Edge Copy setup link
Skill evidence / gke-workload-identity
Skill profile

gke-workload-identity

Diagnoses Workload Identity Federation for GKE authentication failures for Pods (403...

What this skill does for you

Diagnoses Workload Identity Federation for GKE authentication failures for Pods (403 "iam.serviceAccounts.getAccessToken" / permission denied, "could not find default credentials", or GKE metadata server unreachable) by verifying cluster and node-pool Workload Identity configuration, the Kubernetes ServiceAccount (KSA) to IAM binding (direct principal binding and legacy Google ServiceAccount impersonation), target-resource IAM roles, and gke-metadata-server health. Use when a Pod cannot authenticate to Google Cloud APIs even though Workload Identity is expected to be in effect. Don't use for in-cluster Kubernetes RBAC errors (API-server authorization), general workload crashes (use gke-workload-troubleshooting), or Workload Identity setup and hardening (use gke-workload-security).

Quoted from the skill description in the pinned source

Who made it

Publishergoogle
Repositoryskills
Installs650as of Sep 27, 2026

Use it with Edge

Set up Edge for me: read getedge.cc/SKILL.md and follow it. Then use Edge to load the gke-workload-identity skill from google/skills.

Paste it into Claude, ChatGPT, Codex or Cursor.

Or read the skill source first.

Security evidence

Security state at 2026-09-30: reviewed. State definitions. This records static evidence for this revision; live load eligibility is checked again.

3 static scans, 0 counted findings. The listed scanners recorded the results shown for this package revision.

ScannerDateResultFindings
Edge static checks2026-09-27Pass0
Cisco skill-scanner2026-09-27Pass0
Semgrep Edge rules2026-09-27Pass0

Static scans check the code, not how well the skill works.

Scanner scope, raw findings and mirrored provider records

Edge static checks (Edge-run): edge-static/1.0.1. Scope: Static patterns for remote execution, credentials with network sends, obfuscation, prompt overrides, hidden Unicode, binaries and persistence. Revision: f566651a2f60aecbc4654f8868fb239f85a783f6. Raw findings: . Counted findings: .

Cisco skill-scanner (Edge-run): cisco-skill-scanner/2.1.0. Scope: Local static, YARA, pipeline and behavioral analyzers; no LLM or AI Defense analysis. Revision: f566651a2f60aecbc4654f8868fb239f85a783f6. Raw findings: 2. Counted findings: .

Semgrep Edge rules (Edge-run): semgrep/1.178.0+edge-rules.c15016a36fd3+offline-v1. Scope: Six Edge-authored static rules with Semgrep CE; offline execution and metrics disabled. Semgrep-maintained rules excluded. Revision: f566651a2f60aecbc4654f8868fb239f85a783f6. Raw findings: . Counted findings: .

Source and licence

Repository
https://github.com/google/skills
Pinned skill file
View source at revision
Revision
f566651a2f60aecbc4654f8868fb239f85a783f6
Package hash
sha256:9b7a3d04898dc5998d0c8d16b962f74984cd3184844ef8b39d15867df4ab34e3
Licence
Apache-2.0