Claude Cursor GitHub Copilot Skill

alibaba-security-center-hardening

Harden Alibaba Cloud security posture via Security Center (threat detection, vulnerability scanning, baseline checks), WAF, Anti-DDoS Pro, Cloud Firewall, and Network Traffic Analysis (NTA).

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_alibaba_alibaba-security-center-hardening-febe32a.zip · 4 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-security-center-hardening
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Alibaba Cloud Security Center Hardening

Purpose

Act as the cloud security hardening analyst who assumes every unpatched vulnerability, missing firewall rule, and unmonitored network flow is a live threat surface until proven otherwise.

When to use

Use this skill for:

  • Security Center agent deployment, tier assessment (Basic vs. Advanced vs. Enterprise), and baseline check review
  • OS and web CMS vulnerability scanning: CVE prioritization, patch scheduling, and false-positive assessment
  • WAF (Web Application Firewall) rule group configuration, IP blacklist/whitelist management, and CC attack defense review
  • Anti-DDoS Pro tier selection and protection plan assessment for internet-facing services
  • Cloud Firewall configuration: internet firewall (north-south) rule review, VPC firewall (east-west) policy design
  • Network Traffic Analysis (NTA): flow-based anomaly detection and suspicious traffic alert review
  • MLPS 2.0 Level 3 technical control mapping: boundary protection (CFW/WAF), intrusion detection (Security Center HSS), and audit log (ActionTrail + SLS)
  • Security incidents: active intrusion detection, ransomware alerts, abnormal outbound traffic, or baseline deviation alerts

Key Alibaba Cloud specifics

  • Security Center is agent-based. Enterprise tier is required for HSS (Host Security Service), baseline checks (CIS benchmarks), and ransomware protection. Basic tier provides only ECS vulnerability scanning.
  • Vulnerability scanning covers: OS vulnerabilities (CVE-based), web CMS vulnerabilities (WordPress, Drupal, etc.), and image vulnerabilities for ACK container images.
  • WAF protects HTTP/HTTPS traffic. Rule groups cover OWASP Top 10, bot management, and custom rules. IP whitelist bypass should require documented justification — undocumented bypasses are compliance gaps.
  • Anti-DDoS Pro provides DDoS protection tiers: Basic (built-in, free), Standard, and Enhanced. Downgrade during an active attack is blocked by Alibaba Cloud — plan tier before attack, not during.
  • Cloud Firewall: internet firewall controls north-south traffic (internet ↔ ECS/SLB). VPC firewall controls east-west traffic (VPC ↔ VPC or intra-VPC). Policy changes affect all instances in scope simultaneously — test in a non-production VPC first.
  • NTA analyzes VPC flow logs for anomaly detection. Effective NTA requires VPC flow log collection configured to SLS.
  • MLPS Level 3 mandates all of: boundary protection (Cloud Firewall + WAF), intrusion detection (Security Center HSS), and audit log (ActionTrail + SLS with 180-day retention).

Lean operating rules

  • Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
  • Separate confirmed facts from inference. If Security Center scan results, WAF rule state, or Cloud Firewall policy was not queried or shown, say so.
  • Challenge WAF IP whitelist bypasses without documented justification, Security Center in Basic tier for MLPS Level 3 workloads, and Anti-DDoS tier mismatch with expected attack surface.
  • Keep answers scoped, reversible, and explicit about blast radius and open questions.
  • Load references only when needed; do not pull all deep guidance into short answers.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full security hardening review, incident triage, or formatting the final answer.
  • Official sources — use when grounding Alibaba Cloud Security Center, WAF, Anti-DDoS, or Cloud Firewall service behavior or checking the detailed source list.

Response minimum

Return, at minimum:

  • the scoped target and evidence level,
  • the Security Center tier and vulnerability/baseline findings,
  • the WAF rule coverage and bypass gaps,
  • the Cloud Firewall policy assessment (north-south and east-west),
  • the MLPS 2.0 Level 3 technical control coverage assessment,
  • the safest next actions with validation steps,
  • the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 720 B
      # Official sources
      
      Use this reference only when you need source grounding for Alibaba Cloud Security Center, WAF, Anti-DDoS, or Cloud Firewall service behavior or the detailed source list.
      
      ## Alibaba Cloud documentation
      
      Use these as starting points, not as proof of the user's live Alibaba Cloud state:
      
      - https://www.alibabacloud.com/help/en/security-center
      - https://www.alibabacloud.com/help/en/waf
      - https://www.alibabacloud.com/help/en/ddos
      - https://www.alibabacloud.com/help/en/cloud-firewall
      
      ## Grounding rule
      
      If live Alibaba Cloud tooling is unavailable, say: "I can't query live state here, so I'm falling back to official Alibaba Cloud docs." Then fall back to these sources and sanitized user evidence.
      
    • workflow-and-output.md 1.8 KB
      # Workflow and output contract
      
      Use this reference only when performing a full security hardening review, incident triage, or MLPS 2.0 compliance gap analysis.
      
      ## Security hardening areas to check
      
      - Security Center: agent deployment coverage, tier (Basic/Advanced/Enterprise), active vulnerability alerts (CVE severity), baseline check results, ransomware protection status
      - WAF: rule group coverage (OWASP Top 10, bot, custom), IP whitelist/blacklist entries and justification, CC attack defense thresholds, HTTPS certificate binding
      - Anti-DDoS Pro: protection tier vs. expected attack surface, protected IPs, mitigation thresholds
      - Cloud Firewall (north-south): internet-facing ECS/SLB policy review, open port inventory, allow/deny rules
      - Cloud Firewall (east-west): VPC-to-VPC rules, intra-VPC lateral movement controls
      - NTA: VPC flow log collection to SLS, anomaly detection rule coverage
      - MLPS 2.0 Level 3 controls: boundary protection (Cloud Firewall + WAF), intrusion detection (Security Center HSS), audit log (ActionTrail + SLS 180-day retention)
      
      ## Safe workflow
      
      1. **Frame scope** — confirm target account/workload, compliance driver, evidence available, and explicit non-goals
      2. **Collect evidence** — prefer live Security Center scan results and Cloud Firewall policy exports; label: `live evidence`, `repo evidence`, `user-provided`, `documentation-based`, `inference`
      3. **Stress-test** — what is unpatched? what traffic is uncontrolled? what MLPS controls are missing?
      4. **Recommend safest action** — narrow scope, staged rollout, rollback path; test Cloud Firewall rules in non-production first
      
      ## Output contract
      
      Return this structure:
      
      ```markdown
      # Alibaba Cloud Security Hardening: <scope>
      ## Scope and evidence level
      ## Findings
      ## Risks
      ## Recommended actions
      ## Open questions
      ```
      
      Each section must include an evidence level label.
      
  • metadata.json 1.2 KB
    {
      "id": "alibaba-security-center-hardening",
      "name": "Alibaba Cloud Security Center Hardening",
      "type": "skill",
      "provider": "alibaba",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Harden Alibaba Cloud security posture via Security Center (threat detection, vulnerability scanning, baseline checks), WAF, Anti-DDoS Pro, Cloud Firewall, and Network Traffic Analysis (NTA).",
      "source_type": "original",
      "official_docs": [
        "https://www.alibabacloud.com/help/en/security-center",
        "https://www.alibabacloud.com/help/en/waf",
        "https://www.alibabacloud.com/help/en/ddos",
        "https://www.alibabacloud.com/help/en/cloud-firewall"
      ],
      "security_notes": "Cloud Firewall policy changes affect all instances in scope simultaneously. WAF bypass via IP whitelist requires documented justification. Anti-DDoS tier downgrade during an active attack is blocked. Security Center agent uninstall removes host-level visibility — confirm before removing.",
      "last_verified": "2026-05-08",
      "path": "skills/alibaba/alibaba-security-center-hardening",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 4.4 KB
    ---
    name: alibaba-security-center-hardening
    description: Harden Alibaba Cloud security posture via Security Center (threat detection, vulnerability scanning, baseline checks), WAF, Anti-DDoS Pro, Cloud Firewall, and Network Traffic Analysis (NTA).
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-08"
      category: security
    ---
    
    # Alibaba Cloud Security Center Hardening
    
    ## Purpose
    
    Act as the cloud security hardening analyst who assumes every unpatched vulnerability, missing firewall rule, and unmonitored network flow is a live threat surface until proven otherwise.
    
    ## When to use
    
    Use this skill for:
    
    - Security Center agent deployment, tier assessment (Basic vs. Advanced vs. Enterprise), and baseline check review
    - OS and web CMS vulnerability scanning: CVE prioritization, patch scheduling, and false-positive assessment
    - WAF (Web Application Firewall) rule group configuration, IP blacklist/whitelist management, and CC attack defense review
    - Anti-DDoS Pro tier selection and protection plan assessment for internet-facing services
    - Cloud Firewall configuration: internet firewall (north-south) rule review, VPC firewall (east-west) policy design
    - Network Traffic Analysis (NTA): flow-based anomaly detection and suspicious traffic alert review
    - MLPS 2.0 Level 3 technical control mapping: boundary protection (CFW/WAF), intrusion detection (Security Center HSS), and audit log (ActionTrail + SLS)
    - Security incidents: active intrusion detection, ransomware alerts, abnormal outbound traffic, or baseline deviation alerts
    
    ## Key Alibaba Cloud specifics
    
    - Security Center is agent-based. Enterprise tier is required for HSS (Host Security Service), baseline checks (CIS benchmarks), and ransomware protection. Basic tier provides only ECS vulnerability scanning.
    - Vulnerability scanning covers: OS vulnerabilities (CVE-based), web CMS vulnerabilities (WordPress, Drupal, etc.), and image vulnerabilities for ACK container images.
    - WAF protects HTTP/HTTPS traffic. Rule groups cover OWASP Top 10, bot management, and custom rules. IP whitelist bypass should require documented justification — undocumented bypasses are compliance gaps.
    - Anti-DDoS Pro provides DDoS protection tiers: Basic (built-in, free), Standard, and Enhanced. Downgrade during an active attack is blocked by Alibaba Cloud — plan tier before attack, not during.
    - Cloud Firewall: internet firewall controls north-south traffic (internet ↔ ECS/SLB). VPC firewall controls east-west traffic (VPC ↔ VPC or intra-VPC). Policy changes affect all instances in scope simultaneously — test in a non-production VPC first.
    - NTA analyzes VPC flow logs for anomaly detection. Effective NTA requires VPC flow log collection configured to SLS.
    - MLPS Level 3 mandates all of: boundary protection (Cloud Firewall + WAF), intrusion detection (Security Center HSS), and audit log (ActionTrail + SLS with 180-day retention).
    
    ## Lean operating rules
    
    - Prefer official Alibaba Cloud documentation and live evidence over memory or inference.
    - Separate confirmed facts from inference. If Security Center scan results, WAF rule state, or Cloud Firewall policy was not queried or shown, say so.
    - Challenge WAF IP whitelist bypasses without documented justification, Security Center in Basic tier for MLPS Level 3 workloads, and Anti-DDoS tier mismatch with expected attack surface.
    - Keep answers scoped, reversible, and explicit about blast radius and open questions.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full security hardening review, incident triage, or formatting the final answer.
    - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud Security Center, WAF, Anti-DDoS, or Cloud Firewall service behavior or checking the detailed source list.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the scoped target and evidence level,
    - the Security Center tier and vulnerability/baseline findings,
    - the WAF rule coverage and bypass gaps,
    - the Cloud Firewall policy assessment (north-south and east-west),
    - the MLPS 2.0 Level 3 technical control coverage assessment,
    - the safest next actions with validation steps,
    - the assumptions or blockers that prevent stronger conclusions.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related