alibabacloud-waf-report

Installation
SKILL.md

Alibaba Cloud WAF Security Operations Report

Produce an evidence-based WAF security operations report or focused assessment. Separate observed facts, technical inferences, and unverified assumptions. Optimize protection effectiveness and business accuracy rather than maximizing block volume.

Scope and authorization

Inspect the material already provided and ask only for missing inputs that affect execution:

  • Customer name, report type, assessment interval, and time zone
  • Alibaba Cloud region, WAF instance ID, SLS project, and logstore
  • An existing authenticated aliyun CLI context or offline exports
  • Main domains, sensitive business flows, trusted sources, partner callbacks, and approved test sources
  • Known false positives, known false negatives, recent changes, and requested output format
  • Authorization scope for read-only cloud queries and public endpoint verification

Use only the aliyun CLI default credential chain or an already configured profile. Never request, inspect, print, persist, transform, or pass AccessKey credentials. Redact cookies, tokens, AccessKeys, phone numbers, government identifiers, and other sensitive values from artifacts.

Default to read-only collection and analysis. Changing WAF rules, allowlists, blocklists, BOT policies, or logging settings is a separate write operation and requires explicit user approval for the exact change.

Installs
1
GitHub Stars
249
First Seen
Aug 27, 2026
alibabacloud-waf-report — aliyun/alibabacloud-aiops-skills