Security Hardening

adobe/skills/plugins/aem/cloud-service/skills/dispatcher/security-hardening

by adobe940b8795c0df3e25de68ce3881dc90855129b215Apache-2.0197 starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated today

Perform security audits for the Adobe Dispatcher Apache HTTP Server module and Apache HTTPD in AEMaaCS cloud workflows only, with cloud-specific hardening verification.

Instructions onlySecurity
AI-generated overview

Performs evidence-backed security audits and hardening verification for Adobe Dispatcher and Apache HTTPD in AEMaaCS cloud workflows.

What it does
Guides a cloud-only security audit of the Adobe Dispatcher Apache HTTP Server module and related HTTPD configuration. It defines a threat model and scope, applies AEMaaCS cloud guardrails, gathers baseline evidence with validate, lint and sdk, verifies exposure controls with trace_request, and checks cache and header protections with inspect_cache, tail_logs and monitor_metrics. It produces risk-rated findings, an evidence table, a prioritized remediation plan, selected test IDs and outcomes, and a rollback plan with residual risk.
When to use it
Use it when auditing or hardening Dispatcher and HTTPD configuration in AEMaaCS cloud deployments. It suits first-time or broad audits as well as scenario-driven security reviews that need documented evidence and remediation priorities.
Requirements
Requires a Dispatcher MCP configured for the cloud variant (AEM_DEPLOYMENT_MODE=cloud) exposing the tools validate, lint, sdk, trace_request, inspect_cache, monitor_metrics and tail_logs. Instructions only; no scripts are shipped.

Dispatcher Security Hardening (Cloud)

Deliver evidence-backed security findings and remediations for cloud workflows that use the Adobe Dispatcher Apache HTTP Server module and related HTTPD configuration.

Variant Scope

  • This skill is cloud-service-only.
  • Scope is fixed by this skill directory; do not ask the user to choose deployment variant.

MCP Tool Contract

Use only these Dispatcher MCP tools:

  • validate
  • lint
  • sdk
  • trace_request
  • inspect_cache
  • monitor_metrics
  • tail_logs

Workflow

  1. Define threat model and audit scope.
  2. Apply cloud guardrails (immutable/default include constraints, reserved probe-path behavior, and CDN-vs-Dispatcher ownership).
  3. Gather baseline evidence (validate, lint, sdk).
  4. Verify exposure controls (trace_request).
  5. Verify cache/header protections (inspect_cache, tail_logs, monitor_metrics).
  6. Return risk-rated findings, prioritized remediation, and rollback.

Verification Scope Selection

Use shared references to select security evidence depth:

  • mode-specific-verification-matrix.md
  • test-case-catalog.md

Output Contract

Always return:

  • scope + threat model assumptions
  • risk-rated findings table
  • evidence table (tool/input/result)
  • prioritized remediation plan
  • selected test IDs and outcomes
  • rollback plan and residual risk

Guardrails

  • Do not downgrade severity without evidence.
  • Do not claim a control is effective without verification evidence.
  • Keep cloud assumptions explicit for each remediation recommendation.
  • Separate mandatory remediations from defense-in-depth guidance.
  • Separate Dispatcher hardening findings from CDN/WAF edge-policy findings.

References

  • security-baseline-checklist.md
  • security-scenario-playbooks.md – scenario-driven security workflows adapted from broader MCP prompt surfaces
  • security-headers-checklist.md
  • sensitive-paths-catalog.md
  • owasp-coverage-matrix.md
  • security-audit-report-template.md
  • quick-start-execution-path.md – single entry path for broad or first-time audits
  • repo-layout-workflows.md – map findings to actual dispatcher file families
  • playbook-command-linkage.md – exact MCP command chains for security playbooks
  • mode-specific-verification-matrix.md
  • cloud-service-aemaacs-guardrails.md – cloud-service-only immutable/include/runtime boundary checks from AEMaaCS patterns
  • test-case-catalog.md
  • change-risk-and-rollback-template.md
  • public-docs-index.md
  • public-doc-citation-rules.md
  • core-7-tools-reference.md

Source and attribution

Source:adobe/skillsinplugins/aem/cloud-service/skills/dispatcher/security-hardeningat commit940b879

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal