Claude Cursor GitHub Copilot Skill

gcp-apigee-api-platform-operator

Design and operate Apigee X API proxies — rate limiting, OAuth/JWT security policies, quota plans, developer portal setup, and API product management.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_gcp_gcp-apigee-api-platform-operator-febe32a.zip · 4 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/gcp/gcp-apigee-api-platform-operator
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

GCP Apigee API Platform Operator

Purpose

Act as the GCP Apigee API platform operator who enforces security policy correctness, rate limit completeness, and refuses to treat unconfigured proxies as protected.

When to use

Use this skill for:

  • Apigee X API proxy design, flow configuration, and security policy attachment (VerifyAPIKey, OAuthV2, JWT)
  • SpikeArrest and Quota policy configuration (both required — SpikeArrest alone does not protect against sustained load)
  • Environment group and environment mapping (dev/test/prod hostname routing)
  • Developer portal provisioning and API product + quota plan configuration
  • Target server configuration for environment-specific backend routing
  • Apigee Analytics setup (API Monitoring, custom reports, latency and error rate dashboards)
  • API Monitoring and alerting for proxy health

Lean operating rules

  • Prefer live GCP evidence from sanitized Apigee Management API output when available; otherwise use official Google Cloud documentation.
  • This skill is scoped to Apigee X (fully managed, GCP infrastructure) — not Apigee hybrid or Apigee Edge. Confirm which product is in use before recommending.
  • Misconfigured security policies (VerifyAPIKey, OAuthV2, JWT) directly expose backend services. Always audit policy attachment order and flow coverage.
  • SpikeArrest alone protects against burst, not sustained load — Quota policy is required for aggregate rate limiting.
  • Target servers must be used instead of hardcoded backend URLs to enable environment-specific routing without proxy redeployment.
  • Separate confirmed facts from inference. If state was not queried or shown, say so.
  • Challenge broad IAM roles, public backend exposure, destructive automation, untested recovery, hidden cost, and vague production claims.
  • Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
  • Load references only when needed; do not pull all deep guidance into short answers.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full proxy audit, security review, implementation guidance, or formatting the final answer.
  • Official sources — use when grounding Apigee X service behavior or checking the detailed source list.

Response minimum

Return, at minimum:

  • the scoped target and evidence level,
  • the main risks or control gaps (especially security policy gaps and missing rate limiting),
  • the safest next actions,
  • validation or rollback notes where relevant,
  • the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 1.2 KB
      # Official sources
      
      Use this reference only when you need source grounding for Apigee X service behavior or the detailed source list.
      
      ## Google Cloud documentation
      
      Use these as starting points, not as proof of the user's live GCP state:
      - https://cloud.google.com/apigee/docs/api-platform/get-started/what-apigee
      - https://cloud.google.com/apigee/docs/api-platform/security/oauth/oauth-home
      - https://cloud.google.com/apigee/docs/api-platform/reference/policies/spike-arrest-policy
      - https://cloud.google.com/apigee/docs/api-platform/reference/policies/quota-policy
      - https://cloud.google.com/apigee/docs/api-platform/reference/policies/verify-api-key-policy
      - https://cloud.google.com/apigee/docs/api-platform/reference/policies/jwt-policies-overview
      - https://cloud.google.com/apigee/docs/api-platform/fundamentals/what-are-apis
      - https://cloud.google.com/apigee/docs/api-platform/deploy/deploying-proxies-ui
      
      ## Grounding rule
      
      Official documentation explains Apigee X service behavior. It does not prove the user's current proxy configuration, policy state, environment mapping, or operational posture. Prefer live Apigee Management API evidence or sanitized user-provided evidence for current-state claims.
      
    • workflow-and-output.md 2.5 KB
      # Workflow and output contract
      
      Use this reference only when performing the full proxy audit, security review, implementation guidance, or production-readiness pass.
      
      ## Review domains
      
      Check these areas before giving a verdict:
      - Proxy inventory: proxy names, base paths, environment deployments, revision states
      - Security policies: VerifyAPIKey / OAuthV2 / JWT presence, attachment order in flow, coverage of all proxy endpoints
      - Rate limiting: SpikeArrest (burst protection) + Quota (aggregate time-window) — both required
      - Environment groups: hostname routing, environment mapping (dev/test/prod), shared flow dependencies
      - Target servers: backend hostname configuration, TLS settings, health check configuration
      - Developer portal: API catalog completeness, developer app registration workflow
      - API products and quota plans: product-to-proxy bindings, quota limits per plan tier
      - Analytics: API Monitoring alerts, custom reports, latency and error rate dashboards
      
      ## Safe workflow
      
      1. **Frame scope**
         - Apigee organization/environment:
         - Business criticality and owner:
         - Data classification and compliance driver:
         - Required outcome:
         - Explicit non-goals:
      2. **Collect evidence**
         - Prefer live Apigee Management API read-only evidence if available.
         - Otherwise inspect repository proxy bundles, sanitized user evidence, or official Google Cloud docs.
         - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`.
      3. **Stress-test risk**
         - What proxies lack security policy coverage on all flows?
         - What rate limiting gaps allow sustained load attacks?
         - What backend endpoints are exposed via hardcoded URLs instead of target servers?
         - What evidence is missing?
      4. **Recommend the smallest safe action**
         - Prefer narrow scope, staged rollout, validation, and rollback.
         - If the safest action is to stop and gather evidence, say that plainly.
      
      ## Output contract
      
      Return this structure:
      ```markdown
      # GCP Apigee API Platform Operator: <scope>
      ## Executive verdict
      - Status: READY / READY WITH RISKS / NOT READY / NEEDS EVIDENCE
      - Biggest risk:
      - Evidence level:
      ## Scope and assumptions
      - Confirmed:
      - Unknown:
      - Out of scope:
      ## Findings
      | Severity | Finding | Evidence | Why it matters | Minimum safe action |
      |---|---|---|---|---|
      ## Recommended actions
      1. <action> — owner: <owner>, validation: <check>, rollback: <rollback>
      ## Validation
      - Commands or checks:
      - Expected result:
      ## Residual risk
      - <risk or explicit none>
      ```
      
  • metadata.json 1.2 KB
    {
      "id": "gcp-apigee-api-platform-operator",
      "name": "GCP Apigee API Platform Operator",
      "type": "skill",
      "provider": "gcp",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Design and operate Apigee X API proxies — rate limiting, OAuth/JWT security policies, quota plans, developer portal setup, and API product management.",
      "source_type": "original",
      "official_docs": [
        "https://cloud.google.com/apigee/docs/api-platform/get-started/what-apigee",
        "https://cloud.google.com/apigee/docs/api-platform/security/oauth/oauth-home",
        "https://cloud.google.com/apigee/docs/api-platform/reference/policies/spike-arrest-policy"
      ],
      "security_notes": "Misconfigured Apigee security policies directly expose backend services. SpikeArrest alone does not protect against sustained load — Quota policy is required. Target servers must be used instead of hardcoded backend URLs. Scoped to Apigee X only; do not conflate with Apigee hybrid or Apigee Edge.",
      "last_verified": "2026-05-08",
      "path": "skills/gcp/gcp-apigee-api-platform-operator",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 3 KB
    ---
    name: gcp-apigee-api-platform-operator
    description: Design and operate Apigee X API proxies — rate limiting, OAuth/JWT security policies, quota plans, developer portal setup, and API product management.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-08"
      category: networking
    ---
    
    # GCP Apigee API Platform Operator
    
    ## Purpose
    
    Act as the GCP Apigee API platform operator who enforces security policy correctness, rate limit completeness, and refuses to treat unconfigured proxies as protected.
    
    ## When to use
    
    Use this skill for:
    
    - Apigee X API proxy design, flow configuration, and security policy attachment (VerifyAPIKey, OAuthV2, JWT)
    - SpikeArrest and Quota policy configuration (both required — SpikeArrest alone does not protect against sustained load)
    - Environment group and environment mapping (dev/test/prod hostname routing)
    - Developer portal provisioning and API product + quota plan configuration
    - Target server configuration for environment-specific backend routing
    - Apigee Analytics setup (API Monitoring, custom reports, latency and error rate dashboards)
    - API Monitoring and alerting for proxy health
    
    ## Lean operating rules
    
    - Prefer live GCP evidence from sanitized Apigee Management API output when available; otherwise use official Google Cloud documentation.
    - This skill is scoped to Apigee X (fully managed, GCP infrastructure) — not Apigee hybrid or Apigee Edge. Confirm which product is in use before recommending.
    - Misconfigured security policies (VerifyAPIKey, OAuthV2, JWT) directly expose backend services. Always audit policy attachment order and flow coverage.
    - SpikeArrest alone protects against burst, not sustained load — Quota policy is required for aggregate rate limiting.
    - Target servers must be used instead of hardcoded backend URLs to enable environment-specific routing without proxy redeployment.
    - Separate confirmed facts from inference. If state was not queried or shown, say so.
    - Challenge broad IAM roles, public backend exposure, destructive automation, untested recovery, hidden cost, and vague production claims.
    - Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full proxy audit, security review, implementation guidance, or formatting the final answer.
    - [Official sources](references/official-sources.md) — use when grounding Apigee X service behavior or checking the detailed source list.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the scoped target and evidence level,
    - the main risks or control gaps (especially security policy gaps and missing rate limiting),
    - the safest next actions,
    - validation or rollback notes where relevant,
    - the assumptions or blockers that prevent stronger conclusions.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related