skills/cloud/gcp/cloud-iam/SKILL.md
--- name: cloud-iam description: Use when configuring GCP IAM roles, service accounts, org policies, Workload Identity Federation, or least-privilege access. Covers GCP Security Engineer domain: Configuring access (~22-28%) and DevOps domain: Org management (~20%). --- # Cloud IAM ## When to Use - Designing access control for GCP resources - Configuring service accounts and Workload Identity Federation - Setting org policies for compliance - Preparing for GCP Professional Cloud Security or Dev
npx skillsauth add kienbui1995/magic-powers skills/cloud/gcp/cloud-iamInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
| Type | Description | Example | |------|-------------|---------| | Basic | Project-wide: Owner, Editor, Viewer | roles/editor | | Predefined | Service-specific, fine-grained | roles/bigquery.dataViewer | | Custom | User-defined combination of permissions | custom/myRole |
constraints/compute.requireShieldedVm, constraints/iam.disableServiceAccountKeyCreationrequest.time < timestamp, resource.name.startsWith("projects/prod")bigquery.tables.get)roles/owner or roles/editor on service accounts, service account keys committed to codeallUsers / allAuthenticatedUsers = public access; audit carefullycontent-media
Use when designing for XR (AR/VR/MR), choosing interaction modes, or adapting 2D UI patterns for spatial computing
testing
Use when creating new skills, editing existing skills, or verifying skills work before deployment
development
Use when you have a spec or requirements for a multi-step task, before touching code
development
Use when executing a structured workflow — select and run a feature, bugfix, refactor, research, or incident template with correct agent and model assignments per phase.