Google Cloud Waf SecuritySAFE
CLI tool for configuring and monitoring Claude Code
Overview
CLI tool for configuring and monitoring Claude Code
aa855ad1e58dOBSERVED · 2026-10-02What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: google-cloud-waf-security
description: Generates security-focused guidance for Google Cloud workloads based on the Google Cloud Well-Architected Framework (WAF). Use to evaluate a workload, identify security requirements, and provide actionable recommendations for IAM, network security, data protection, and operational security.
source: google/skills (Apache 2.0)
---
# Google Cloud Well-Architected Framework skill for the Security pillar
## Overview
The security pillar of the Google Cloud Well-Architected Framework provides
design principles and best practices for building a robust security posture by
integrating security into every layer of the architecture for cloud workloads.
It focuses on maintaining confidentiality and integrity of data and systems
while ensuring compliance and privacy. It provides a structured approach to risk
management, threat defense, and identity control, enabling you to operate cloud
workloads securely and at scale.
## Core principles
The recommendations in the security pillar of the Well-Architected Framework are
aligned with the following core principles:
- **Implement security by design**: Integrate cloud security and network
security considerations starting from the initial design phase of your
applications and infrastructure. Google Cloud provides architecture
blueprints and recommendations to help you apply this principle. Grounding
document:
https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design
- **Implement zero trust**: Use a _never trust, always verify_ approach, where
access to resources is granted based on continuous verification of trust.
Google Cloud supports this principle through products like Chrome Enterprise
Premium and Identity-Aware Proxy (IAP). Grounding document:
https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust
- **Implement shift-left security**: Implement security controls early in the
software development lifecycle. Avoid security defects before system changes
are made. Detect and fix security bugs early, fast, and reliably after the
system changes are committed. Google Cloud supports this principle through
products like Cloud Build, Binary Authorization, and Artifact Registry.
Grounding document:
https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security
- **Implement preemptive cyber defense**: Adopt a proactive approach to
security by implementing robust fundamental measures like threat
intelligence. This approach helps you build a foundation for more effective
threat detection and response. Google Cloud's approach to layered security
controls aligns with this principle. Google Cloud supports this principle
through products like Security Command Center, Google Threat Intelligence,
and Google SecOps. Grounding document:
https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense
- **Use AI securely and responsibly**: Develop and deploy AI systems in a
responsible and secure manner. The recommendations for this principle are
aligned with guidance in the AI and ML perspective of the Well-Architected
Framework and in Google's Secure AI Framework (SAIF). Grounding document:
https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly
- **Use AI for security**: Use AI capabilities to improve your existing
security systems and processes through Gemini in Security and overall
platform-security capabilities. Use AI as a tool to increase the automation
of remedial work and ensure security hygiene to make other systems more
secure. Google Cloud supports this principle through products like Google
Threat Intelligence and Google SecOps. Grounding document:
https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security
- **Meet regulatory, compliance, and privacy needs**: Adhere to
industry-specific regulations, compliance standards, and privacy
requirements. Google Cloud helps you meet these obligations through products
like Assured Workloads, Organization Policy Service, and our compliance
resource center. Grounding document:
https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs
## Relevant Google Cloud products
The following are _examples_ of Google Cloud products and features that are
relevant to security:
- **Identity and access management**
- **Identity and Access Management (IAM)**: Fine-grained access control for
Google Cloud resources.
- **Identity-Aware Proxy (IAP)**: Secure access to applications without a VPN.
- **Chrome Enterprise Premium**: Endpoint security and context-aware access.
- **Network security**
- **Google Cloud Armor**: DDoS protection and Web Application Firewall (WAF).
- **VPC Service Controls**: Define security perimeters to prevent data
exfiltration.
- **Cloud Next-Generation Firewall (NGFW)**: Advanced threat protection for
network traffic.
- **Shared VPC**: Centralized network management across projects.
- **Cloud Interconnect and IPsec VPN**: Secure, private connectivity.
- **Data security**
- **Cloud Key Management Service (KMS)**: Manage encryption keys.
- **Sensitive Data Protection (formerly Cloud DLP)**: Discover and redact
sensitive data.
- **Confidential Computing**: Encrypt data in use (memory).
- **Security operations (SecOps)**
- **Google SecOps (Chronicle)**: Threat detection and security analytics.
- **Security Command Center (SCC)**: Centralized vulnerability and threat
management.
- **Cloud Logging and Cloud Monitoring**: Visibility into system activity.
- **Automation and supply chain**
- **Cloud Build**: Secure CI/CD pipelines.
- **Artifact Analysis**: Vulnerability scanning for container images.
- **Binary Authorization**: Deploy-time policy enforcementTrust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
aa855ad1e58dfull audit observations/trust-audit/skill/davila7__google-cloud-waf-security.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | aa855ad1e58d | SAFE | B | 89 | first audit |
Questions
What does the Google Cloud Waf Security skill do?
CLI tool for configuring and monitoring Claude Code
Is Google Cloud Waf Security safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Google Cloud Waf Security access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (aa855ad1e58d), read on 2026-10-02. The repository is watched, and a new audit runs when it changes — this is the first audit.