Agent skill

Implementing Zero Trust With Beyondcorp

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Configures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network…

Apache-2.0Auto-check passedSecurity

Install Implementing Zero Trust With Beyondcorp

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-zero-trust-with-beyondcorp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-zero-trust-with-beyondcorp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-zero-trust-with-beyondcorp .claude/skills/implementing-zero-trust-with-beyondcorp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-zero-trust-with-beyondcorp
GitHub stars
34k
Token cost
~732 tokens
SKILL.md length
277 words
Files
4 (incl. scripts, references)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network…

  • Works in 4 steps: Enable IAP on Target Resources → Define Access Levels → Bind Access Policies → …
  • Eliminating perimeter/VPN trust for GCP resources
  • SKILL.md covers Overview, When to Use, Prerequisites and Steps, plus 1 more section
  • Runs Python scripts from its folder

What it does

Implementing Zero Trust With Beyondcorp is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Configures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network attributes, and auditing the resulting policies for compliance. Use when eliminating perimeter/VPN trust for GCP resources or internal apps, or when setting up identity- and device-posture-based access controls on Google Cloud.

Its SKILL.md is about 730 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Authorization and RBAC. It works with Google Cloud. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Eliminating perimeter/VPN trust for GCP resources
  • Setting up identity- and device-posture-based access controls on Google Cloud

Example prompts

  • “Use the implementing-zero-trust-with-beyondcorp skill to configure Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement…”
  • “/implementing-zero-trust-with-beyondcorp”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Enable IAP on Target Resources
  2. Define Access Levels
  3. Bind Access Policies
  4. Audit and Monitor

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Zero Trust With Beyondcorp loads about 732 tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 277 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~732
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 277 words, ~732 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-zero-trust-with-beyondcorp/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-zero-trust-with-beyondcorp
description
Configures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network attributes, and auditing the resulting policies for compliance. Use when eliminating perimeter/VPN trust for GCP resources or internal apps, or when setting up identity- and device-posture-based access controls on Google Cloud.
domain
cybersecurity
subdomain
zero-trust
tags
zero-trust, beyondcorp, google-cloud, iap, context-aware-access, device-trust, identity
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.AA-01, PR.AA-05, PR.IR-01
mitre_attack
T1078, T1550, T1021, T1556, T1078.004

Implementing Zero Trust with BeyondCorp

Overview

Google BeyondCorp Enterprise implements the zero trust security model by eliminating the concept of a trusted network perimeter. Instead of relying on VPNs and network location, BeyondCorp authenticates and authorizes every request based on user identity, device posture, and contextual attributes. Identity-Aware Proxy (IAP) serves as the enforcement point, intercepting all requests to protected resources and evaluating them against Access Context Manager policies. This skill covers configuring IAP for web applications, defining access levels based on device trust and network attributes, and auditing access policies for compliance.

When to Use

  • When deploying or configuring implementing zero trust with beyondcorp capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Google Cloud project with BeyondCorp Enterprise license
  • IAP API enabled (iap.googleapis.com)
  • Access Context Manager API enabled (accesscontextmanager.googleapis.com)
  • GCP resources to protect (Compute Engine, App Engine, or GKE services)
  • Endpoint Verification deployed on managed devices
  • Python 3.9+ with google-cloud-iap library

Steps

Step 1: Enable IAP on Target Resources

Configure Identity-Aware Proxy on Compute Engine, App Engine, or HTTPS load balancer backends.

Step 2: Define Access Levels

Create Access Context Manager access levels based on IP ranges, device attributes (OS version, encryption, screen lock), and geographic location.

Step 3: Bind Access Policies

Apply access levels as IAP conditions to enforce context-aware access decisions on protected resources.

Step 4: Audit and Monitor

Query IAP audit logs, verify policy enforcement, and identify gaps in zero trust coverage.

Expected Output

JSON report containing IAP-protected resources, access level definitions, policy binding audit results, and zero trust coverage metrics.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-zero-trust-with-beyondcorp of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Zero Trust With Beyondcorp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Zero Trust With Beyondcorp compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Zero Trust With Beyondcorp this skillmukul975/Anthropic-Cybersecurity-Skills34k—~732Automated safety check: PassApache-2.0
Google Cloud PAM Helpergoogle/skills21k—~3.2kAutomated safety check: PassApache-2.0
Iam Helper For Policy Managementgoogle/skills21k—~1.4kAutomated safety check: PassApache-2.0
Gke Workload Identitygoogle/skills21k—~4.4kAutomated safety check: PassApache-2.0
Investigating GCP Incidentstrilwu/secskills156—~2.2kAutomated safety check: PassMIT
Vercel Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: NotesMIT

Similar skills

  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    SecurityAuto-check passed
  • Official

    Streamlines the creation, modification, and management of IAM allow policies (v1) and deny policies (v2).

    21k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • Official

    Configures and diagnoses Workload Identity Federation for GKE authentication failures for Pods (403 "iam.serviceAccounts.getAccessToken" / permission denied, "could not find default credentials", or…

    21k GitHub stars~4.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth…

    156 GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Vercel Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Vercel security best practices for secrets, headers, and access control.

    2.8k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check: notes
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Implementing Zero Trust With Beyondcorp

What does Implementing Zero Trust With Beyondcorp do?

Configures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network…. Implementing Zero Trust With Beyondcorp is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Configures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network attributes, and auditing the resulting policies for compliance.

When should I use Implementing Zero Trust With Beyondcorp?

Implementing Zero Trust With Beyondcorp fits situations like: eliminating perimeter/VPN trust for GCP resources; setting up identity- and device-posture-based access controls on Google Cloud.

How do I install Implementing Zero Trust With Beyondcorp in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-zero-trust-with-beyondcorp -a claude-code`. Or copy the skill folder (skills/implementing-zero-trust-with-beyondcorp in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-zero-trust-with-beyondcorp in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Zero Trust With Beyondcorp in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-zero-trust-with-beyondcorp -a codex`. Or copy the skill folder (skills/implementing-zero-trust-with-beyondcorp in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-zero-trust-with-beyondcorp in your project. Codex loads it when a task matches its description.

Can I use Implementing Zero Trust With Beyondcorp in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-zero-trust-with-beyondcorp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-zero-trust-with-beyondcorp, .gemini/skills/implementing-zero-trust-with-beyondcorp, .github/skills/implementing-zero-trust-with-beyondcorp and .opencode/skills/implementing-zero-trust-with-beyondcorp in your project.

What does Implementing Zero Trust With Beyondcorp need to run?

Going by SKILL.md and its folder, Implementing Zero Trust With Beyondcorp needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Zero Trust With Beyondcorp access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Zero Trust With Beyondcorp safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Zero Trust With Beyondcorp use?

Implementing Zero Trust With Beyondcorp is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Zero Trust With Beyondcorp use?

About 732 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 655 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Zero Trust With Beyondcorp?

Skills that share tags, products or a category with Implementing Zero Trust With Beyondcorp: Google Cloud PAM Helper (google/skills, 21k stars), Iam Helper For Policy Management (google/skills, 21k stars), Gke Workload Identity (google/skills, 21k stars) and Investigating GCP Incidents (trilwu/secskills, 156 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Zero Trust With Beyondcorp?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.