Agent skill

Add Grant

by marin-community in marin-community/marin

Implement a fully specified request for a GCP IAM resource grant or Cloud Run IAP viewer in marin-iac.

Apache-2.0Auto-check passedDevOps & Cloud

Install Add Grant

skills CLI
$ npx skills add marin-community/marin --skill add-grant -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install marin-community/marin add-grant --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/add-grant .claude/skills/add-grant && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
add-grant
GitHub stars
3.9k
Token cost
~1.6k tokens
SKILL.md length
836 words
Files
1
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implement a fully specified request for a GCP IAM resource grant or Cloud Run IAP viewer in marin-iac.

  • Works in 2 steps: Shared project / resource GCP IAM — a… → Deploy-target IAM — runtime, secret,…
  • Tasks that involve Infrastructure as code
  • SKILL.md covers Grant surfaces, Collect the request, Register and grant the principal and Make the edit, plus 1 more section
  • Calls pulumi, uv and python

What it does

Add Grant is an agent skill from marin-community/marin. Implement a fully specified request for a GCP IAM resource grant or Cloud Run IAP viewer in marin-iac.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Google Cloud, Cloud Run and Pulumi. The repository describes itself as: Open-source framework for the research and development of foundation models. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Infrastructure as code

Example prompts

  • “/add-grant”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Shared project / resource GCP IAM — a role on the hai-gcp-models project, the
  2. Deploy-target IAM — runtime, secret, repository, KMS, and IAP grants for

What it can do on your machine

Read from SKILL.md and the folder at commit c468793. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pulumi
    • uv
    • python
    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Add Grant loads about 1.6k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 836 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from marin-community/marin at commit c468793, republished under its Apache-2.0 licence (© marin-community). 836 words, ~1,597 tokens.

Download SKILL.mdSave it as .claude/skills/add-grant/SKILL.md (or your agent's skills folder).
name
add-grant
description
Implement a fully specified request for a GCP IAM resource grant or Cloud Run IAP viewer in marin-iac.

Skill: Add a user grant

Turn an access request into a reviewable Pulumi change. Every human principal is KMS-encrypted, including IAP viewers on Cloud Run services. The change is never applied here — a second person runs the review-grant skill, merges, and runs pulumi up.

Read first:

  • infra/pulumi/README.md — the marin-iac stacks, the KMS key, and the pulumi up prerequisites.
  • infra/pulumi/src/iac/gcp/iam_data.yaml header — why human user: principals are encrypted and this file is public.

Grant surfaces

Decide which one the request needs before editing anything. A single request can touch both.

  1. Shared project / resource GCP IAM — a role on the hai-gcp-models project, the KMS key, a Secret Manager secret, a GCS bucket, an Artifact Registry repo, or a service account (who may impersonate it). Lives in infra/pulumi/src/iac/gcp/iam_data.yaml, applied by the marin stack in infra/pulumi. Each human user:<email> principal is KMS-encrypted once in the principals registry; grants reference its opaque human-NNN ID. Service accounts, groups, and domains stay plain strings.

  2. Deploy-target IAM — runtime, secret, repository, KMS, and IAP grants for Echo, EvalDash, Grafana, or Loom. Lives in that target's Python module under infra/pulumi/src/iac/gcp/ and is composed into the marin stack. Human grants reference the encrypted principal registry by opaque ID.

If you are unsure which surface a request means (e.g. "give Alice access to eval results" could be an IAP viewer on evaldash, a roles/storage.objectViewer grant on the record bucket, or both), ask before editing.

Collect the request

You need, per grant:

  • Principal — an email for a person, or a serviceAccount:/group:/domain: member for automation. Only personal emails get encrypted.
  • What they need access to — the specific resource, stated as a capability ("read the eval record bucket", "impersonate the ray autoscaler SA") rather than a raw role when the requester does not know GCP roles.
  • Why / for how long — a one-line justification. If the access is temporary, note it; GcpIamCondition can scope a grant with a CEL expiry, but prefer a follow-up removal PR unless the requester asks for an expiry.

Translate a capability into the narrowest role that satisfies it. Reuse a role already present in the relevant shared or deploy-target declaration for the same resource class before reaching for a broader built-in role. If the request is vague or over-broad, ask for specifics instead of guessing — an IAM grant is hard to walk back once applied.

Running against a GitHub issue

When invoked to respond to an issue rather than a local prompt:

  • Fetch it with gh issue view <n> --repo marin-community/marin --json title,body,comments.
  • If the issue is missing a principal, the target resource, or a justification, do not guess — post one comment (prefixed 🤖) listing exactly what you need, and stop. Do not open a half-specified PR.
  • If the request is complete, build the change and open a PR (below), then comment on the issue linking the PR.
Show full SKILL.md (378 more words)Show less

Register and grant the principal

For project-level roles, update the principal registry and every requested role in one command:

bash
uv run --package marin-iac --extra deploy \
  python infra/pulumi/iam_principal.py grant alice@openathena.ai \
    --project-role roles/logging.viewer \
    --project-role roles/monitoring.viewer

The command decrypts existing registry entries locally to find and reuse the person's opaque ID. It encrypts and registers the email once when the person is new, then writes deterministic YAML. Encryption and lookup need roles/cloudkms.cryptoKeyEncrypterDecrypter on the marin-iac key (the same access pulumi up needs).

For a KMS key, secret, bucket, Artifact Registry repository, or service-account grant, register the principal first:

bash
uv run --package marin-iac --extra deploy \
  python infra/pulumi/iam_principal.py register alice@openathena.ai

The command prints the existing or new human-NNN ID. Add principal: human-NNN to a shared resource grant or principals["human-NNN"] to a deploy-target module. Never write a personal email in plaintext into either declaration, a commit message, or the PR body — the repo is public.

Make the edit

Project / resource IAM — update iam_data.yaml:

  • Find the grant for the target role and resource, or add one. Project roles go in project_grants; a bucket/secret/repo/service-account grant goes under that resource's entry in buckets / secrets / artifact_repositories / service_accounts (add the resource entry if it is not there yet).
  • Project-role requests are already complete after iam_principal.py grant. For other resource grants, add the registered principal: human-NNN reference. Add a plain member string for service accounts, groups, domains, workload identities, or other automation.

Deploy-target or IAP grant — add the registered principals["human-NNN"] reference to the target's iam_grants() declaration under infra/pulumi/src/iac/gcp/. Plain service-account, group, and domain members can be added directly.

Verify and open the PR

  • ./infra/pre-commit.py --files <edited files> (or --changed-files), fixing anything it reports. git add a new file before linting so it is scoped in.

  • Do not run pulumi preview/up — a local preview decrypts and prints the real emails, and applying is the reviewer's step. CI runs a redacted preview on the PR.

  • Follow the commit skill to commit, push, and open the PR against main. Add the agent-generated label. Title the PR for the capability, not the person: [iac] Grant eval-bucket read to a new operator, never the email. The body states the resource, the role, and the one-line justification — no personal emails. Note in the body that a reviewer should run review-grant, then pulumi up on the marin stack.

  • Assign the PR to the grant approvers so one of them picks up review-grant:

    bash
    gh pr edit <n> --repo marin-community/marin \
      --add-assignee yonromai,ravwojdyla,rjpower

© marin-community, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/add-grant of marin-community/marin.

Open the folder on GitHubat commit c468793

Compare with similar skills

Add Grant next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Add Grant compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Add Grant this skillmarin-community/marin3.9k—~1.6kAutomated safety check: PassApache-2.0
DeployingGoogleCloudPlatform/race-condition234—~3kAutomated safety check: PassCustom licence
Gke Alert Configurationgoogle/skills21k—~5.3kAutomated safety check: PassApache-2.0
Dd GCP Integrationdatadog-labs/agent-skills177—~8kAutomated safety check: NotesMIT
Generating Infrastructure As Codejeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMIT
GCP To AWSaws/agent-toolkit-for-aws2.8k—~15kAutomated safety check: PassApache-2.0

Similar skills

  • Deploying

    GoogleCloudPlatform/race-condition

    Guides deployment of Race Condition to a GCP project. An agent skill from GoogleCloudPlatform/race-condition.

    234 GitHub stars~3k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Official

    Configures alerting policies in Terraform for Google Kubernetes Engine (GKE) clusters, workloads, and services using PromQL and Google Cloud Managed Service for Prometheus.

    21k GitHub stars~5.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Dd GCP Integration

    datadog-labs/agent-skills

    Set up the Datadog Google Cloud integration with Terraform - creates a service account in the host project, lets Datadog's delegate principal impersonate it via roles/iam.serviceAccountTokenCreator…

    177 GitHub stars~8k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Generating Infrastructure As Code

    jeremylongshore/tons-of-skills-marketplace

    Execute use when generating infrastructure as code configurations.

    2.8k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • GCP To AWS

    aws/agent-toolkit-for-aws

    Official

    Migrate workloads from Google Cloud Platform to AWS — plus AI and agentic workloads from any provider.

    2.8k GitHub stars~15k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Research To Deploy

    jeremylongshore/tons-of-skills-marketplace

    Researches infrastructure best practices and generates deployment-ready configurations, Terraform modules, Dockerfiles, and CI/CD pipelines.

    2.8k GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check passed

More from marin-community/marin

All 41 skills in this repo
  • Noslop

    marin-community/marin

    Deslop, simplify, or review low-value tests and prose only when explicitly requested for a branch or diff.

    3.9k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Use Iris

    marin-community/marin

    Use Iris to submit, inspect, debug, monitor, or recover jobs and tasks; diagnose scheduling and federation; deploy controllers; or reserve dev GPUs and TPUs.

    3.9k GitHub stars~745 tokensUpdated today
    Auto-check passed
  • Launch Rl

    marin-community/marin

    Define, validate, submit, or restart a Marin SkyRL experiment through its artifact main.

    3.9k GitHub stars~894 tokensUpdated today
    Auto-check passed
  • Marina Applet

    marin-community/marin

    Build, validate, publish, update, inspect, query, roll back, or archive a dynamic Marina applet.

    3.9k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Query Finelog

    marin-community/marin

    Query Finelog logs and telemetry for Iris tasks, workers, profiles, training, vLLM, and cross-cluster forwarding.

    3.9k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Trace Pulumi Diff

    marin-community/marin

    Run a read-only preview for a specified Marin infra/pulumi stack and trace each pending resource change to merged pull requests since its latest successful update when that update records a clean…

    3.9k GitHub stars~663 tokensUpdated today
    Auto-check passed

Categories

Questions about Add Grant

What does Add Grant do?

Implement a fully specified request for a GCP IAM resource grant or Cloud Run IAP viewer in marin-iac. Add Grant is an agent skill from marin-community/marin. Implement a fully specified request for a GCP IAM resource grant or Cloud Run IAP viewer in marin-iac.

When should I use Add Grant?

Add Grant fits situations like: tasks that involve Infrastructure as code.

How do I install Add Grant in Claude Code?

Run `npx skills add marin-community/marin --skill add-grant -a claude-code`. Or copy the skill folder (.agents/skills/add-grant in marin-community/marin) into .claude/skills/add-grant in your project. Claude Code loads it when a task matches its description.

How do I install Add Grant in Codex?

Run `npx skills add marin-community/marin --skill add-grant -a codex`. Or copy the skill folder (.agents/skills/add-grant in marin-community/marin) into .agents/skills/add-grant in your project. Codex loads it when a task matches its description.

Can I use Add Grant in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add marin-community/marin --skill add-grant -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-grant, .gemini/skills/add-grant, .github/skills/add-grant and .opencode/skills/add-grant in your project.

What does Add Grant need to run?

Going by SKILL.md and its folder, Add Grant needs the command-line tools its instructions call (pulumi, uv, python, gh and git). Our summary lists: Python 3.

Does Add Grant access the network?

SKILL.md contains no URLs. Its commands use uv, gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Add Grant safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Add Grant use?

Add Grant is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Add Grant use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Add Grant?

Skills that share tags, products or a category with Add Grant: Deploying (GoogleCloudPlatform/race-condition, 234 stars), Gke Alert Configuration (google/skills, 21k stars), Dd GCP Integration (datadog-labs/agent-skills, 177 stars) and Generating Infrastructure As Code (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Add Grant?

marin-community (a GitHub organization) maintains it in marin-community/marin, which has 3,921 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 10, 2026.

Source: marin-community/marin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.