一键导入
aem-security
AEM security review — admin resolver, query injection, path validation, exposed endpoints, hardcoded secrets
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
AEM security review — admin resolver, query injection, path validation, exposed endpoints, hardcoded secrets
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
| name | aem-security |
| description | AEM security review — admin resolver, query injection, path validation, exposed endpoints, hardcoded secrets |
| allowed-tools | Read, Grep, Glob |
| argument-hint | [file or class path] |
Review $ARGUMENTS for AEM security issues. Report each finding as Blocking / Warning / Suggestion.
loginAdministrative usage — Blocking; replace with service userAEM accessibility review — WCAG 2.1 AA compliance in HTL templates, Coral UI dialogs, and frontend components
Cloud Manager and OakPAL review — package filters, embed order, Dispatcher SDK, deployment safety
AEM headless review — Content Fragment models, GraphQL persisted queries, CF Java integration, CORS, and Dispatcher rules for headless delivery
Oak index review and creation — index type selection, property coverage, evaluatePathRestrictions, async configuration
AEM performance review — JCR queries, traversal, resolver lifecycle, PostConstruct overhead
Always-loaded AEM project conventions — naming patterns, package structure, utility library usage, and team-specific standards that Claude applies silently on every task