Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Generates security-focused guidance for Google Cloud workloads based on the Google Cloud Well-Architected Framework (WAF). Use to evaluate a workload, identify security requirements, and provide actionable recommendations for IAM, network security, data protection, and operational security.
.claude/skills/davila7-google-cloud-waf-security/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-05 | ✗→✓ | ▲ Improved | 149% | 0% |
| case-15 | ✗→✓ | ▲ Improved | 184% | 0% |
| case-17 | ✗→✓ | ▲ Improved | 66% | 0% |
| case-23 | ✗→✓ | ▲ Improved | 117% | 0% |
| case-02 | ✓→✗ | ▼ Worse | 119% | 0% |
The security pillar of the Google Cloud Well-Architected Framework provides design principles and best practices for building a robust security posture by integrating security into every layer of the architecture for cloud workloads. It focuses on maintaining confidentiality and integrity of data and systems while ensuring compliance and privacy. It provides a structured approach to risk management, threat defense, and identity control, enabling you to operate cloud workloads securely and at scale.
The recommendations in the security pillar of the Well-Architected Framework are aligned with the following core principles:
security considerations starting from the initial design phase of your applications and infrastructure. Google Cloud provides architecture blueprints and recommendations to help you apply this principle. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-security-by-design
access to resources is granted based on continuous verification of trust. Google Cloud supports this principle through products like Chrome Enterprise Premium and Identity-Aware Proxy (IAP). Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-zero-trust
software development lifecycle. Avoid security defects before system changes are made. Detect and fix security bugs early, fast, and reliably after the system changes are committed. Google Cloud supports this principle through products like Cloud Build, Binary Authorization, and Artifact Registry. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-shift-left-security
security by implementing robust fundamental measures like threat intelligence. This approach helps you build a foundation for more effective threat detection and response. Google Cloud's approach to layered security controls aligns with this principle. Google Cloud supports this principle through products like Security Command Center, Google Threat Intelligence, and Google SecOps. Grounding document: https://docs.cloud.google.com/architecture/framework/security/implement-preemptive-cyber-defense
responsible and secure manner. The recommendations for this principle are aligned with guidance in the AI and ML perspective of the Well-Architected Framework and in Google's Secure AI Framework (SAIF). Grounding document: https://docs.cloud.google.com/architecture/framework/security/use-ai-securely-and-responsibly
security systems and processes through Gemini in Security and overall platform-security capabilities. Use AI as a tool to increase the automation of remedial work and ensure security hygiene to make other systems more secure. Google Cloud supports this principle through products like Google Threat Intelligence and Google SecOps. Grounding document: https://docs.cloud.google.com/architecture/framework/security/use-ai-for-security
industry-specific regulations, compliance standards, and privacy requirements. Google Cloud helps you meet these obligations through products like Assured Workloads, Organization Policy Service, and our compliance resource center. Grounding document: https://docs.cloud.google.com/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs
The following are _examples_ of Google Cloud products and features that are relevant to security:
Google Cloud resources.
exfiltration.
network traffic.
sensitive data.
management.
Ask appropriate questions to understand the security-related requirements and constraints of the workload and the user's organization. Choose questions from the following list:
planning and design phases?
and services?
lifecycle?
design phase?
the design and development process?
infrastructure?
and stakeholders?
across your environments?
measures?
design?
Cloud resources?
environment?
environment?
activity?
Trust environment?
environment?
your Zero Trust principles?
environment?
practices?
in the process?
best practices?
communicated to developers?
initiatives?
code?
environment?
policies in development?
developers?
before they impact your systems?
analysis?
vulnerabilities?
services?
persistent threats (APTs)?
poisoning?
AI and ML?
models?
use of AI and ML?
systems?
security systems?
infrastructure?
security applications?
purposes?
posture?
adhere to?
environment?
Google Cloud?
regulations?
regulatory and privacy requirements?
regulations?
standards?
privacy requirements?
Use the following checklist to evaluate the architecture's alignment with security recommendations:
hardening?
layers?
vulnerabilities?
location)?
traffic?
(e.g., Terraform)?
dependencies?
appropriate?
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-02 | pass→fail | 13,034 | 12,364 | -5% | 1 | 1 | 0% | 2,247 | 4,911 | +119% | 0 | 0 | — |
case-18 | pass→pass | 17,863 | 16,519 | -8% | 1 | 1 | 0% | 2,938 | 5,693 | +94% | 0 | 0 | — |
case-01 | pass→pass | 17,485 | 10,970 | -37% | 1 | 1 | 0% | 2,844 | 4,776 | +68% | 0 | 0 | — |
case-03 | pass→pass | 17,267 | 11,693 | -32% | 1 | 1 | 0% | 2,797 | 4,804 | +72% | 0 | 0 | — |
case-04 | pass→pass | 14,348 | 10,493 | -27% | 1 | 1 | 0% | 2,396 | 4,795 | +100% | 0 | 0 | — |
case-05 | fail→pass | 15,264 | 8,523 | -44% | 1 | 1 | 0% | 1,787 | 4,448 | +149% | 0 | 0 | — |
case-06 | pass→pass | 11,281 | 8,911 | -21% | 1 | 1 | 0% | 1,914 | 4,483 | +134% | 0 | 0 | — |
case-07 | pass→pass | 7,917 | 7,476 | -6% | 1 | 1 | 0% | 1,111 | 4,126 | +271% | 0 | 0 | — |
case-08 | pass→pass | 4,506 | 4,017 | -11% | 1 | 1 | 0% | 735 | 3,553 | +383% | 0 | 0 | — |
case-09 | pass→pass | 4,456 | 5,550 | +25% | 1 | 1 | 0% | 676 | 3,892 | +476% | 0 | 0 | — |
case-10 | pass→pass | 8,187 | 10,044 | +23% | 1 | 1 | 0% | 1,422 | 4,512 | +217% | 0 | 0 | — |
case-11 | pass→pass | 14,539 | 12,586 | -13% | 1 | 1 | 0% | 2,380 | 4,940 | +108% | 0 | 0 | — |
case-12 | pass→pass | 6,817 | 7,588 | +11% | 1 | 1 | 0% | 1,107 | 4,143 | +274% | 0 | 0 | — |
case-13 | pass→pass | 17,468 | 9,843 | -44% | 1 | 1 | 0% | 2,791 | 4,547 | +63% | 0 | 0 | — |
case-14 | pass→pass | 17,020 | 11,538 | -32% | 1 | 1 | 0% | 2,818 | 4,829 | +71% | 0 | 0 | — |
case-15 | fail→pass | 8,594 | 6,040 | -30% | 1 | 1 | 0% | 1,407 | 3,993 | +184% | 0 | 0 | — |
case-16 | pass→pass | 14,038 | 11,130 | -21% | 1 | 1 | 0% | 2,221 | 4,618 | +108% | 0 | 0 | — |
case-17 | fail→pass | 19,257 | 12,370 | -36% | 1 | 1 | 0% | 3,013 | 5,008 | +66% | 0 | 0 | — |
case-19 | pass→pass | 4,517 | 4,761 | +5% | 1 | 1 | 0% | 682 | 3,743 | +449% | 0 | 0 | — |
case-20 | pass→pass | 4,367 | 4,835 | +11% | 1 | 1 | 0% | 707 | 3,744 | +430% | 0 | 0 | — |
case-21 | pass→pass | 17,453 | 5,743 | -67% | 1 | 1 | 0% | 2,867 | 3,991 | +39% | 0 | 0 | — |
case-22 | fail→fail | 18,342 | 10,886 | -41% | 1 | 1 | 0% | 3,073 | 4,764 | +55% | 0 | 0 | — |
case-23 | fail→pass | 10,170 | 3,693 | -64% | 1 | 1 | 0% | 1,627 | 3,530 | +117% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +13 percentage points is the difference between those two pass rates over the 23 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.