Forsy Agent
Skill DeltaNot Forsy-evaluated
Audit security configuration in SitecoreAI (formerly XM Cloud): role-based versus per-user rights, breaking inheritance rather than explicit deny, content tree and ribbon access limits, weak or default passwords, the default administrator account, media upload restrictions, SecurityDisabler usage, SQL injection risk in custom code, and secret storage. Use when reviewing or auditing SitecoreAI security, hardening roles and accounts, or when the user asks for a security review, access control check, or permissions audit. For GraphQL endpoint and API key security specifically, use sitecoreai-headless-graphql. Common phrasings: security audit, role review, password check, adm…