← CrowdStrike Falcon FusionCONTENT HISTORY

Update to CrowdStrike Falcon Fusion

Snapshot Oct 8, 2026 · 18:00 UTC · version 1.3.0

WHAT CHANGED · RULE-BASED ANALYSIS

Declared capabilities changed

Declared skills changed from “[{"description":"Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, vali...” to “[{"description":"Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, vali...”.

Observed in instructions or declared skills. Runtime behavior has not been tested.

Declared skills

Before

[{"description":"Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, vali...

After

[{"description":"Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, vali...

Id

Before

pluginrel_ee7b7c8164ac81918d534aae474937fd

After

pluginrel_57619d69555c8191a9e539f6151a75f7

Composer icon url

Before

https://files.openai.com/content?id=file_000000005a78822fbee13db38ee19c1e

After

https://files.openai.com/content?id=file_0000000030c882109d902ec296ec6892

Logo url

Before

https://files.openai.com/content?id=file_00000000cf30820eb21ec7897657365b

After

https://files.openai.com/content?id=file_0000000085548210b5020baf0b7205d6

Compare saved observations

Download comparison JSON
Full technical diff · 5 changed fields

changed /release/id

BEFORE
"pluginrel_ee7b7c8164ac81918d534aae474937fd"
AFTER
"pluginrel_57619d69555c8191a9e539f6151a75f7"

changed /release/interface/composer_icon_url

BEFORE
"https://files.openai.com/content?id=file_000000005a78822fbee13db38ee19c1e"
AFTER
"https://files.openai.com/content?id=file_0000000030c882109d902ec296ec6892"

changed /release/interface/logo_url

BEFORE
"https://files.openai.com/content?id=file_00000000cf30820eb21ec7897657365b"
AFTER
"https://files.openai.com/content?id=file_0000000085548210b5020baf0b7205d6"

changed /release/skills

BEFORE
[
  {
    "description": "Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, validate a workflow, use CEL expressions, or needs action discovery. DO NOT TRIGGER for deploying, importing, executing, or monitoring workflows — use deployment or execution skills. DO NOT TRIGGER when the request is for a Falcon Foundry app, a UI extension/page, an API integration, custom actions from a third-party API, or a manifest.yml — those are foundry-skills territory; advise foundry-skills instead of authoring a workflow.",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "authoring",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "code",
      "short_description": "Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, validate a workflow, use CEL expressions, or needs action discovery. DO NOT TRIGGER for deploying, importing, executing, or monitoring workflows — use deployment or execution skills. DO NOT TRIGGER when the request is for a Falcon Foundry app, a UI extension/page, an API integration, custom actions from a third-party API, or a manifest.yml — those are foundry-skills territory; advise foundry-skills instead of authoring a workflow."
    },
    "name": "authoring",
    "plugin_release_skill_id": "pluginrsk_6aa19a29ce888191b44ab671e3dc5c95"
  },
  {
    "description": "Import, release, and manage Falcon Fusion workflow definitions in a CID. TRIGGER when user asks to import a workflow, release a workflow version, list existing workflows, check for duplicates, or manage workflow definitions. DO NOT TRIGGER for writing YAML (use authoring), executing workflows, or monitoring (use execution).",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "deployment",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "bolt",
      "short_description": "Import, release, and manage Falcon Fusion workflow definitions in a CID. TRIGGER when user asks to import a workflow, release a workflow version, list existing workflows, check for duplicates, or manage workflow definitions. DO NOT TRIGGER for writing YAML (use authoring), executing workflows, or monitoring (use execution)."
    },
    "name": "deployment",
    "plugin_release_skill_id": "pluginrsk_6aa19a2960ec8191879a406c804bc47c"
  },
  {
    "description": "Trigger Falcon Fusion workflows, monitor execution status, and debug failures. TRIGGER when user asks to run a workflow, check execution status, tail logs, get execution results, or debug a workflow failure. DO NOT TRIGGER for writing YAML (use authoring) or importing/releasing workflows (use deployment).",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "execution",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "bolt",
      "short_description": "Trigger Falcon Fusion workflows, monitor execution status, and debug failures. TRIGGER when user asks to run a workflow, check execution status, tail logs, get execution results, or debug a workflow failure. DO NOT TRIGGER for writing YAML (use authoring) or importing/releasing workflows (use deployment)."
    },
    "name": "execution",
    "plugin_release_skill_id": "pluginrsk_6aa19a2b6700819195162d14c90eb46a"
  },
  {
    "description": "TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without Claude Code hooks; it yields to the real Foundry plugin when that plugin is also installed.",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "foundry-redirect",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "hierarchy",
      "short_description": "TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without Claude Code hooks; it yields to the real Foundry plugin when that plugin is also installed."
    },
    "name": "foundry-redirect",
    "plugin_release_skill_id": "pluginrsk_6aa19a28e8dc81918a04bfdcefd25ff7"
  },
  {
    "description": "Manage Falcon Next-Gen SIEM lookup files (CSV/JSON/TXT) for CQL match() queries. TRIGGER when user asks to create, list, update, or delete lookup files, or needs help with CQL match() function. DO NOT TRIGGER for Fusion workflows, action discovery, or workflow deployment — use the workflows/authoring/deployment skills.",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "lookup-files",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "search",
      "short_description": "Manage Falcon Next-Gen SIEM lookup files (CSV/JSON/TXT) for CQL match() queries. TRIGGER when user asks to create, list, update, or delete lookup files, or needs help with CQL match() function. DO NOT TRIGGER for Fusion workflows, action discovery, or workflow deployment — use the workflows/authoring/deployment skills."
    },
    "name": "lookup-files",
    "plugin_release_skill_id": "pluginrsk_6aa19a29fdbc819193833a827a7506df"
  },
  {
    "description": "Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "setup",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "bolt",
      "short_description": "Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors."
    },
    "name": "setup",
    "plugin_release_skill_id": "pluginrsk_6aa19a293ebc8191a1b43a25319b75c4"
  },
  {
    "description": "Orchestrates the full Falcon Fusion workflow lifecycle from discovery through deployment and execution. TRIGGER when user asks to \"create a Fusion workflow\", \"build a Fusion playbook\", \"automate CrowdStrike actions\", or mentions Fusion workflows without specifying a sub-task. DO NOT TRIGGER when user is working in a Foundry app context, mentions manifest.yml, or asks to \"build a Foundry app\" — use foundry-skills instead.",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "workflows",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "hierarchy",
      "short_description": "Orchestrates the full Falcon Fusion workflow lifecycle from discovery through deployment and execution. TRIGGER when user asks to \"create a Fusion workflow\", \"build a Fusion playbook\", \"automate CrowdStrike actions\", or mentions Fusion workflows without specifying a sub-task. DO NOT TRIGGER when user is working in a Foundry app context, mentions manifest.yml, or asks to \"build a Foundry app\" — use foundry-skills instead."
    },
    "name": "workflows",
    "plugin_release_skill_id": "pluginrsk_6aa19a2a7df881919901de2a4d864d81"
  }
]
AFTER
[
  {
    "description": "Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, validate a workflow, use CEL expressions, or needs action discovery. DO NOT TRIGGER for deploying, importing, executing, or monitoring workflows — use deployment or execution skills. DO NOT TRIGGER when the request is for a Falcon Foundry app, a UI extension/page, an API integration, custom actions from a third-party API, or a manifest.yml — those are foundry-skills territory; advise foundry-skills instead of authoring a workflow.\n",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "authoring",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "hierarchy",
      "short_description": "Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, validate a workflow, use CEL expressions, or needs action discovery. DO NOT TRIGGER for deploying, importing, executing, or monitoring workflows — use deployment or execution skills. DO NOT TRIGGER when the request is for a Falcon Foundry app, a UI extension/page, an API integration, custom actions from a third-party API, or a manifest.yml — those are foundry-skills territory; advise foundry-skills instead of authoring a workflow.\n"
    },
    "name": "authoring",
    "plugin_release_skill_id": "pluginrsk_6abfb6043420819184444eb18d030d12"
  },
  {
    "description": "Import, release, and manage Falcon Fusion workflow definitions in a CID. TRIGGER when user asks to import a workflow, release a workflow version, list existing workflows, check for duplicates, or manage workflow definitions. DO NOT TRIGGER for writing YAML (use authoring), executing workflows, or monitoring (use execution).\n",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "deployment",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "bolt",
      "short_description": "Import, release, and manage Falcon Fusion workflow definitions in a CID. TRIGGER when user asks to import a workflow, release a workflow version, list existing workflows, check for duplicates, or manage workflow definitions. DO NOT TRIGGER for writing YAML (use authoring), executing workflows, or monitoring (use execution).\n"
    },
    "name": "deployment",
    "plugin_release_skill_id": "pluginrsk_6abfb6024dc88191bd8c7de58985a597"
  },
  {
    "description": "Trigger Falcon Fusion workflows, monitor execution status, and debug failures. TRIGGER when user asks to run a workflow, check execution status, tail logs, get execution results, or debug a workflow failure. DO NOT TRIGGER for writing YAML (use authoring) or importing/releasing workflows (use deployment).\n",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "execution",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "bolt",
      "short_description": "Trigger Falcon Fusion workflows, monitor execution status, and debug failures. TRIGGER when user asks to run a workflow, check execution status, tail logs, get execution results, or debug a workflow failure. DO NOT TRIGGER for writing YAML (use authoring) or importing/releasing workflows (use deployment).\n"
    },
    "name": "execution",
    "plugin_release_skill_id": "pluginrsk_6abfb60355508191b220675fbd7310f7"
  },
  {
    "description": "TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "foundry-redirect",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "code",
      "short_description": "TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n"
    },
    "name": "foundry-redirect",
    "plugin_release_skill_id": "pluginrsk_6abfb602294481919af9990a29f3a9ca"
  },
  {
    "description": "Manage Falcon Next-Gen SIEM lookup files (CSV/JSON/TXT) for CQL match() queries. TRIGGER when user asks to create, list, update, or delete lookup files, or needs help with CQL match() function. DO NOT TRIGGER for Fusion workflows, action discovery, or workflow deployment — use the workflows/authoring/deployment skills.\n",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "lookup-files",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "search",
      "short_description": "Manage Falcon Next-Gen SIEM lookup files (CSV/JSON/TXT) for CQL match() queries. TRIGGER when user asks to create, list, update, or delete lookup files, or needs help with CQL match() function. DO NOT TRIGGER for Fusion workflows, action discovery, or workflow deployment — use the workflows/authoring/deployment skills.\n"
    },
    "name": "lookup-files",
    "plugin_release_skill_id": "pluginrsk_6abfb6030e088191a8f1ed5d6d72c69b"
  },
  {
    "description": "Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.\n",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "setup",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "bolt",
      "short_description": "Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.\n"
    },
    "name": "setup",
    "plugin_release_skill_id": "pluginrsk_6abfb60240d88191ab3870dcb0a6488a"
  },
  {
    "description": "Orchestrates the full Falcon Fusion workflow lifecycle from discovery through deployment and execution. TRIGGER when user asks to \"create a Fusion workflow\", \"build a Fusion playbook\", \"automate CrowdStrike actions\", or mentions Fusion workflows without specifying a sub-task. DO NOT TRIGGER when user is working in a Foundry app context, mentions manifest.yml, or asks to \"build a Foundry app\" — use foundry-skills instead.\n",
    "interface": {
      "brand_color": null,
      "default_prompt": null,
      "display_name": "workflows",
      "icon_large_url": null,
      "icon_small_url": null,
      "iconography": "hierarchy",
      "short_description": "Orchestrates the full Falcon Fusion workflow lifecycle from discovery through deployment and execution. TRIGGER when user asks to \"create a Fusion workflow\", \"build a Fusion playbook\", \"automate CrowdStrike actions\", or mentions Fusion workflows without specifying a sub-task. DO NOT TRIGGER when user is working in a Foundry app context, mentions manifest.yml, or asks to \"build a Foundry app\" — use foundry-skills instead.\n"
    },
    "name": "workflows",
    "plugin_release_skill_id": "pluginrsk_6abfb6021848819193522c43055a4d84"
  }
]

changed /release/version

BEFORE
"1.2.0"
AFTER
"1.3.0"
Full snapshot data
{
  "canonical_app_id": null,
  "connector_id": null,
  "created_at": "2026-08-26T23:15:34.926040Z",
  "discoverability": "UNLISTED",
  "id": "plugins_6a8f7048ed7881918bf5b79011fe2b5e",
  "is_template": false,
  "name": "crowdstrike-falcon-fusion",
  "release": {
    "app_ids": [],
    "app_manifest": null,
    "app_templates": [],
    "description": "CrowdStrike Falcon Fusion skills for authoring, deploying, and executing Fusion workflows. Includes live action discovery, YAML authoring with schema validation, workflow import and release, execution monitoring, and Falcon Next-Gen SIEM lookup files.",
    "display_name": "CrowdStrike Falcon Fusion",
    "id": "pluginrel_57619d69555c8191a9e539f6151a75f7",
    "interface": {
      "brand_color": "#E01F3D",
      "capabilities": [
        "Interactive",
        "Write"
      ],
      "category": "Developer Tools",
      "composer_icon_dark_url": null,
      "composer_icon_url": "https://files.openai.com/content?id=file_0000000030c882109d902ec296ec6892",
      "default_prompt": "Create a Falcon Fusion workflow",
      "default_prompts": [
        "Create a Falcon Fusion workflow",
        "Automate a CrowdStrike response",
        "Troubleshoot a Fusion workflow"
      ],
      "developer_name": "CrowdStrike",
      "logo_url": "https://files.openai.com/content?id=file_0000000085548210b5020baf0b7205d6",
      "logo_url_dark": null,
      "long_description": "Discover live Falcon Fusion actions, author workflow YAML with schema validation, import and release workflow definitions to a CID, trigger and monitor executions, and manage Falcon Next-Gen SIEM lookup files.",
      "plugin_category_id": "developer tools",
      "privacy_policy_url": null,
      "screenshot_urls": [],
      "short_description": "Build Falcon Fusion workflows",
      "terms_of_service_url": null,
      "website_url": "https://github.com/CrowdStrike/fusion-skills"
    },
    "keywords": [
      "crowdstrike",
      "falcon",
      "fusion",
      "soar",
      "workflow",
      "automation",
      "security"
    ],
    "onboarding_skill_name": null,
    "requires_local_executor": false,
    "skills": [
      {
        "description": "Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, validate a workflow, use CEL expressions, or needs action discovery. DO NOT TRIGGER for deploying, importing, executing, or monitoring workflows — use deployment or execution skills. DO NOT TRIGGER when the request is for a Falcon Foundry app, a UI extension/page, an API integration, custom actions from a third-party API, or a manifest.yml — those are foundry-skills territory; advise foundry-skills instead of authoring a workflow.\n",
        "interface": {
          "brand_color": null,
          "default_prompt": null,
          "display_name": "authoring",
          "icon_large_url": null,
          "icon_small_url": null,
          "iconography": "hierarchy",
          "short_description": "Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, validate a workflow, use CEL expressions, or needs action discovery. DO NOT TRIGGER for deploying, importing, executing, or monitoring workflows — use deployment or execution skills. DO NOT TRIGGER when the request is for a Falcon Foundry app, a UI extension/page, an API integration, custom actions from a third-party API, or a manifest.yml — those are foundry-skills territory; advise foundry-skills instead of authoring a workflow.\n"
        },
        "name": "authoring",
        "plugin_release_skill_id": "pluginrsk_6abfb6043420819184444eb18d030d12"
      },
      {
        "description": "Import, release, and manage Falcon Fusion workflow definitions in a CID. TRIGGER when user asks to import a workflow, release a workflow version, list existing workflows, check for duplicates, or manage workflow definitions. DO NOT TRIGGER for writing YAML (use authoring), executing workflows, or monitoring (use execution).\n",
        "interface": {
          "brand_color": null,
          "default_prompt": null,
          "display_name": "deployment",
          "icon_large_url": null,
          "icon_small_url": null,
          "iconography": "bolt",
          "short_description": "Import, release, and manage Falcon Fusion workflow definitions in a CID. TRIGGER when user asks to import a workflow, release a workflow version, list existing workflows, check for duplicates, or manage workflow definitions. DO NOT TRIGGER for writing YAML (use authoring), executing workflows, or monitoring (use execution).\n"
        },
        "name": "deployment",
        "plugin_release_skill_id": "pluginrsk_6abfb6024dc88191bd8c7de58985a597"
      },
      {
        "description": "Trigger Falcon Fusion workflows, monitor execution status, and debug failures. TRIGGER when user asks to run a workflow, check execution status, tail logs, get execution results, or debug a workflow failure. DO NOT TRIGGER for writing YAML (use authoring) or importing/releasing workflows (use deployment).\n",
        "interface": {
          "brand_color": null,
          "default_prompt": null,
          "display_name": "execution",
          "icon_large_url": null,
          "icon_small_url": null,
          "iconography": "bolt",
          "short_description": "Trigger Falcon Fusion workflows, monitor execution status, and debug failures. TRIGGER when user asks to run a workflow, check execution status, tail logs, get execution results, or debug a workflow failure. DO NOT TRIGGER for writing YAML (use authoring) or importing/releasing workflows (use deployment).\n"
        },
        "name": "execution",
        "plugin_release_skill_id": "pluginrsk_6abfb60355508191b220675fbd7310f7"
      },
      {
        "description": "TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n",
        "interface": {
          "brand_color": null,
          "default_prompt": null,
          "display_name": "foundry-redirect",
          "icon_large_url": null,
          "icon_small_url": null,
          "iconography": "code",
          "short_description": "TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n"
        },
        "name": "foundry-redirect",
        "plugin_release_skill_id": "pluginrsk_6abfb602294481919af9990a29f3a9ca"
      },
      {
        "description": "Manage Falcon Next-Gen SIEM lookup files (CSV/JSON/TXT) for CQL match() queries. TRIGGER when user asks to create, list, update, or delete lookup files, or needs help with CQL match() function. DO NOT TRIGGER for Fusion workflows, action discovery, or workflow deployment — use the workflows/authoring/deployment skills.\n",
        "interface": {
          "brand_color": null,
          "default_prompt": null,
          "display_name": "lookup-files",
          "icon_large_url": null,
          "icon_small_url": null,
          "iconography": "search",
          "short_description": "Manage Falcon Next-Gen SIEM lookup files (CSV/JSON/TXT) for CQL match() queries. TRIGGER when user asks to create, list, update, or delete lookup files, or needs help with CQL match() function. DO NOT TRIGGER for Fusion workflows, action discovery, or workflow deployment — use the workflows/authoring/deployment skills.\n"
        },
        "name": "lookup-files",
        "plugin_release_skill_id": "pluginrsk_6abfb6030e088191a8f1ed5d6d72c69b"
      },
      {
        "description": "Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.\n",
        "interface": {
          "brand_color": null,
          "default_prompt": null,
          "display_name": "setup",
          "icon_large_url": null,
          "icon_small_url": null,
          "iconography": "bolt",
          "short_description": "Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.\n"
        },
        "name": "setup",
        "plugin_release_skill_id": "pluginrsk_6abfb60240d88191ab3870dcb0a6488a"
      },
      {
        "description": "Orchestrates the full Falcon Fusion workflow lifecycle from discovery through deployment and execution. TRIGGER when user asks to \"create a Fusion workflow\", \"build a Fusion playbook\", \"automate CrowdStrike actions\", or mentions Fusion workflows without specifying a sub-task. DO NOT TRIGGER when user is working in a Foundry app context, mentions manifest.yml, or asks to \"build a Foundry app\" — use foundry-skills instead.\n",
        "interface": {
          "brand_color": null,
          "default_prompt": null,
          "display_name": "workflows",
          "icon_large_url": null,
          "icon_small_url": null,
          "iconography": "hierarchy",
          "short_description": "Orchestrates the full Falcon Fusion workflow lifecycle from discovery through deployment and execution. TRIGGER when user asks to \"create a Fusion workflow\", \"build a Fusion playbook\", \"automate CrowdStrike actions\", or mentions Fusion workflows without specifying a sub-task. DO NOT TRIGGER when user is working in a Foundry app context, mentions manifest.yml, or asks to \"build a Foundry app\" — use foundry-skills instead.\n"
        },
        "name": "workflows",
        "plugin_release_skill_id": "pluginrsk_6abfb6021848819193522c43055a4d84"
      }
    ],
    "version": "1.3.0"
  },
  "scope": "GLOBAL",
  "status": "ENABLED"
}

SHA-256 of public snapshot: ccda5c0c59d081f51bb69533d145bbae13daf2db99caa2269bd0974d2621c143