All skills
google avatar

/bigquery-basics

@becc4b8
by googlegoogle/skills21k stars
1,698

Manages datasets, tables, and jobs in BigQuery. Use when you need to interact with BigQuery, run SQL queries, manage BigQuery resources (datasets, tables, views), or perform basic data ingestion and analysis.

Use this Skill: https://skilld.dev/gh/google/skills/bigquery-basics

This session only. Nothing lands on disk.

referencesiam-security.md

≈495 tokens on demand. Your agent reads this file only when SKILL.md points to it.

BigQuery IAM & Security

BigQuery uses Identity and Access Management (IAM) to provide granular access control to its resources. As a security best practice, follow the principle of least privilege: grant only the permissions required to perform a specific action. This includes using the least permissive IAM role at the most granular level—such as the table or view level—that is necessary.

Predefined IAM Roles

For a complete list of predefined roles and detailed usage information, see BigQuery IAM roles.

Service Accounts and Agents

  • Default Service Account: BigQuery uses a managed service account (bq-PROJECT_NUMBER@bigquery-encryption.iam.gserviceaccount.com or the more general BigQuery Service Agent service-PROJECT_NUMBER@gcp-sa-bigquery.iam.gserviceaccount.com) for internal operations.

  • Service Account Impersonation: Use gcloud config set auth/impersonate_service_account for secure, temporary credential access.

Data Security

  • Encryption at Rest: All data is encrypted by default using Google-managed keys. Use Customer-Managed Encryption Keys (CMEK) for greater control.

  • VPC Service Controls: Define a service perimeter to prevent data exfiltration.

  • Column-Level Security: Use policy tags to restrict access to sensitive columns.

  • Row-Level Security: Use row access policies to filter data based on user identity.

  • Data Masking: Obscure sensitive data in a table while still permitting authorized users to access surrounding data.

  • Audit Logs: Record user activity and system events to enforce data governance policies and identify potential security risks.

  • Authorized Views: Allow users to query a view without granting them access to the underlying tables.

For more detailed information, see: BigQuery Security Overview.

Source: SKILL.md on GitHub

No alerts10d3 checks · Risk SAFE
  • Gen Agent Trust Hub10d

    This skill provides comprehensive guidance for managing Google BigQuery resources, including CLI usage, client libraries, and infrastructure as code. It implements standard vendor practices for command attribution and emphasizes security best practices such as the principle of least privilege. No security issues were detected.

  • Socket10d

    No alerts

  • Snyk10d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
metadata
{
  "version": "1.0.0",
  "category": "BigDataAndAnalytics"
}

README badge

README badge for google/skills/bigquery-basics