Agent skill · aliyun
alibabacloud-waf-report
Generate or review Alibaba Cloud WAF 3.0 security operations reports, customer assessments, rule-tuning reports, and focused false-positive or false-negative investigations using WAF OpenAPI, SLS traffic logs, authorized read-only verification, or user-supplied offline WAF samples and exports. Use for WAF monthly reports, security patrols, API Security reviews, BOT analysis, and OWASP API Security Top 10 coverage. Do not use for unauthorized testing or direct production rule changes.
What it needs
About 6k tokens when loaded.
What this skill does
Alibaba Cloud WAF Security Operations Report Produce an evidence-based WAF security operations report or focused assessment. Separate observed facts, technical inferences, and unverified assumptions. Optimize protection effectiveness and business accuracy rather than maximizing block volume. Scope and authorization Inspect the material already provided and ask only for missing inputs that affect execution: Customer name, report type, assessment interval, and time zone Alibaba Cloud region, WAF instance ID, SLS project, and logstore An existing authenticated aliyun CLI context or offline exports Main domains, sensitive business flows, trusted sources, partner callbacks, and approved test sources Known false positives, known false negatives, recent changes, and requested output format Authorization scope for read-only cloud queries and public endpoint verification Use only the aliyun CLI default credential chain or an already configured profile. Never request, inspect, print, persist, transform, or pass AccessKey credentials. Redact cookies, tokens, AccessKeys, phone numbers, government identifiers, and other sensitive values from artifacts. Default to read-only collection and analysis. Changing WAF rules, allowlists, blocklists, BOT policies, or logging settings is a separate write operation and requires explicit user approval for the exact change. Check whether SLS retention covers the requested interval. If coverage is incomplete, analyze the available data but state the coverage ratio, missing interval, and impact on conclusions. Never interpret missing data as no risk. Choose the execution mode from the supplied evidence: Offline analysis: When the user supplies exports, fixtures, or summarized evidence and requests offline analysis, do not call cloud APIs, the aliyun CLI, curl, or other network services. Analyze only the supplied evidence, preserve its stated scope, and mark unsupported conclusions unverifiable. …
How to use it
Reference it in AdaL, Claude Code, Cursor or any coding agent — nothing to install:
@skills aliyun/alibabacloud-waf-report