Validate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices.

MITAuto-check passedDevOps & Cloud

Install Validator Expert

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill validator-expert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace validator-expert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/validator-expert .claude/skills/validator-expert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validator-expert
GitHub stars
2.8k
Token cost
~1.9k tokens
SKILL.md length
722 words
Files
7 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Validate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices.

  • Works in 7 steps: Retrieve the deployment configuration… → Run the security validation suite (see… → Run the monitoring validation suite → …
  • Asked to validate a deployment
  • SKILL.md covers Current State, Overview, Prerequisites and Instructions, plus 4 more sections
  • Runs Shell scripts from its folder; calls gcloud

What it does

Validator Expert is an agent skill from jeremylongshore/tons-of-skills-marketplace. Validate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices. Generates weighted scores (0-100%) with actionable remediation plans. Use when asked to validate a deployment, run a production readiness check, audit security posture, or verify compliance for Vertex AI agents. Trigger with "validate deployment", "production readiness", "security audit", "compliance check", "is this agent ready for prod", "check my ADK agent", "review…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `ARD.md`, `PRD.md` and `references/monitoring-checklist.md`). Compatibility notes: Designed for Claude Code

It sits in DevOps & Cloud, covering Deployment, Security review and Regulatory compliance. It works with Vertex AI and Google Cloud. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Asked to validate a deployment
  • Run a production readiness check
  • Audit security posture
  • Verify compliance for Vertex AI agents

Example prompts

  • “validate deployment”
  • “production readiness”
  • “security audit”
  • “/validator-expert”

Requirements

  • Python 3
  • A Bash shell
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash(gcloud:*), Bash(python:*), Bash(pylint:*), Bash(flake8:*), Bash(mypy:*), Bash(bandit:*), Bash(pytest:*)

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Retrieve the deployment configuration using the Python SDK (vertexai.Client().agent_engines.get(name)) or REST API (GET…
  2. Run the security validation suite (see security checklist)
  3. Run the monitoring validation suite
  4. Run the performance validation suite
  5. Run the compliance validation suite
  6. Calculate weighted scores per category and compute the overall production readiness percentage
  7. Generate a prioritized recommendation list sorted by score impact per remediation effort

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash(gcloud:*)
    • Bash(python:*)
    • Bash(pylint:*)
    • Bash(flake8:*)
    • Bash(mypy:*)
    • Bash(bandit:*)
    • Bash(pytest:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Validator Expert loads about 1.9k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 164 tokens; SKILL.md has 722 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~164
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 722 words, ~1,859 tokens.

Download SKILL.mdSave it as .claude/skills/validator-expert/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
validator-expert
description
Validate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices. Generates weighted scores (0-100%) with actionable remediation plans. Use when asked to validate a deployment, run a production readiness check, audit security posture, or verify compliance for Vertex AI agents. Trigger with "validate deployment", "production readiness", "security audit", "compliance check", "is this agent ready for prod", "check my ADK agent", "review before deploy", or "production readiness check". Make sure to use this skill whenever validating ADK agents for Agent Engine.
allowed-tools
Read, Grep, Glob, Bash(gcloud:*), Bash(python:*), Bash(pylint:*), Bash(flake8:*), Bash(mypy:*), Bash(bandit:*), Bash(pytest:*)
compatibility
Designed for Claude Code
version
2.22.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
vertex-ai, security, compliance, validation, production-readiness, gcp
model
inherit
effort
high
argument-hint
[project-id]

Validator Expert

Current State

!gcloud config get-value project 2>/dev/null || echo 'no active project' !gcloud auth list --filter=status:ACTIVE --format="value(account)" 2>/dev/null || echo 'not authenticated'

Overview

Validate production readiness of Vertex AI Agent Engine deployments by executing weighted checks across five categories: security (30 points), monitoring (20 points), performance (25 points), compliance (15 points), and best practices (10 points). This skill produces a 0-100% composite score with pass/fail per check and prioritized remediation recommendations.

Prerequisites

  • gcloud CLI authenticated with roles/aiplatform.viewer, roles/iam.securityReviewer, and roles/monitoring.viewer
  • Access to the target Google Cloud project and Vertex AI Agent Engine deployment
  • Cloud Monitoring API and Cloud Logging API enabled in the project
  • Knowledge of the deployment's expected SLOs (latency targets, error rate thresholds)
  • Read-only access to IAM policies, VPC-SC configurations, and service account bindings

Instructions

  1. Retrieve the deployment configuration using the Python SDK (vertexai.Client().agent_engines.get(name)) or REST API (GET https://{LOCATION}-aiplatform.googleapis.com/v1/projects/{PROJECT}/locations/{LOCATION}/reasoningEngines/{ID}) and parse model, scaling, and feature settings
  2. Run the security validation suite (see security checklist):
    • Check if Agent Identity is enabled (recommended over service accounts for 2025+ deployments)
    • If using service accounts, verify IAM roles follow least-privilege (roles/aiplatform.expressUser, not roles/aiplatform.admin)
    • Confirm VPC Service Controls perimeter is active and correctly scoped
    • Check encryption at rest (CMEK or Google-managed) and in-transit (TLS 1.3)
    • Scan configuration files and environment variables for hardcoded secrets
    • Validate Model Armor is enabled with roles/modelarmor.user granted
    • Check Memory Bank IAM Conditions for multi-tenant agents
  3. Run the monitoring validation suite:
    • Verify Cloud Monitoring dashboards exist with required panels (request count, error rate, latency)
    • Confirm alerting policies cover error rate spikes, latency SLO breaches, and cost thresholds
    • Check token usage tracking is enabled with per-model granularity
    • Validate structured logging with severity levels and correlation IDs
    • Confirm latency SLOs are defined with p95 and p99 targets
  4. Run the performance validation suite:
    • Verify auto-scaling is configured with appropriate min/max instance counts
    • Check resource limits (CPU, memory) match expected workload profile
    • Confirm caching strategy is implemented for repeated prompts or embeddings
    • Validate Code Execution Sandbox TTL is set between 7-14 days
    • Check Memory Bank retention policy (min 100 memories, auto-cleanup enabled)
  5. Run the compliance validation suite:
    • Confirm audit logging is enabled for all admin and data access operations
    • Verify data residency meets regional requirements
    • Check privacy policies and data retention schedules
    • Validate backup and disaster recovery configuration
  6. Calculate weighted scores per category and compute the overall production readiness percentage
  7. Generate a prioritized recommendation list sorted by score impact per remediation effort
Show full SKILL.md (316 more words)Show less

Output

  • Production readiness score: 0-100% with status (READY >= 85%, NEEDS WORK 70-84%, NOT READY < 70%)
  • Per-category breakdown: security (x/30), monitoring (x/20), performance (x/25), compliance (x/15), best practices (x/10)
  • Pass/fail table for each individual check with evidence notes
  • Prioritized remediation plan: action items ranked by score improvement per effort
  • Comparison to previous validation run (if available) showing score delta

Error Handling

ErrorCauseSolution
Insufficient IAM permissionsViewer roles not granted on target projectRequest roles/aiplatform.viewer and roles/iam.securityReviewer from project admin
Agent deployment not foundIncorrect agent ID or deployment deletedVerify agent ID with vertexai.Client().agent_engines.list() or REST GET .../reasoningEngines; confirm deployment region
Monitoring API returns no dataAPI not enabled or agent has zero trafficEnable Monitoring API; generate synthetic traffic to populate baseline metrics
VPC-SC configuration inaccessibleOrganization policy restricts VPC-SC readsRequest roles/accesscontextmanager.policyReader at organization level
Compliance check inconclusiveAudit logs not enabled or retention too shortEnable Data Access audit logs; set log retention to minimum 365 days

Examples

Scenario 1: Pre-Launch Validation -- Validate a new ADK agent before production launch. Run all five validation categories. Target score: 85%+ overall, with security score at 28/30 minimum. Generate remediation plan for any failing checks.

Scenario 2: Post-Incident Security Audit -- After a permission escalation incident, re-validate security posture. Focus on IAM least-privilege, service account bindings, and VPC-SC perimeter integrity. Compare scores against the last passing validation.

Scenario 3: Quarterly Compliance Review -- Execute compliance and monitoring validation suites for SOC 2 audit preparation. Verify audit logging coverage, data residency compliance, and backup/DR configuration. Export results as evidence artifacts.

Resources

Validation checklists (read the relevant one during each validation step):

Official Google Cloud documentation:

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/.curated/validator-expert of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • ARD.md
  • PRD.md
  • references/monitoring-checklist.md
  • references/performance-compliance-checklist.md
  • references/security-checklist.md
  • scripts/validate-production.sh

Open the folder on GitHubat commit cfae287

Compare with similar skills

Validator Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validator Expert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validator Expert this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: PassMIT
Google Agents CLI Scaffoldpifferologo/cloud-agents-cli1291 repos~2.9kAutomated safety check: NotesApache-2.0
Batfish Config Analysisautomateyournetwork/netclaw676—~1.4kAutomated safety check: PassApache-2.0
Frontmcp Production Readinessagentfront/frontmcp146—~6.5kAutomated safety check: PassApache-2.0
AWS Cloudformationaws/agent-toolkit-for-aws2.8k—~3.6kAutomated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence

Similar skills

  • Google Agents CLI Scaffold

    pifferologo/cloud-agents-cli

    This skill should be used when the user wants to "create an agent project", "start a new ADK project", "build me a new agent", "add CI/CD to my project", "add deployment", "enhance my project", or…

    129 GitHub starsUsed in 1 repo~2.9k tokens
    DevOps & CloudAuto-check: notes
  • Batfish Config Analysis

    automateyournetwork/netclaw

    Batfish network configuration analysis -- pre-deployment validation, reachability testing, ACL/firewall tracing, differential analysis, compliance checking.

    676 GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Pre-production audit, hardening, and go-live checklists for FrontMCP servers.

    146 GitHub stars~6.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Cloudformation

    aws/agent-toolkit-for-aws

    Official

    Authors, validates, and troubleshoots AWS CloudFormation templates.

    2.8k GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Broccoli Oss GCP Deploy

    besimple-oss/broccoli

    Deploy this repository to a new Google Cloud project using the repo's existing Cloud Run, Cloud Run Jobs, Cloud SQL, Secret Manager, and Artifact Registry scripts.

    285 GitHub stars~4.1k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Validator Expert

What does Validator Expert do?

Validate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices. Validator Expert is an agent skill from jeremylongshore/tons-of-skills-marketplace. Validate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices.

When should I use Validator Expert?

Validator Expert fits situations like: asked to validate a deployment; run a production readiness check; audit security posture; verify compliance for Vertex AI agents.

How do I install Validator Expert in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill validator-expert -a claude-code`. Or copy the skill folder (skills/.curated/validator-expert in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/validator-expert in your project. Claude Code loads it when a task matches its description.

How do I install Validator Expert in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill validator-expert -a codex`. Or copy the skill folder (skills/.curated/validator-expert in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/validator-expert in your project. Codex loads it when a task matches its description.

Can I use Validator Expert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill validator-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validator-expert, .gemini/skills/validator-expert, .github/skills/validator-expert and .opencode/skills/validator-expert in your project.

What does Validator Expert need to run?

Going by SKILL.md and its folder, Validator Expert needs a shell for the scripts in its folder and the command-line tools its instructions call (gcloud). Our summary lists: Python 3; A Bash shell. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash(gcloud:*), Bash(python:*), Bash(pylint:*), Bash(flake8:*), Bash(mypy:*), Bash(bandit:*), Bash(pytest:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Validator Expert access the network?

SKILL.md names 1 domain. As links in the text: cloud.google.com. This is read from the text; nothing was executed.

Is Validator Expert safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Validator Expert use?

Validator Expert is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validator Expert use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.8k tokens, read only when the agent opens those files.

What are the alternatives to Validator Expert?

Skills that share tags, products or a category with Validator Expert: Google Agents CLI Scaffold (pifferologo/cloud-agents-cli, 129 stars), Batfish Config Analysis (automateyournetwork/netclaw, 676 stars), Frontmcp Production Readiness (agentfront/frontmcp, 146 stars) and AWS Cloudformation (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validator Expert?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.