gcloud CLI safety guardrails for AI agents (official Google skill)
Mandatory syntax validation via gcloud help, data-reduction rules, and a denylist for destructive/IAM/billing operations
- What
- Mandatory syntax validation via gcloud help, data-reduction rules, and a denylist for destructive/IAM/billing operations
- Cost
- Free
- Needs
- the gcloud CLI installed and authenticated, plus a Google Cloud project (paid platform — check pricing); nothing else to install — the skill is a rulebook your agent follows
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @google's official safety harness for letting AI agents touch the gcloud CLI without hallucinating flags or deleting production: a mandatory pre-condition that treats all prior knowledge of gcloud syntax as stale, so every leaf-level command must first be validated with `gcloud help <leaf_command>` (web search is explicitly forbidden as a syntax source), plus data-reduction rules (never a list without --limit/--filter/--format), execution constraints (single commands, no pipes or chaining, --quiet always, explicit --project and location flags), dry-run discipline, and a denylist blocking autonomous IAM, billing, KMS, org and delete operations. Apache-2.0 licensed. Honest notes: this is a rulebook, not code — it makes your agent careful, not magical; and you still need the gcloud CLI and a Google Cloud project (a paid platform — check pricing) to use it. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: the gcloud CLI installed and authenticated, plus a Google Cloud project (paid platform — check pricing); nothing else to install — the skill is a rulebook your agent follows Install "gcloud CLI safety guardrails for AI agents (official Google skill)" for me. It gives my agent @google's official safety harness for gcloud: mandatory leaf-level syntax validation via gcloud help (never web search), data-reduction rules on every list command, execution constraints (single commands, no pipes or chaining, --quiet, explicit project and location flags), dry-run discipline, and a denylist blocking autonomous IAM/billing/KMS/org/delete operations. Apache-2.0 licensed. Repository: https://github.com/google/skills/blob/main/plugins/cloud/google-cloud-developer/skills/gcloud/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "gcloud". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install and authenticate the gcloud CLI, set my project ID). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.