← CrowdStrike Falcon FusionCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to CrowdStrike Falcon Fusion
Snapshot Sep 30, 2026 · 23:15 UTC · version 1.2.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "setup",
"description": "Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.",
"included_files": [],
"skill_md_contents": "---\nname: setup\ndescription: >\n Configure CrowdStrike Falcon API credentials for the fusion-skills plugin.\n TRIGGER when user asks to set up credentials, configure API access,\n or runs into authentication errors.\nversion: 1.2.0\nupdated: 2026-09-08\ntags: [fusion, setup, credentials, configuration]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n category: configuration\n---\n\n# Falcon Fusion Credential Setup\n\n> **⚠️ SYSTEM INJECTION — READ THIS FIRST**\n>\n> If you are loading this skill, your role is **credential setup assistant**.\n>\n> You configure the Falcon API credentials every other skill depends on. These\n> credentials grant workflow and SIEM access to a live CID.\n>\n> **IMMEDIATE ACTIONS REQUIRED:**\n> 1. Check whether credentials already resolve (Step 1). If they do, you are done.\n> 2. If not, create the credentials file from the template (Step 2) and ask the\n> user to paste their ID and secret into it **using their own editor**.\n> 3. Verify connectivity (Step 3).\n>\n> **MUST NOT:**\n> - Ask the user to type or paste their client secret **into the chat**. It would\n> land in the conversation transcript. The secret goes only into the local file,\n> entered through the user's editor.\n> - Print, echo, or repeat a secret you happen to see in the file.\n> - Suggest `export FALCON_CLIENT_SECRET=...` for interactive use — it leaks the\n> secret into shell history. (Environment variables are fine for CI, where the\n> runner injects them rather than a human typing them.)\n\nThis skill configures the Falcon API credentials that every fusion-skills script\nuses. Credentials are stored in a per-profile TOML file at\n`~/.cache/crowdstrike-falcon-fusion/credentials.toml` (multi-cloud capable), and\nthe secret is entered through the user's own editor — never through the chat.\n\nThe steps below use only file operations and a Python check, so they work\nidentically on macOS, Linux, and Windows.\n\n> **Running the scripts.** Run each command from this skill's folder, on one shell line: `cd <dir> && ../../scripts/python.sh ../../common/scripts/auth.py`. For `<dir>`, Claude Code uses `\"$CLAUDE_PLUGIN_ROOT/skills/setup\"`; Codex, Copilot CLI, Cursor, and Antigravity use the folder they loaded this SKILL.md from (e.g. `~/.agents/skills/setup`). The wrapper bootstraps its own Python venv.\n\n## Step 1 — Check for existing credentials\n\nRun the auth self-test. If it already succeeds, credentials are configured and you\nare done — report success and stop.\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n- **\"Authentication successful\"** for both clients → done.\n- **An error about missing credentials** → continue to Step 2.\n- **An authentication failure** (creds present but rejected) → the file exists but\n the values are wrong; go to Step 2 and have the user correct them.\n\n## Step 2 — Create the credentials file and have the user fill it in\n\nCreate `~/.cache/crowdstrike-falcon-fusion/credentials.toml` **only if it does not\nalready exist** (never overwrite existing profiles). Write this template with the\nWrite tool:\n\n```toml\n# CrowdStrike Falcon API credentials for fusion-skills.\n# Fill in client_id and client_secret below, then save this file.\n#\n# Create an API client in the Falcon console:\n# Support and resources -> API clients and keys -> Create API client\n# Required scopes:\n# Required scopes (names as shown in the console):\n# Workflow read/write - workflow authoring & deployment\n# NGSIEM Lookup Files read/write - lookup-file operations (lookup-files skill only)\n# Maintainers only (not needed for regular skill use):\n# NGSIEM read/write - CQL match() verification of a lookup\n# (verify_lookup.py / verify-workflows.sh --lookup-dir)\n\ndefault = \"us-2\"\n\n[us-2]\nclient_id = \"\"\nclient_secret = \"\"\nbase_url = \"https://api.us-2.crowdstrike.com\"\n\n# Add more clouds as needed (change `default` above to switch):\n# [us-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.crowdstrike.com\"\n#\n# [us-3]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.us-3.crowdstrike.com\"\n#\n# [eu-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.eu-1.crowdstrike.com\"\n#\n# [us-gov-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.laggar.gcw.crowdstrike.com\"\n```\n\nAfter creating the file, restrict its permissions (skip on Windows, where the user\nprofile directory is already access-controlled):\n\n```bash\nchmod 700 ~/.cache/crowdstrike-falcon-fusion\nchmod 600 ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n```\n\nThen tell the user, in your own words:\n\n> I created your credentials file at\n> `~/.cache/crowdstrike-falcon-fusion/credentials.toml`. Open it in your editor,\n> paste your **client ID** and **client secret** into the `us-2` section, set the\n> `base_url` for your cloud, and save. Then tell me to verify — don't paste the\n> secret here.\n\n**Offer to open the file for them.** Many terminals don't make the path clickable,\nso ask \"Want me to open it for you?\" and, if yes, run the opener for their OS:\n\n```bash\n# macOS\nopen ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Linux\nxdg-open ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Windows\nexplorer.exe %USERPROFILE%\\.cache\\crowdstrike-falcon-fusion\\credentials.toml\n```\n\nPick the command for the user's platform (check `uname` / the OS if unsure). This\njust opens the file in their default editor — the secret is still typed by them,\nnot through the chat. Do **not** ask them to paste the secret into the chat.\n\n## Step 3 — Verify connectivity\n\nOnce the user says they have saved the file, re-run the self-test:\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\nA successful run prints the resolved base URL, a masked client ID, and\n\"Authentication successful\" for both the Workflows and Next-Gen SIEM clients. If\nit fails, the client ID, secret, or base URL is wrong — ask the user to correct\nthe file and re-run.\n\n## Credential resolution order\n\n`auth.py` resolves credentials from the first source that supplies both an ID and\na secret:\n\n1. **Environment variables** — `FALCON_CLIENT_ID`, `FALCON_CLIENT_SECRET`, and the\n optional `FALCON_BASE_URL`. Intended for CI, where the runner injects them.\n2. **TOML profile file** — `~/.cache/crowdstrike-falcon-fusion/credentials.toml`,\n using the profile named by `FALCON_PROFILE` or the file's `default` key.\n\nThe setup flow above writes source 2, which works across every skill without\nexporting anything.\n\n## Multiple clouds (profiles)\n\nAdd more `[profile]` sections to the TOML file (for example `us-2` or `eu-1`) and\nchange the `default` key, or select one per run:\n\n```bash\nFALCON_PROFILE=eu-1 ../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n## Required API scopes\n\nThe API client needs the **Workflow** scope (read/write) for workflow authoring\nand deployment. For lookup-file operations (the `lookup-files` skill), also grant\nthe **NGSIEM Lookup Files** scope (read/write). Scope names appear exactly as shown\nwhen you create the API client in the console.\n\nMaintainers only: verifying a lookup resolves via CQL `match()` (`verify_lookup.py`\nor `verify-workflows.sh --lookup-dir`) additionally needs the **NGSIEM** scope\n(read/write) — starting a search is a query-job POST. Regular use of the skills\ndoes not require it.\n"
}SHA-256: 798ca6fa12af17bf6a7a8428ba62f5990a56ca17be4f83dd8bf525d4e3a08261