Security Hardening

adobe/skills/plugins/aem/6.5-lts/skills/dispatcher/security-hardening

作者 adobe940b8795c0dfApache-2.0197 個星標收錄於 2026年10月9日更新於 2026年10月8日儲存庫今天更新

Perform security audits for the Adobe Dispatcher Apache HTTP Server module and Apache HTTPD in AEM 6.5 / AMS workflows only, with AMS-specific hardening verification.

僅含說明Security
AI 產生的概覽

使用 Dispatcher MCP 工具稽核並強化 AEM 6.5 AMS 工作流程中的 Adobe Dispatcher 與 Apache HTTPD 設定。

功能
引導對 AMS 工作流程中 Adobe Dispatcher Apache HTTP Server 模組及相關 HTTPD 設定進行有證據佐證的安全稽核。它會定義威脅模型與稽核範圍、蒐集基準證據、套用 AMS 6.5 防護準則,並驗證暴露面、快取與標頭防護。產出包含風險分級發現、證據表、依優先順序排列的修補計畫、所選測試 ID 與結果,以及回復計畫與剩餘風險。
適用情境
適用於 AEM 6.5 AMS 部署中 Dispatcher 與 HTTPD 設定的安全稽核、威脅建模或強化檢視。僅針對 AMS 工作流程,不涵蓋其他部署變體。
執行需求
需要供 AMS 使用的 Dispatcher MCP(AEM_DEPLOYMENT_MODE=ams),或已預設為 ams 的 AMS Dispatcher MCP SDK,並提供 validate、lint、sdk、trace_request、inspect_cache、monitor_metrics 與 tail_logs 工具。不隨附指令碼,僅有指示與參考文件。

Dispatcher Security Hardening (AMS)

Deliver evidence-backed security findings and remediations for AMS workflows that use the Adobe Dispatcher Apache HTTP Server module and related HTTPD configuration.

Variant Scope

  • This skill is AMS-only.
  • Scope is fixed by this skill directory; do not ask the user to choose deployment variant.

MCP Tool Contract

Use only these Dispatcher MCP tools:

  • validate
  • lint
  • sdk
  • trace_request
  • inspect_cache
  • monitor_metrics
  • tail_logs

Workflow

  1. Define threat model and audit scope.
  2. Gather baseline evidence (validate, lint, sdk).
  3. Apply AMS 6.5 guardrails (tier boundaries, immutable constraints, flush ACL rules) before rating risk.
  4. Verify exposure controls (trace_request).
  5. Verify cache/header protections (inspect_cache, tail_logs, monitor_metrics).
  6. Return risk-rated findings, prioritized remediation, and rollback.

Verification Scope Selection

Use shared references to select security evidence depth:

  • mode-specific-verification-matrix.md
  • test-case-catalog.md

Output Contract

Always return:

  • scope + threat model assumptions
  • risk-rated findings table
  • evidence table (tool/input/result)
  • prioritized remediation plan
  • selected test IDs and outcomes
  • rollback plan and residual risk

Guardrails

  • Do not downgrade severity without evidence.
  • Do not claim a control is effective without verification evidence.
  • Keep AMS assumptions explicit for each remediation recommendation.
  • Separate mandatory remediations from defense-in-depth guidance.

References

  • security-baseline-checklist.md
  • security-scenario-playbooks.md – scenario-driven security workflows adapted from broader MCP prompt surfaces
  • security-headers-checklist.md
  • sensitive-paths-catalog.md
  • owasp-coverage-matrix.md
  • security-audit-report-template.md
  • quick-start-execution-path.md – single entry path for broad or first-time audits
  • repo-layout-workflows.md – map findings to actual dispatcher file families
  • playbook-command-linkage.md – exact MCP command chains for security playbooks
  • ams-6-5-guardrails.md
  • mode-specific-verification-matrix.md
  • test-case-catalog.md
  • change-risk-and-rollback-template.md
  • public-docs-index.md
  • public-doc-citation-rules.md
  • core-7-tools-reference.md

來源與署名

來源:adobe/skills位於plugins/aem/6.5-lts/skills/dispatcher/security-hardening提交940b879

授權條款: Apache-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架