Dispatcher Security Hardening (Cloud)
Deliver evidence-backed security findings and remediations for cloud workflows that use the Adobe Dispatcher Apache HTTP Server module and related HTTPD configuration.
Variant Scope
- This skill is cloud-service-only.
- Scope is fixed by this skill directory; do not ask the user to choose deployment variant.
MCP Tool Contract
Use only these Dispatcher MCP tools:
validatelintsdktrace_requestinspect_cachemonitor_metricstail_logs
Workflow
- Define threat model and audit scope.
- Apply cloud guardrails (immutable/default include constraints, reserved probe-path behavior, and CDN-vs-Dispatcher ownership).
- Gather baseline evidence (
validate,lint,sdk). - Verify exposure controls (
trace_request). - Verify cache/header protections (
inspect_cache,tail_logs,monitor_metrics). - Return risk-rated findings, prioritized remediation, and rollback.
Verification Scope Selection
Use shared references to select security evidence depth:
Output Contract
Always return:
- scope + threat model assumptions
- risk-rated findings table
- evidence table (tool/input/result)
- prioritized remediation plan
- selected test IDs and outcomes
- rollback plan and residual risk
Guardrails
- Do not downgrade severity without evidence.
- Do not claim a control is effective without verification evidence.
- Keep cloud assumptions explicit for each remediation recommendation.
- Separate mandatory remediations from defense-in-depth guidance.
- Separate Dispatcher hardening findings from CDN/WAF edge-policy findings.
References
- security-baseline-checklist.md
- security-scenario-playbooks.md – scenario-driven security workflows adapted from broader MCP prompt surfaces
- security-headers-checklist.md
- sensitive-paths-catalog.md
- owasp-coverage-matrix.md
- security-audit-report-template.md
- quick-start-execution-path.md – single entry path for broad or first-time audits
- repo-layout-workflows.md – map findings to actual dispatcher file families
- playbook-command-linkage.md – exact MCP command chains for security playbooks
- mode-specific-verification-matrix.md
- cloud-service-aemaacs-guardrails.md – cloud-service-only immutable/include/runtime boundary checks from AEMaaCS patterns
- test-case-catalog.md
- change-risk-and-rollback-template.md
- public-docs-index.md
- public-doc-citation-rules.md
- core-7-tools-reference.md