Security Hardening

adobe/skills/plugins/aem/cloud-service/skills/dispatcher/security-hardening

作者 adobe940b8795c0df3e25de68ce3881dc90855129b215Apache-2.0197 个星标收录于 2026年10月9日更新于 2026年10月9日仓库今天更新

Perform security audits for the Adobe Dispatcher Apache HTTP Server module and Apache HTTPD in AEMaaCS cloud workflows only, with cloud-specific hardening verification.

仅含说明Security
AI 生成的概览

针对 AEMaaCS 云工作流中的 Adobe Dispatcher 与 Apache HTTPD 执行有证据支撑的安全审计与加固验证。

功能
指导对 Adobe Dispatcher Apache HTTP Server 模块及相关 HTTPD 配置进行仅限云环境的安全审计。它定义威胁模型与范围,应用 AEMaaCS 云防护约束,使用 validate、lint 和 sdk 收集基线证据,使用 trace_request 验证暴露控制,并使用 inspect_cache、tail_logs 和 monitor_metrics 检查缓存与响应头防护。产出包括风险分级发现、证据表、按优先级排序的修复计划、所选测试 ID 及结果,以及回滚计划和剩余风险。
适用场景
适用于审计或加固 AEMaaCS 云部署中的 Dispatcher 与 HTTPD 配置。既适合首次或范围较广的审计,也适合需要记录证据和修复优先级的场景化安全审查。
运行要求
需要配置为云变体的 Dispatcher MCP(AEM_DEPLOYMENT_MODE=cloud),并提供 validate、lint、sdk、trace_request、inspect_cache、monitor_metrics 和 tail_logs 工具。仅为说明文档,不附带脚本。

Dispatcher Security Hardening (Cloud)

Deliver evidence-backed security findings and remediations for cloud workflows that use the Adobe Dispatcher Apache HTTP Server module and related HTTPD configuration.

Variant Scope

  • This skill is cloud-service-only.
  • Scope is fixed by this skill directory; do not ask the user to choose deployment variant.

MCP Tool Contract

Use only these Dispatcher MCP tools:

  • validate
  • lint
  • sdk
  • trace_request
  • inspect_cache
  • monitor_metrics
  • tail_logs

Workflow

  1. Define threat model and audit scope.
  2. Apply cloud guardrails (immutable/default include constraints, reserved probe-path behavior, and CDN-vs-Dispatcher ownership).
  3. Gather baseline evidence (validate, lint, sdk).
  4. Verify exposure controls (trace_request).
  5. Verify cache/header protections (inspect_cache, tail_logs, monitor_metrics).
  6. Return risk-rated findings, prioritized remediation, and rollback.

Verification Scope Selection

Use shared references to select security evidence depth:

  • mode-specific-verification-matrix.md
  • test-case-catalog.md

Output Contract

Always return:

  • scope + threat model assumptions
  • risk-rated findings table
  • evidence table (tool/input/result)
  • prioritized remediation plan
  • selected test IDs and outcomes
  • rollback plan and residual risk

Guardrails

  • Do not downgrade severity without evidence.
  • Do not claim a control is effective without verification evidence.
  • Keep cloud assumptions explicit for each remediation recommendation.
  • Separate mandatory remediations from defense-in-depth guidance.
  • Separate Dispatcher hardening findings from CDN/WAF edge-policy findings.

References

  • security-baseline-checklist.md
  • security-scenario-playbooks.md – scenario-driven security workflows adapted from broader MCP prompt surfaces
  • security-headers-checklist.md
  • sensitive-paths-catalog.md
  • owasp-coverage-matrix.md
  • security-audit-report-template.md
  • quick-start-execution-path.md – single entry path for broad or first-time audits
  • repo-layout-workflows.md – map findings to actual dispatcher file families
  • playbook-command-linkage.md – exact MCP command chains for security playbooks
  • mode-specific-verification-matrix.md
  • cloud-service-aemaacs-guardrails.md – cloud-service-only immutable/include/runtime boundary checks from AEMaaCS patterns
  • test-case-catalog.md
  • change-risk-and-rollback-template.md
  • public-docs-index.md
  • public-doc-citation-rules.md
  • core-7-tools-reference.md

来源与署名

来源:adobe/skills位于plugins/aem/cloud-service/skills/dispatcher/security-hardening提交940b879

许可证: Apache-2.0

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架