Security Hardening

adobe/skills/plugins/aem/cloud-service/skills/dispatcher/security-hardening

作者 adobe940b8795c0df3e25de68ce3881dc90855129b215Apache-2.0197 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫今天更新

Perform security audits for the Adobe Dispatcher Apache HTTP Server module and Apache HTTPD in AEMaaCS cloud workflows only, with cloud-specific hardening verification.

僅含說明Security
AI 產生的概覽

針對 AEMaaCS 雲端工作流程中的 Adobe Dispatcher 與 Apache HTTPD 執行有證據支撐的安全稽核與強化驗證。

功能
指導對 Adobe Dispatcher Apache HTTP Server 模組及相關 HTTPD 設定進行僅限雲端環境的安全稽核。它定義威脅模型與範圍,套用 AEMaaCS 雲端防護限制,使用 validate、lint 和 sdk 蒐集基準證據,使用 trace_request 驗證暴露控制,並使用 inspect_cache、tail_logs 和 monitor_metrics 檢查快取與標頭防護。產出包含風險分級發現、證據表、依優先順序排列的修復計畫、所選測試 ID 與結果,以及回復計畫與剩餘風險。
適用情境
適用於稽核或強化 AEMaaCS 雲端部署中的 Dispatcher 與 HTTPD 設定。既適合首次或範圍較廣的稽核,也適合需要記錄證據與修復優先順序的情境式安全審查。
執行需求
需要設定為雲端變體的 Dispatcher MCP(AEM_DEPLOYMENT_MODE=cloud),並提供 validate、lint、sdk、trace_request、inspect_cache、monitor_metrics 和 tail_logs 工具。僅為說明文件,不附帶指令碼。

Dispatcher Security Hardening (Cloud)

Deliver evidence-backed security findings and remediations for cloud workflows that use the Adobe Dispatcher Apache HTTP Server module and related HTTPD configuration.

Variant Scope

  • This skill is cloud-service-only.
  • Scope is fixed by this skill directory; do not ask the user to choose deployment variant.

MCP Tool Contract

Use only these Dispatcher MCP tools:

  • validate
  • lint
  • sdk
  • trace_request
  • inspect_cache
  • monitor_metrics
  • tail_logs

Workflow

  1. Define threat model and audit scope.
  2. Apply cloud guardrails (immutable/default include constraints, reserved probe-path behavior, and CDN-vs-Dispatcher ownership).
  3. Gather baseline evidence (validate, lint, sdk).
  4. Verify exposure controls (trace_request).
  5. Verify cache/header protections (inspect_cache, tail_logs, monitor_metrics).
  6. Return risk-rated findings, prioritized remediation, and rollback.

Verification Scope Selection

Use shared references to select security evidence depth:

  • mode-specific-verification-matrix.md
  • test-case-catalog.md

Output Contract

Always return:

  • scope + threat model assumptions
  • risk-rated findings table
  • evidence table (tool/input/result)
  • prioritized remediation plan
  • selected test IDs and outcomes
  • rollback plan and residual risk

Guardrails

  • Do not downgrade severity without evidence.
  • Do not claim a control is effective without verification evidence.
  • Keep cloud assumptions explicit for each remediation recommendation.
  • Separate mandatory remediations from defense-in-depth guidance.
  • Separate Dispatcher hardening findings from CDN/WAF edge-policy findings.

References

  • security-baseline-checklist.md
  • security-scenario-playbooks.md – scenario-driven security workflows adapted from broader MCP prompt surfaces
  • security-headers-checklist.md
  • sensitive-paths-catalog.md
  • owasp-coverage-matrix.md
  • security-audit-report-template.md
  • quick-start-execution-path.md – single entry path for broad or first-time audits
  • repo-layout-workflows.md – map findings to actual dispatcher file families
  • playbook-command-linkage.md – exact MCP command chains for security playbooks
  • mode-specific-verification-matrix.md
  • cloud-service-aemaacs-guardrails.md – cloud-service-only immutable/include/runtime boundary checks from AEMaaCS patterns
  • test-case-catalog.md
  • change-risk-and-rollback-template.md
  • public-docs-index.md
  • public-doc-citation-rules.md
  • core-7-tools-reference.md

來源與署名

來源:adobe/skills位於plugins/aem/cloud-service/skills/dispatcher/security-hardening提交940b879

授權條款: Apache-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架