use?

About 1.7k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.9k tokens, read only when the agent opens those files.

What are the alternatives to Workload Manager Basics?

Skills that share tags, products or a category with Workload Manager Basics: Imaging Data Commons (K-Dense-AI/scientific-agent-skills, 48k stars), Deploying On GCP (ancoleman/ai-design-components, 526 stars), Io Connectors (Kilo-Org/kilo-marketplace, 189 stars) and GCP Patterns (vibeeval/vibecosystem, 531 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Workload Manager Basics?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 20,994 GitHub stars. The repository holds 145 skills in this directory. The repository was last updated on October 6, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.