Enforcing Resource Attribution

by gemini-cli-extensions2df10e25bbf7Apache-2.0215 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Enforces resource attribution for CLI commands. Use this skill whenever you are running `bq` or `gcloud` commands via `run_command`. It ensures mandatory labeling for supported `bq` operations while avoiding invalid flags on read-only commands.

Instructions only

Resource Attribution Enforcement

To track resources created or manipulated by AI agents, you MUST ensure that standard CLI commands are tagged with appropriate attribution labels under relevant conditions.

Applicability

You should apply these attribution labels ONLY under the following conditions:

  1. DAK Tooling: You are executing Python scripts, running MCP tools, or following workflows provided by the Data Agent Kit.
  2. Domain Relevance: You are operating on BigQuery datasets, GCS buckets, or Analytics infrastructure (including Spark, Dataproc, or Serverless Spark) intended for data preparation, deduplication, or analysis.

🚫 When to Omit

Do NOT apply these labels if you are running generic administrative commands or working on infrastructure completely unrelated to Data Cloud / Analytics (e.g., managing Compute Engines for web apps, setting up standard IAM policies, etc.).

Do NOT apply --label flags to commands that do not accept labels, as the --label flag is unsupported by these specific bq subcommands. These include:

  • bq show
  • bq ls
  • bq version
  • bq rm
  • bq cancel
  • bq head

BigQuery CLI (bq)

You MUST apply --label key:value ONLY to subcommands that accept job or resource labels (bq query, bq load, bq extract, bq mk, bq update, and bq cp).

  • Flag Form: --label key:value
  • Mandatory Label: datacloud:<ide>
  • Deduction Rule: Substitute <ide> with your actual environment/client (e.g., vscode, jetski, antigravity, codex, cursor, cloud-shell, workstation, gemini-cli, claude).
    • Use cloud-shell for GCP Cloud Shell.
    • Use workstation for GCP Cloud Workstations. If you cannot determine your environment, use ai-agent. Note that BigQuery labels cannot contain dots or spaces.

Examples

Query Example

Incorrect:

bash
bq query --use_legacy_sql=false "SELECT 1"

Correct (assuming you are running in VS Code):

bash
bq query --use_legacy_sql=false --label datacloud:vscode "SELECT 1"
Copy Example

Incorrect:

bash
bq cp dataset1.table1 dataset2.table1_copy

Correct (assuming you are running in Jetski):

bash
bq cp --label datacloud:jetski dataset1.table1 dataset2.table1_copy

Google Cloud SDK (gcloud)

Whenever you execute any gcloud command via run_command, you MUST prepend the command with the CLOUDSDK_METRICS_ENVIRONMENT environment variable to ensure proper resource attribution.

  • Environment Variable: prepend commands using the append form. It keeps any attribution another tool or skill already set on the same variable and adds the DAK tag after it, so both values reach the metrics pipeline:

    bash
    CLOUDSDK_METRICS_ENVIRONMENT="${CLOUDSDK_METRICS_ENVIRONMENT:+$CLOUDSDK_METRICS_ENVIRONMENT }datacloud.<ide>"
  • Deduction Rule: Substitute <ide> with your actual environment/client (e.g., vscode, jetski, antigravity, codex, cursor, cloud-shell, workstation, gemini-cli, claude).

    • Use cloud-shell for GCP Cloud Shell.
    • Use workstation for GCP Cloud Workstations. If you cannot determine your environment, use ai-agent. Note that values must use dots (e.g., datacloud.vscode), not colons.

Examples

Incorrect:

bash
gcloud compute disks create my-disk --size=10GB

Correct (assuming you are running in VS Code):

bash
CLOUDSDK_METRICS_ENVIRONMENT="${CLOUDSDK_METRICS_ENVIRONMENT:+$CLOUDSDK_METRICS_ENVIRONMENT }datacloud.vscode" gcloud compute disks create my-disk --size=10GB

[!IMPORTANT]

This applies to ALL gcloud commands, whether they are read-only (gcloud ... list) or mutations (gcloud ... create).

Source and attribution

Source:gemini-cli-extensions/data-agent-kit-starter-packinskills/enforcing-resource-attributionat commit2df10e2

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from gemini-cli-extensions/data-agent-kit-starter-pack

Schema Mapping

gemini-cli-extensions

Plans source-to-target schema mappings for ETL, ELT, or data integration work, producing a documented Mapping Manifesto.

Data & Analytics215updated today

Resolving Mcp Region Configs

gemini-cli-extensions

Fixes unreplaced region placeholders in regional Google Cloud MCP server configs so missing MCP tools register.

DevOps & Cloud215updated today

Notebook Guidance

gemini-cli-extensions

This skill guides the use of Jupyter notebooks for data analysis, exploration, and visualization, particularly with BigQuery. It outlines best practices for notebook execution and validation (supporting both cell-by-cell execution and full notebook generation depending on tool availability), library installation, and structuring notebooks for clarity. It also covers specific rules for data cleaning, plotting, and integrating with BigQuery SQL and machine learning workflows. Relevant when any of the following conditions are true: 1. The user request involves a data analysis, data exploration, data visualization, or data insights task that requires multiple steps, queries, or visualizations to answer. 2. The user explicitly requests a notebook (.ipynb). 3. You are creating, editing, or executing cells in a Jupyter notebook. 4. You need to query BigQuery from within a notebook. DO NOT use the Python BigQuery client library; instead, you MUST use the `%%bqsql` magics explained in this skill.

Awaiting classification215updated today

Ml Best Practices

gemini-cli-extensions

Guides machine learning notebooks with step-by-step plans for clustering, forecasting, classification, regression and model comparison.

Data & Analytics215updated today

Managing Python Dependencies

gemini-cli-extensions

Guides agents to detect a Python project's dependency manager and install packages correctly instead of using global pip.

Software Development215updated today

Google Cloud Storage Fuse

gemini-cli-extensions

Mounts Cloud Storage buckets as a POSIX file system with Cloud Storage FUSE (gcsfuse). Use when you need to interact with gcsfuse — decide whether FUSE, native gs:// reads, or Filestore/Managed Lustre fits a workload, deploy tuned mounts on GKE, Compute Engine, or Cloud Run, enable and size the file, stat, and list caches, tune mount flags or config-file settings, apply workload profiles, keep ML checkpointing safe (rename atomicity, hierarchical namespace, close-time finalization, concurrent writers), or diagnose slow training, low throughput, or GCS bill spikes on existing mounts with gcsfuse metrics. Covers mount semantics, the gcsfuse CLI and config file, the GKE gcsfuse CSI driver (Workload Identity principal:// bindings, profile StorageClasses, sidecar sizing), and Cloud Run volume mounts. Don't use for bucket administration or data management without a mount (google-cloud-storage-basics) or for fully POSIX-compliant shared file systems (Filestore, Managed Lustre).

Awaiting classification215updated today