Deploying
GoogleCloudPlatform/race-condition
Guides deployment of Race Condition to a GCP project. An agent skill from GoogleCloudPlatform/race-condition.
Implement a fully specified request for a GCP IAM resource grant or Cloud Run IAP viewer in marin-iac.
$ npx skills add marin-community/marin --skill add-grant -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install marin-community/marin add-grant --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/add-grant .claude/skills/add-grant && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "add-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/add-grant into .claude/skills/add-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-grant", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/marin-community/marin/tree/main/.agents/skills/add-grantType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add marin-community/marin --skill add-grant -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install marin-community/marin add-grant --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/add-grant .agents/skills/add-grant && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "add-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/add-grant into .agents/skills/add-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-grant", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add marin-community/marin --skill add-grant -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install marin-community/marin add-grant --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/add-grant .cursor/skills/add-grant && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "add-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/add-grant into .cursor/skills/add-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-grant", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/marin-community/marin.git --path .agents/skills/add-grant--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add marin-community/marin --skill add-grant -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install marin-community/marin add-grant --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/add-grant .gemini/skills/add-grant && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "add-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/add-grant into .gemini/skills/add-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-grant", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install marin-community/marin add-grantInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add marin-community/marin --skill add-grant -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/add-grant .github/skills/add-grant && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "add-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/add-grant into .github/skills/add-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-grant", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add marin-community/marin --skill add-grant -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install marin-community/marin add-grant --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/add-grant .opencode/skills/add-grant && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "add-grant" agent skill from https://github.com/marin-community/marin/tree/main/.agents/skills/add-grant into .opencode/skills/add-grant/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-grant", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
add-grantImplement a fully specified request for a GCP IAM resource grant or Cloud Run IAP viewer in marin-iac.
Add Grant is an agent skill from marin-community/marin. Implement a fully specified request for a GCP IAM resource grant or Cloud Run IAP viewer in marin-iac.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Infrastructure as code. It works with Google Cloud, Cloud Run and Pulumi. The repository describes itself as: Open-source framework for the research and development of foundation models. The licence is Apache-2.0.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c468793. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pulumiuvpythonghgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use uv, gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Add Grant loads about 1.6k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 836 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from marin-community/marin at commit c468793, republished under its Apache-2.0 licence (© marin-community). 836 words, ~1,597 tokens.
.claude/skills/add-grant/SKILL.md (or your agent's skills folder).Turn an access request into a reviewable Pulumi change. Every human principal is
KMS-encrypted, including IAP viewers on Cloud Run services. The change is never
applied here — a second person runs the
review-grant skill, merges, and runs pulumi up.
Read first:
infra/pulumi/README.md — the marin-iac stacks, the KMS key, and the
pulumi up prerequisites.infra/pulumi/src/iac/gcp/iam_data.yaml header — why human user: principals
are encrypted and this file is public.Decide which one the request needs before editing anything. A single request can touch both.
Shared project / resource GCP IAM — a role on the hai-gcp-models project, the
KMS key, a Secret Manager secret, a GCS bucket, an Artifact Registry repo, or
a service account (who may impersonate it). Lives in
infra/pulumi/src/iac/gcp/iam_data.yaml, applied by the marin stack in
infra/pulumi. Each human user:<email> principal is KMS-encrypted once in
the principals registry; grants reference its opaque human-NNN ID.
Service accounts, groups, and domains stay plain strings.
Deploy-target IAM — runtime, secret, repository, KMS, and IAP grants for
Echo, EvalDash, Grafana, or Loom. Lives in that target's Python module under
infra/pulumi/src/iac/gcp/ and is composed into the marin stack.
Human grants reference the encrypted principal registry by opaque ID.
If you are unsure which surface a request means (e.g. "give Alice access to eval
results" could be an IAP viewer on evaldash, a roles/storage.objectViewer
grant on the record bucket, or both), ask before editing.
You need, per grant:
serviceAccount:/group:/domain:
member for automation. Only personal emails get encrypted.GcpIamCondition can scope a grant with a CEL expiry, but prefer a
follow-up removal PR unless the requester asks for an expiry.Translate a capability into the narrowest role that satisfies it. Reuse a role already present in the relevant shared or deploy-target declaration for the same resource class before reaching for a broader built-in role. If the request is vague or over-broad, ask for specifics instead of guessing — an IAM grant is hard to walk back once applied.
When invoked to respond to an issue rather than a local prompt:
gh issue view <n> --repo marin-community/marin --json title,body,comments.🤖) listing exactly what you
need, and stop. Do not open a half-specified PR.For project-level roles, update the principal registry and every requested role in one command:
uv run --package marin-iac --extra deploy \
python infra/pulumi/iam_principal.py grant alice@openathena.ai \
--project-role roles/logging.viewer \
--project-role roles/monitoring.viewerThe command decrypts existing registry entries locally to find and reuse the
person's opaque ID. It encrypts and registers the email once when the person is
new, then writes deterministic YAML. Encryption and lookup need
roles/cloudkms.cryptoKeyEncrypterDecrypter on the marin-iac key (the same
access pulumi up needs).
For a KMS key, secret, bucket, Artifact Registry repository, or service-account grant, register the principal first:
uv run --package marin-iac --extra deploy \
python infra/pulumi/iam_principal.py register alice@openathena.aiThe command prints the existing or new human-NNN ID. Add
principal: human-NNN to a shared resource grant or
principals["human-NNN"] to a deploy-target module. Never write a personal
email in plaintext into either declaration, a commit message, or the PR body —
the repo is public.
Project / resource IAM — update iam_data.yaml:
project_grants; a bucket/secret/repo/service-account grant goes
under that resource's entry in buckets / secrets /
artifact_repositories / service_accounts (add the resource entry if it is
not there yet).iam_principal.py grant.
For other resource grants, add the registered principal: human-NNN
reference. Add a plain member string for service accounts, groups, domains,
workload identities, or other automation.Deploy-target or IAP grant — add the registered principals["human-NNN"]
reference to the target's iam_grants() declaration under
infra/pulumi/src/iac/gcp/. Plain service-account, group, and domain members can
be added directly.
./infra/pre-commit.py --files <edited files> (or --changed-files), fixing
anything it reports. git add a new file before linting so it is scoped in.
Do not run pulumi preview/up — a local preview decrypts and prints the
real emails, and applying is the reviewer's step. CI runs a redacted preview on
the PR.
Follow the commit skill to commit, push, and open the PR against main. Add
the agent-generated label. Title the PR for the capability, not the person:
[iac] Grant eval-bucket read to a new operator, never the email. The body
states the resource, the role, and the one-line justification — no personal
emails. Note in the body that a reviewer should run review-grant, then
pulumi up on the marin stack.
Assign the PR to the grant approvers so one of them picks up review-grant:
gh pr edit <n> --repo marin-community/marin \
--add-assignee yonromai,ravwojdyla,rjpower© marin-community, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/add-grant of marin-community/marin.
Open the folder on GitHubat commit c468793
Add Grant next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Add Grant this skillmarin-community/marin | 3.9k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| DeployingGoogleCloudPlatform/race-condition | 234 | — | ~3k | Automated safety check: Pass | Custom licence | |
| Gke Alert Configurationgoogle/skills | 21k | — | ~5.3k | Automated safety check: Pass | Apache-2.0 | |
| Dd GCP Integrationdatadog-labs/agent-skills | 177 | — | ~8k | Automated safety check: Notes | MIT | |
| Generating Infrastructure As Codejeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | |
| GCP To AWSaws/agent-toolkit-for-aws | 2.8k | — | ~15k | Automated safety check: Pass | Apache-2.0 |
GoogleCloudPlatform/race-condition
Guides deployment of Race Condition to a GCP project. An agent skill from GoogleCloudPlatform/race-condition.
google/skills
Configures alerting policies in Terraform for Google Kubernetes Engine (GKE) clusters, workloads, and services using PromQL and Google Cloud Managed Service for Prometheus.
datadog-labs/agent-skills
Set up the Datadog Google Cloud integration with Terraform - creates a service account in the host project, lets Datadog's delegate principal impersonate it via roles/iam.serviceAccountTokenCreator…
jeremylongshore/tons-of-skills-marketplace
Execute use when generating infrastructure as code configurations.
aws/agent-toolkit-for-aws
Migrate workloads from Google Cloud Platform to AWS — plus AI and agentic workloads from any provider.
jeremylongshore/tons-of-skills-marketplace
Researches infrastructure best practices and generates deployment-ready configurations, Terraform modules, Dockerfiles, and CI/CD pipelines.
marin-community/marin
Deslop, simplify, or review low-value tests and prose only when explicitly requested for a branch or diff.
marin-community/marin
Use Iris to submit, inspect, debug, monitor, or recover jobs and tasks; diagnose scheduling and federation; deploy controllers; or reserve dev GPUs and TPUs.
marin-community/marin
Define, validate, submit, or restart a Marin SkyRL experiment through its artifact main.
marin-community/marin
Build, validate, publish, update, inspect, query, roll back, or archive a dynamic Marina applet.
marin-community/marin
Query Finelog logs and telemetry for Iris tasks, workers, profiles, training, vLLM, and cross-cluster forwarding.
marin-community/marin
Run a read-only preview for a specified Marin infra/pulumi stack and trace each pending resource change to merged pull requests since its latest successful update when that update records a clean…
Works with
Categories
Implement a fully specified request for a GCP IAM resource grant or Cloud Run IAP viewer in marin-iac. Add Grant is an agent skill from marin-community/marin. Implement a fully specified request for a GCP IAM resource grant or Cloud Run IAP viewer in marin-iac.
Add Grant fits situations like: tasks that involve Infrastructure as code.
Run `npx skills add marin-community/marin --skill add-grant -a claude-code`. Or copy the skill folder (.agents/skills/add-grant in marin-community/marin) into .claude/skills/add-grant in your project. Claude Code loads it when a task matches its description.
Run `npx skills add marin-community/marin --skill add-grant -a codex`. Or copy the skill folder (.agents/skills/add-grant in marin-community/marin) into .agents/skills/add-grant in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add marin-community/marin --skill add-grant -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-grant, .gemini/skills/add-grant, .github/skills/add-grant and .opencode/skills/add-grant in your project.
Going by SKILL.md and its folder, Add Grant needs the command-line tools its instructions call (pulumi, uv, python, gh and git). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use uv, gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Add Grant is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Add Grant: Deploying (GoogleCloudPlatform/race-condition, 234 stars), Gke Alert Configuration (google/skills, 21k stars), Dd GCP Integration (datadog-labs/agent-skills, 177 stars) and Generating Infrastructure As Code (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
marin-community (a GitHub organization) maintains it in marin-community/marin, which has 3,921 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 10, 2026.
Source: marin-community/marin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.