Security Hardening

adobe/skills/plugins/aem/6.5-lts/skills/dispatcher/security-hardening

by adobe940b8795c0dfApache-2.0197 starsListed Oct 9, 2026Updated Oct 8, 2026Repository updated today

Perform security audits for the Adobe Dispatcher Apache HTTP Server module and Apache HTTPD in AEM 6.5 / AMS workflows only, with AMS-specific hardening verification.

Instructions onlySecurity
AI-generated overview

Audits and hardens Adobe Dispatcher and Apache HTTPD configurations in AEM 6.5 AMS workflows using Dispatcher MCP tools.

What it does
Guides an evidence-backed security audit of the Adobe Dispatcher Apache HTTP Server module and related HTTPD configuration in AMS workflows. It defines a threat model and scope, gathers baseline evidence, applies AMS 6.5 guardrails, and verifies exposure, cache and header protections. It produces risk-rated findings, an evidence table, a prioritized remediation plan, selected test IDs and outcomes, plus a rollback plan and residual risk.
When to use it
Use it for security audits, threat modelling or hardening reviews of Dispatcher and HTTPD configuration in AEM 6.5 AMS deployments. It is intended for AMS-only workflows and does not cover other deployment variants.
Requirements
Requires the Dispatcher MCP for AMS with AEM_DEPLOYMENT_MODE=ams, or the AMS Dispatcher MCP SDK pre-set to ams, exposing the tools validate, lint, sdk, trace_request, inspect_cache, monitor_metrics and tail_logs. Ships no scripts; it is instructions plus reference documents.

Dispatcher Security Hardening (AMS)

Deliver evidence-backed security findings and remediations for AMS workflows that use the Adobe Dispatcher Apache HTTP Server module and related HTTPD configuration.

Variant Scope

  • This skill is AMS-only.
  • Scope is fixed by this skill directory; do not ask the user to choose deployment variant.

MCP Tool Contract

Use only these Dispatcher MCP tools:

  • validate
  • lint
  • sdk
  • trace_request
  • inspect_cache
  • monitor_metrics
  • tail_logs

Workflow

  1. Define threat model and audit scope.
  2. Gather baseline evidence (validate, lint, sdk).
  3. Apply AMS 6.5 guardrails (tier boundaries, immutable constraints, flush ACL rules) before rating risk.
  4. Verify exposure controls (trace_request).
  5. Verify cache/header protections (inspect_cache, tail_logs, monitor_metrics).
  6. Return risk-rated findings, prioritized remediation, and rollback.

Verification Scope Selection

Use shared references to select security evidence depth:

  • mode-specific-verification-matrix.md
  • test-case-catalog.md

Output Contract

Always return:

  • scope + threat model assumptions
  • risk-rated findings table
  • evidence table (tool/input/result)
  • prioritized remediation plan
  • selected test IDs and outcomes
  • rollback plan and residual risk

Guardrails

  • Do not downgrade severity without evidence.
  • Do not claim a control is effective without verification evidence.
  • Keep AMS assumptions explicit for each remediation recommendation.
  • Separate mandatory remediations from defense-in-depth guidance.

References

  • security-baseline-checklist.md
  • security-scenario-playbooks.md – scenario-driven security workflows adapted from broader MCP prompt surfaces
  • security-headers-checklist.md
  • sensitive-paths-catalog.md
  • owasp-coverage-matrix.md
  • security-audit-report-template.md
  • quick-start-execution-path.md – single entry path for broad or first-time audits
  • repo-layout-workflows.md – map findings to actual dispatcher file families
  • playbook-command-linkage.md – exact MCP command chains for security playbooks
  • ams-6-5-guardrails.md
  • mode-specific-verification-matrix.md
  • test-case-catalog.md
  • change-risk-and-rollback-template.md
  • public-docs-index.md
  • public-doc-citation-rules.md
  • core-7-tools-reference.md

Source and attribution

Source:adobe/skillsinplugins/aem/6.5-lts/skills/dispatcher/security-hardeningat commit940b879

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal