← ClaudeAtlas

gcp-dispute-kitlisted

Use to assemble a dispute-grade evidence packet and ready-to-file letters after GCP API-key fraud (leaked-key abuse, runaway Gemini/Vertex charges). READ-ONLY — mutates nothing. Triggers on "dispute gcp charges", "google cloud fraud refund", "gemini api fraud dispute", "gcp billing dispute", "chargeback google cloud".
shivamsriva31093/gcp-ironclad · ★ 24 · DevOps & Infrastructure · score 76
Install: claude install-skill shivamsriva31093/gcp-ironclad
# GCP Dispute Kit (READ-ONLY) ## Overview Assembles everything a fraud victim needs to file: an exhibit-backed evidence summary, ready-to-file letters for their situation and jurisdiction (Google + India + US tracks), and a filing-sequence README with a deadline tracker. Formalizes the practice in `docs/incident-story.md`. **Mutates no cloud state.** Three entry states, three different products: | State | Meaning | You get | |---|---|---| | `BLEEDING` | Spend is spiking right now | `checklists/emergency-stop.md` — nothing else until the bleeding stops | | `FRESH` | Incident over, nothing filed | Full packet + Google console-dispute letter (+ India bank-chargeback letter when jurisdiction includes IN — the card-dispute clock runs from the statement date, not from Google's reply) | | `STUCK` | Dispute filed but stalled | Packet + escalation letters (Google reply + IN/US external tracks) | ## When to Use - After a leaked-key incident, once spend is back to normal, to prepare the dispute. - When an existing dispute is stalled: ghosted, partial offer, denied, or a refund that never landed. - NOT while spend is actively spiking — the kit will hand you the emergency-stop checklist and halt. ## Inputs - `SESSION_DIR` env var (optional): defaults to `/tmp/gcp-dispute-kit/$(date -u +%Y-%m-%dT%H-%M-%SZ)/`. - Intake answers from the victim (Phase 0). Everything else is discovered. ## Outputs `${SESSION_DIR}/packet/` — `README.md`, `evidence-summary.md`, `letters/`, `exhibits/`,