Security Hardening

adobe/skills/plugins/aem/6.5-lts/skills/dispatcher/security-hardening

作者 adobe940b8795c0dfApache-2.0197 个星标收录于 2026年10月9日更新于 2026年10月8日仓库今天更新

Perform security audits for the Adobe Dispatcher Apache HTTP Server module and Apache HTTPD in AEM 6.5 / AMS workflows only, with AMS-specific hardening verification.

仅含说明Security
AI 生成的概览

使用 Dispatcher MCP 工具审计并加固 AEM 6.5 AMS 工作流中的 Adobe Dispatcher 与 Apache HTTPD 配置。

功能
指导对 AMS 工作流中 Adobe Dispatcher Apache HTTP Server 模块及相关 HTTPD 配置进行有证据支撑的安全审计。它定义威胁模型与审计范围,收集基线证据,应用 AMS 6.5 防护准则,并验证暴露面、缓存与响应头防护。产出包括风险分级发现、证据表、按优先级排序的修复计划、所选测试 ID 与结果,以及回滚计划和剩余风险。
适用场景
适用于 AEM 6.5 AMS 部署中 Dispatcher 与 HTTPD 配置的安全审计、威胁建模或加固评审。仅面向 AMS 工作流,不覆盖其他部署变体。
运行要求
需要用于 AMS 的 Dispatcher MCP(AEM_DEPLOYMENT_MODE=ams),或已预设为 ams 的 AMS Dispatcher MCP SDK,并提供 validate、lint、sdk、trace_request、inspect_cache、monitor_metrics 和 tail_logs 工具。不附带脚本,仅包含指令与参考文档。

Dispatcher Security Hardening (AMS)

Deliver evidence-backed security findings and remediations for AMS workflows that use the Adobe Dispatcher Apache HTTP Server module and related HTTPD configuration.

Variant Scope

  • This skill is AMS-only.
  • Scope is fixed by this skill directory; do not ask the user to choose deployment variant.

MCP Tool Contract

Use only these Dispatcher MCP tools:

  • validate
  • lint
  • sdk
  • trace_request
  • inspect_cache
  • monitor_metrics
  • tail_logs

Workflow

  1. Define threat model and audit scope.
  2. Gather baseline evidence (validate, lint, sdk).
  3. Apply AMS 6.5 guardrails (tier boundaries, immutable constraints, flush ACL rules) before rating risk.
  4. Verify exposure controls (trace_request).
  5. Verify cache/header protections (inspect_cache, tail_logs, monitor_metrics).
  6. Return risk-rated findings, prioritized remediation, and rollback.

Verification Scope Selection

Use shared references to select security evidence depth:

  • mode-specific-verification-matrix.md
  • test-case-catalog.md

Output Contract

Always return:

  • scope + threat model assumptions
  • risk-rated findings table
  • evidence table (tool/input/result)
  • prioritized remediation plan
  • selected test IDs and outcomes
  • rollback plan and residual risk

Guardrails

  • Do not downgrade severity without evidence.
  • Do not claim a control is effective without verification evidence.
  • Keep AMS assumptions explicit for each remediation recommendation.
  • Separate mandatory remediations from defense-in-depth guidance.

References

  • security-baseline-checklist.md
  • security-scenario-playbooks.md – scenario-driven security workflows adapted from broader MCP prompt surfaces
  • security-headers-checklist.md
  • sensitive-paths-catalog.md
  • owasp-coverage-matrix.md
  • security-audit-report-template.md
  • quick-start-execution-path.md – single entry path for broad or first-time audits
  • repo-layout-workflows.md – map findings to actual dispatcher file families
  • playbook-command-linkage.md – exact MCP command chains for security playbooks
  • ams-6-5-guardrails.md
  • mode-specific-verification-matrix.md
  • test-case-catalog.md
  • change-risk-and-rollback-template.md
  • public-docs-index.md
  • public-doc-citation-rules.md
  • core-7-tools-reference.md

来源与署名

来源:adobe/skills位于plugins/aem/6.5-lts/skills/dispatcher/security-hardening提交940b879

许可证: Apache-2.0

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架