
GCP Infrastructure Audit & Optimization
Audit GCP projects for security, cost & performance—then generate optimization code
What You Can Do
You provide your GCP project configuration, and this skill systematically identifies security misconfigurations, unused resources, performance bottlenecks, and compliance gaps. It then generates a prioritized action plan with runnable Terraform or gcloud CLI code to fix each issue, saving you weeks of manual analysis and remediation work.
Features
Scans IAM policies, firewall rules, encryption, and access controls; flags OWASP and CIS compliance violations
Identifies unused compute instances, over-provisioned resources, and suboptimal pricing models; quantifies monthly savings potential
Analyzes CPU, memory, disk I/O, and network latency across Compute Engine, Cloud SQL, and Cloud Storage
Ranks findings by risk severity and implementation effort; suggests quick wins vs. strategic improvements
Produces ready-to-run Terraform modules and gcloud commands for each fix
Audits entire GCP organization, Folders, or specific projects in a single run
Tests against CIS GCP Foundations Benchmark and NIST controls
Quantifies risk scores, estimated cost savings, and performance gains
Example Output
Security Finding:
- ❌ CRITICAL: Default VPC with unrestricted SSH access
Location: us-central1 firewall rule 'default-allow-ssh'
Risk: Exposure to brute-force attacks
Fix (Terraform):
resource "google_compute_firewall" "restrict_ssh" {
name = "restrict-ssh"
network = "default"
allow { protocol = "tcp"; ports = ["22"] }
source_ranges = ["203.0.113.0/24"] # Your office IP
}
Cost Finding:
- 💰 HIGH: 4 Compute Engine instances (us-central1-a) using e2-standard-4, but metrics show <10% avg CPU
Current cost: $600/month
Recommendation: Downsize to e2-standard-2
Monthly savings: $300 (50% reduction)
Implementation: gcloud compute instances stop [INSTANCE] && gcloud compute instances change-machine-type [INSTANCE] --machine-type=e2-standard-2
Performance Finding:
- ⚡ MEDIUM: Cloud SQL (mysql-prod) connection pool exhaustion every morning 9-11 AM
Current: max_connections=100, avg concurrent=95
Recommendation: Increase to 150; add connection pooling (Cloud SQL Proxy)
Expected impact: Eliminate 95th percentile query latency spikes (+500ms)
What's Included
- SKILL.md: Complete audit workflows, decision trees, and remediation templates
- GCP scanning module: Automated project inventory collection via gcloud CLI or Terraform state
- Security assessment checklist: CIS GCP Foundations Benchmark verification
- Cost analysis formulas: Monthly spend projections and rightsizing logic
- Remediation code templates: Terraform modules and gcloud scripts for common fixes
- Report generator: Markdown/HTML audit report with findings, priorities, and ROI estimates
- Interactive remediation prompt: Step-by-step guidance to implement specific fixes
Who It's For
- Cloud architects and infrastructure engineers — plan and execute GCP platform optimization
- DevOps/SRE teams — reduce operational overhead and cost drift across production environments
- Security and compliance officers — validate architecture against industry frameworks (CIS, NIST, SOC 2)
- FinOps/cost optimization specialists — identify and quantify savings opportunities for budget forecasting
- Startup CTOs — audit inherited or legacy GCP setups to find quick wins before scaling
Best For
- Security posture assessments and compliance audits (CIS, NIST, FedRAMP, PCI-DSS readiness)
- Post-acquisition or platform consolidation audits (multi-project organizations)
- FinOps initiatives — quantifying and implementing cost reduction targets
- Performance baselines and capacity planning — forecasting growth and resource needs
- Incident prevention — proactive detection of misconfigurations that could cause outages







