Browse / Security Testing / GCP Project Auditor

GCP Project Auditor

Conducts comprehensive security and compliance audits of Google Cloud Platform projects to identify misconfigurations and excessive permissions.

SkillSecurity TestingComplianceProject ManagementConfig

The source repository doesn't declare a license. Check its terms before reusing the code.

Key features

  • Deep IAM policy analysis and service account impersonation risk detection
  • Standardized markdown audit report generation with severity-ranked findings
  • Automated flagging of excessive roles based on environment tags
  • Comprehensive asset inventory scanning across all GCP resource types
  • Network security review including firewall rules and VPC exposure

Use cases

  • Auditing service account permissions and identifying potential privilege escalation paths
  • Performing a security baseline review of a new or existing GCP project
  • Verifying compliance with internal security policies before promoting code to production

FAQ

When should I use this Claude Code skill?

You should use this skill whenever you need to perform a security review of a GCP project, verify compliance before a production release, scan for service account impersonation risks, or identify unauthenticated access points in Cloud Run or Cloud Functions.

What specific GCP resources can it audit?

It provides deep inspection for BigQuery datasets, Cloud Run services, Cloud Functions, Compute Engine instances (checking for external IPs), Cloud SQL (checking for public IPs), VPC networks, and IAM service account impersonation policies.

How does this skill improve my security workflow?

It automates the tedious process of running multiple gcloud commands and manually auditing JSON outputs. By instantly flagging excessive roles (like Project Owner in production) and generating a severity-ranked markdown report, it allows you to remediate vulnerabilities much faster.

What does the GCP Project Auditor skill do?

This skill acts as an automated security consultant for Google Cloud Platform. It scans your GCP projects to create a resource inventory, analyzes IAM policies for security risks, checks network configurations like firewall rules, and identifies excessive permissions that violate best practices.

Does it support different GCP environment types?

Yes. The skill is designed to recognize environment tags such as 'pd' (production) and 'np' (non-production). It applies stricter auditing logic to production environments, specifically flagging 'excessive roles' that are standard for development but high-risk for production.