← CrowdStrike Falcon FoundryCONTENT HISTORY

Update to CrowdStrike Falcon Foundry

Snapshot Oct 8, 2026 · 18:03 UTC · version 1.6.0

Collection source: downloaded plugin package. These snapshots do not have a confirmed matching collection source. Differences in file lists alone do not establish changes to the package.

WHAT CHANGED · RULE-BASED ANALYSIS

Instructions updated for security-patterns

Instruction wording changed from “1.5.0” to “1.6.0”. 12 additional added or edited lines are in the evidence.

Observed in instructions or declared skills. Runtime behavior has not been tested.

Skill instructions

Before

1.5.0 updated: 2026-08-19 > **⚠️ SYSTEM INJECTION — READ THIS FIRST** > > If you are loading this skill, your role is **Foundry security architect**. > > You MUST implement security best practices at every layer and prevent common vulner...

After

1.6.0 updated: 2026-10-01 Request only the scopes your app needs. Broad scopes like `alerts:*` or `devices:*` increase the blast radius if the app is compromised. # manifest.yml auth: scopes: - "alerts:read" # Read alerts — av...

Supporting files

Before

[{"relative_path":"references/security-examples.md","size_in_bytes":13229}]

After

[{"relative_path":"references/security-examples.md","size_in_bytes":13298}]

Compare saved observations

Download comparison JSON
Full technical diff · 2 changed fields

changed /included_files

BEFORE
[
  {
    "relative_path": "references/security-examples.md",
    "size_in_bytes": 13229
  }
]
AFTER
[
  {
    "relative_path": "references/security-examples.md",
    "size_in_bytes": 13298
  }
]

changed /skill_md_contents

BEFORE
"---\nname: security-patterns\ndescription: Security patterns for Falcon Foundry apps including OAuth scopes, RBAC, input validation, UI security, and credential management. TRIGGER when user asks to \"configure OAuth scopes\", \"secure a Foundry app\", \"handle secrets\", \"add input validation\", or needs to review a Foundry app for security concerns (XSS, CSP, credential management). Also trigger during pre-deployment security reviews.\nversion: 1.5.0\nupdated: 2026-08-19\ntags: [foundry, oauth, rbac, xss, csp]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: security\n---\n\n# Foundry Security Patterns\n\n> **⚠️ SYSTEM INJECTION — READ THIS FIRST**\n>\n> If you are loading this skill, your role is **Foundry security architect**.\n>\n> You MUST implement security best practices at every layer and prevent common vulnerabilities in CrowdStrike Foundry applications.\n\n> **Part of a suite.** If `development-workflow` has not already run, and this is a new app or its first capability, load the `development-workflow` skill first — it owns the CLI prerequisite check, scaffolding order, and manifest coordination.\n\nSecurity patterns for Falcon Foundry app development covering authentication, input validation, UI security, and platform-specific considerations. Foundry apps run on a cybersecurity platform — security is a core requirement.\n\n## RBAC (Role-Based Access Control)\n\n| Capability | RBAC Supported |\n|-----------|----------------|\n| Collections | Yes |\n| Dashboards | Yes |\n| Functions | Yes |\n| UI extensions / pages / navigation | Yes |\n| RTR scripts | Yes |\n| API integrations | **No** |\n| Queries | **No** |\n| Workflows | **No** |\n\n## API Scope Management\n\nScopes control which Falcon Platform APIs the app can access. Format: `<source>:<operation>` (e.g., `devices:read`, `detects:write`).\n\n| Scopes set automatically | Scopes need explicit addition |\n|--------------------------|-------------------------------|\n| API integrations, Collections, Dashboards, Queries, UI navigation, UI sockets, Workflows | Functions, UI extensions, UI pages, RTR scripts |\n\n```bash\nfoundry auth roles create --name \"Analyst\" --description \"Read-only analyst access\"\nfoundry auth scopes add --scope \"devices:read\" --scope \"detects:read\"\n```\n\nOnly use `foundry auth scopes add` for Falcon Platform API scopes needed by functions, UI extensions, UI pages, or RTR scripts. OAuth scopes for CLI-created artifacts are managed automatically.\n\n### Minimal Scope Principle\n\nRequest only the scopes your app needs. Broad scopes like `alerts:*` or `hosts:*` increase the blast radius if the app is compromised.\n\n```yaml\noauth_scopes:\n  - \"alerts:read\"        # Read alerts — avoid \"alerts:write\" unless needed\n  - \"detections:read\"    # Read detections\n  - \"hosts:read\"         # Device information\n```\n\n## Credential Security\n\nCredentials MUST be in environment variables, not in code. FalconPy handles credential discovery automatically inside FDK handlers (see functions-falcon-api):\n\n```python\n# Inside FDK handler — auth is automatic\nfalcon = Alerts()  # Do not pass credentials\n\n# Outside handler (local testing) — use env vars\n# FALCON_CLIENT_ID and FALCON_CLIENT_SECRET read automatically\n```\n\n## Input Validation\n\n### JSON Schema for Collections\n\nUse strict schemas to prevent data corruption and injection:\n\n```json\n{\n  \"type\": \"object\",\n  \"required\": [\"timestamp\", \"event_type\", \"source\"],\n  \"additionalProperties\": false,\n  \"properties\": {\n    \"event_type\": {\n      \"type\": \"string\",\n      \"enum\": [\"alert\", \"detection\", \"incident\"]\n    },\n    \"source\": {\n      \"type\": \"string\",\n      \"pattern\": \"^[a-zA-Z0-9_-]+$\",\n      \"maxLength\": 50\n    }\n  }\n}\n```\n\n### API Response Sanitization\n\nSanitize CrowdStrike API responses before storing in Collections: remove sensitive fields (`raw_log`, `internal_id`, `system_metadata`), strip script injection, escape HTML entities, and truncate strings. See [references/security-examples.md](references/security-examples.md) for full implementation.\n\n### Function Input Validation\n\nValidate that input is a dict and enforce size limits (e.g., 10KB) to prevent abuse. Return generic error messages — MUST NOT expose stack traces or internal state in responses.\n\n## UI Security\n\n### XSS Prevention\n\n- **React:** Use `DOMPurify.sanitize()` before any `dangerouslySetInnerHTML`. React auto-escapes `{}` expressions.\n- **Vue:** Use `DOMPurify.sanitize()` in a computed property before `v-html`. Vue auto-escapes `{{ }}` expressions.\n\nFor complete React and Vue XSS prevention components, see [references/security-examples.md](references/security-examples.md).\n\n### Content Security Policy\n\nConfigure CSP in `manifest.yml` for UI pages:\n\n```yaml\nui:\n  pages:\n    - name: my-page\n      csp:\n        connect_src:\n          - \"'self'\"\n          - \"https://api.crowdstrike.com\"\n        img_src:\n          - \"'self'\"\n          - \"data:\"\n        script_src:\n          - \"'self'\"\n```\n\n### Iframe Security for Extensions\n\nExtensions run in sandboxed iframes. Validate message origins against Falcon console domains:\n\n```typescript\nconst allowedOrigins = [\n  'https://falcon.crowdstrike.com',\n  'https://falcon.eu-1.crowdstrike.com',\n  'https://falcon.us-gov-1.crowdstrike.com',\n];\n\nwindow.addEventListener('message', (event) => {\n  if (!allowedOrigins.includes(event.origin)) return;\n  // Process event.data\n});\n```\n\nFor the full `SecureConsoleMessaging` class, see [references/security-examples.md](references/security-examples.md).\n\n## Manifest Security Configuration\n\n```yaml\napp:\n  name: \"my-security-app\"\n\noauth_scopes:\n  - \"alerts:read\"\n  - \"hosts:read\"\n\nfunctions:\n  - name: \"process-alerts\"\n    language: \"python\"\n    max_exec_duration_seconds: 30  # Prevent runaway execution\n    max_exec_memory_mb: 128        # Limit resource usage\n\ncollections:\n  - name: \"audit_logs\"\n    ttl: 86400  # Auto-expire sensitive data (24 hours)\n```\n\n## Test Data Security\n\n- Use only RFC 1918 IPs (`192.168.x.x`, `10.x.x.x`) in mock data\n- Use obviously fake hostnames and users (`test-workstation-01`, `test_user`)\n- Validate mock data does not contain production indicators (`crowdstrike.com`, `falcon-`, `prod-`)\n- Test XSS prevention with known attack vectors (`<script>`, `javascript:`, `onerror=`)\n\nSee [references/security-examples.md](references/security-examples.md) for mock data validation and CI/CD security patterns.\n\n## Pre-Deployment Checklist\n\n- [ ] OAuth scopes: minimal required permissions only\n- [ ] Input validation: JSON schemas enforce strict validation\n- [ ] XSS prevention: all user data sanitized before rendering\n- [ ] CSP headers: Content Security Policy configured\n- [ ] Postmessage security: origin validation implemented\n- [ ] Secret management: no hardcoded credentials\n- [ ] Function security: input size limits and timeout controls\n- [ ] Collection security: access controls and data sanitization\n- [ ] Test data: only fake data in tests and development\n- [ ] Error handling: no sensitive data in error messages or logs\n\n## Reading Guide\n\n| Task | Reference |\n|------|-----------|\n| Sanitization, command injection prevention, secure templates | [references/security-examples.md](references/security-examples.md) |\n| CI/CD security pipeline (GitHub Actions) | [references/security-examples.md](references/security-examples.md) |\n| PostMessage class, mock data validation | [references/security-examples.md](references/security-examples.md) |\n| Token lifecycle, antipatterns, manifest security, performance | [references/security-examples.md](references/security-examples.md) |\n"
AFTER
"---\nname: security-patterns\ndescription: Security patterns for Falcon Foundry apps including OAuth scopes, RBAC, input validation, UI security, and credential management. TRIGGER when user asks to \"configure OAuth scopes\", \"secure a Foundry app\", \"handle secrets\", \"add input validation\", or needs to review a Foundry app for security concerns (XSS, CSP, credential management). Also trigger during pre-deployment security reviews.\nversion: 1.6.0\nupdated: 2026-10-01\ntags: [foundry, oauth, rbac, xss, csp]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: security\n---\n\n# Foundry Security Patterns\n\n> **Part of a suite.** If `development-workflow` has not already run, and this is a new app or its first capability, load the `development-workflow` skill first — it owns the CLI prerequisite check, scaffolding order, and manifest coordination.\n\nSecurity patterns for Falcon Foundry app development covering authentication, input validation, UI security, and platform-specific considerations. Foundry apps run on a cybersecurity platform — security is a core requirement.\n\n## RBAC (Role-Based Access Control)\n\n| Capability | RBAC Supported |\n|-----------|----------------|\n| Collections | Yes |\n| Dashboards | Yes |\n| Functions | Yes |\n| UI extensions / pages / navigation | Yes |\n| RTR scripts | Yes |\n| API integrations | **No** |\n| Queries | **No** |\n| Workflows | **No** |\n\n## API Scope Management\n\nScopes control which Falcon Platform APIs the app can access. Format: `<source>:<operation>` (e.g., `devices:read`, `detects:write`).\n\n| Scopes set automatically | Scopes need explicit addition |\n|--------------------------|-------------------------------|\n| API integrations, Collections, Dashboards, Queries, UI navigation, UI sockets, Workflows | Functions, UI extensions, UI pages, RTR scripts |\n\n```bash\nfoundry auth roles create --name \"Analyst\" --description \"Read-only analyst access\"\nfoundry auth scopes add --scope \"devices:read\" --scope \"detects:read\"\n```\n\nOnly use `foundry auth scopes add` for Falcon Platform API scopes needed by functions, UI extensions, UI pages, or RTR scripts. OAuth scopes for CLI-created artifacts are managed automatically.\n\n### Minimal Scope Principle\n\nRequest only the scopes your app needs. Broad scopes like `alerts:*` or `devices:*` increase the blast radius if the app is compromised.\n\n```yaml\n# manifest.yml\nauth:\n  scopes:\n    - \"alerts:read\"      # Read alerts — avoid \"alerts:write\" unless needed\n    - \"detects:read\"     # Read detections\n    - \"devices:read\"     # Device information (Hosts API)\n```\n\n## Credential Security\n\nCredentials MUST be in environment variables, not in code. FalconPy handles credential discovery automatically inside FDK handlers (see functions-falcon-api):\n\n```python\n# Inside FDK handler — auth is automatic\nfalcon = Alerts()  # Do not pass credentials\n\n# Outside handler (local testing) — use env vars\n# FALCON_CLIENT_ID and FALCON_CLIENT_SECRET read automatically\n```\n\n## Input Validation\n\n### JSON Schema for Collections\n\nUse strict schemas to prevent data corruption and injection:\n\n```json\n{\n  \"type\": \"object\",\n  \"required\": [\"timestamp\", \"event_type\", \"source\"],\n  \"additionalProperties\": false,\n  \"properties\": {\n    \"event_type\": {\n      \"type\": \"string\",\n      \"enum\": [\"alert\", \"detection\", \"incident\"]\n    },\n    \"source\": {\n      \"type\": \"string\",\n      \"pattern\": \"^[a-zA-Z0-9_-]+$\",\n      \"maxLength\": 50\n    }\n  }\n}\n```\n\n### API Response Sanitization\n\nSanitize CrowdStrike API responses before storing in Collections: remove sensitive fields (`raw_log`, `internal_id`, `system_metadata`), strip script injection, escape HTML entities, and truncate strings. See [references/security-examples.md](references/security-examples.md) for full implementation.\n\n### Function Input Validation\n\nValidate that input is a dict and enforce size limits (e.g., 10KB) to prevent abuse. Return generic error messages — MUST NOT expose stack traces or internal state in responses.\n\n## UI Security\n\n### XSS Prevention\n\n- **React:** Use `DOMPurify.sanitize()` before any `dangerouslySetInnerHTML`. React auto-escapes `{}` expressions.\n- **Vue:** Use `DOMPurify.sanitize()` in a computed property before `v-html`. Vue auto-escapes `{{ }}` expressions.\n\nFor complete React and Vue XSS prevention components, see [references/security-examples.md](references/security-examples.md).\n\n### Content Security Policy\n\nConfigure CSP in `manifest.yml` for UI pages:\n\n```yaml\nui:\n  pages:\n    - name: my-page\n      csp:\n        connect_src:\n          - \"'self'\"\n          - \"https://api.crowdstrike.com\"\n        img_src:\n          - \"'self'\"\n          - \"data:\"\n        script_src:\n          - \"'self'\"\n```\n\n### Iframe Security for Extensions\n\nExtensions run in sandboxed iframes. Validate message origins against Falcon console domains:\n\n```typescript\nconst allowedOrigins = [\n  'https://falcon.crowdstrike.com',\n  'https://falcon.eu-1.crowdstrike.com',\n  'https://falcon.us-gov-1.crowdstrike.com',\n];\n\nwindow.addEventListener('message', (event) => {\n  if (!allowedOrigins.includes(event.origin)) return;\n  // Process event.data\n});\n```\n\nFor the full `SecureConsoleMessaging` class, see [references/security-examples.md](references/security-examples.md).\n\n## Manifest Security Configuration\n\n```yaml\napp:\n  name: \"my-security-app\"\n\nauth:\n  scopes:\n    - \"alerts:read\"\n    - \"devices:read\"\n\nfunctions:\n  - name: \"process-alerts\"\n    language: \"python\"\n    max_exec_duration_seconds: 30  # Prevent runaway execution\n    max_exec_memory_mb: 128        # Limit resource usage\n\ncollections:\n  - name: \"audit_logs\"\n    ttl: 86400  # Auto-expire sensitive data (24 hours)\n```\n\n## Test Data Security\n\n- Use only RFC 1918 IPs (`192.168.x.x`, `10.x.x.x`) in mock data\n- Use obviously fake hostnames and users (`test-workstation-01`, `test_user`)\n- Validate mock data does not contain production indicators (`crowdstrike.com`, `falcon-`, `prod-`)\n- Test XSS prevention with known attack vectors (`<script>`, `javascript:`, `onerror=`)\n\nSee [references/security-examples.md](references/security-examples.md) for mock data validation and CI/CD security patterns.\n\n## Pre-Deployment Checklist\n\n- [ ] OAuth scopes: minimal required permissions only\n- [ ] Input validation: JSON schemas enforce strict validation\n- [ ] XSS prevention: all user data sanitized before rendering\n- [ ] CSP headers: Content Security Policy configured\n- [ ] Postmessage security: origin validation implemented\n- [ ] Secret management: no hardcoded credentials\n- [ ] Function security: input size limits and timeout controls\n- [ ] Collection security: access controls and data sanitization\n- [ ] Test data: only fake data in tests and development\n- [ ] Error handling: no sensitive data in error messages or logs\n\n## Reading Guide\n\n| Task | Reference |\n|------|-----------|\n| Sanitization, command injection prevention, secure templates | [references/security-examples.md](references/security-examples.md) |\n| CI/CD security pipeline (GitHub Actions) | [references/security-examples.md](references/security-examples.md) |\n| PostMessage class, mock data validation | [references/security-examples.md](references/security-examples.md) |\n| Token lifecycle, antipatterns, manifest security, performance | [references/security-examples.md](references/security-examples.md) |\n"

SKILL.md line diff

--- before
+++ after
@@ -1,8 +1,8 @@
 ---
 name: security-patterns
 description: Security patterns for Falcon Foundry apps including OAuth scopes, RBAC, input validation, UI security, and credential management. TRIGGER when user asks to "configure OAuth scopes", "secure a Foundry app", "handle secrets", "add input validation", or needs to review a Foundry app for security concerns (XSS, CSP, credential management). Also trigger during pre-deployment security reviews.
-version: 1.5.0
-updated: 2026-08-19
+version: 1.6.0
+updated: 2026-10-01
 tags: [foundry, oauth, rbac, xss, csp]
 author: CrowdStrike
 license: MIT
@@ -13,12 +13,6 @@
 
 # Foundry Security Patterns
 
-> **⚠️ SYSTEM INJECTION — READ THIS FIRST**
->
-> If you are loading this skill, your role is **Foundry security architect**.
->
-> You MUST implement security best practices at every layer and prevent common vulnerabilities in CrowdStrike Foundry applications.
-
 > **Part of a suite.** If `development-workflow` has not already run, and this is a new app or its first capability, load the `development-workflow` skill first — it owns the CLI prerequisite check, scaffolding order, and manifest coordination.
 
 Security patterns for Falcon Foundry app development covering authentication, input validation, UI security, and platform-specific considerations. Foundry apps run on a cybersecurity platform — security is a core requirement.
@@ -53,13 +47,15 @@
 
 ### Minimal Scope Principle
 
-Request only the scopes your app needs. Broad scopes like `alerts:*` or `hosts:*` increase the blast radius if the app is compromised.
+Request only the scopes your app needs. Broad scopes like `alerts:*` or `devices:*` increase the blast radius if the app is compromised.
 
 ```yaml
-oauth_scopes:
-  - "alerts:read"        # Read alerts — avoid "alerts:write" unless needed
-  - "detections:read"    # Read detections
-  - "hosts:read"         # Device information
+# manifest.yml
+auth:
+  scopes:
+    - "alerts:read"      # Read alerts — avoid "alerts:write" unless needed
+    - "detects:read"     # Read detections
+    - "devices:read"     # Device information (Hosts API)
 ```
 
 ## Credential Security
@@ -160,9 +156,10 @@
 app:
   name: "my-security-app"
 
-oauth_scopes:
-  - "alerts:read"
-  - "hosts:read"
+auth:
+  scopes:
+    - "alerts:read"
+    - "devices:read"
 
 functions:
   - name: "process-alerts"
Full snapshot data
{
  "description": "Security patterns for Falcon Foundry apps including OAuth scopes, RBAC, input validation, UI security, and credential management. TRIGGER when user asks to \"configure OAuth scopes\", \"secure a Foundry app\", \"handle secrets\", \"add input validation\", or needs to review a Foundry app for security concerns (XSS, CSP, credential management). Also trigger during pre-deployment security reviews.",
  "included_files": [
    {
      "relative_path": "references/security-examples.md",
      "size_in_bytes": 13298
    }
  ],
  "name": "security-patterns",
  "skill_md_contents": "---\nname: security-patterns\ndescription: Security patterns for Falcon Foundry apps including OAuth scopes, RBAC, input validation, UI security, and credential management. TRIGGER when user asks to \"configure OAuth scopes\", \"secure a Foundry app\", \"handle secrets\", \"add input validation\", or needs to review a Foundry app for security concerns (XSS, CSP, credential management). Also trigger during pre-deployment security reviews.\nversion: 1.6.0\nupdated: 2026-10-01\ntags: [foundry, oauth, rbac, xss, csp]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: security\n---\n\n# Foundry Security Patterns\n\n> **Part of a suite.** If `development-workflow` has not already run, and this is a new app or its first capability, load the `development-workflow` skill first — it owns the CLI prerequisite check, scaffolding order, and manifest coordination.\n\nSecurity patterns for Falcon Foundry app development covering authentication, input validation, UI security, and platform-specific considerations. Foundry apps run on a cybersecurity platform — security is a core requirement.\n\n## RBAC (Role-Based Access Control)\n\n| Capability | RBAC Supported |\n|-----------|----------------|\n| Collections | Yes |\n| Dashboards | Yes |\n| Functions | Yes |\n| UI extensions / pages / navigation | Yes |\n| RTR scripts | Yes |\n| API integrations | **No** |\n| Queries | **No** |\n| Workflows | **No** |\n\n## API Scope Management\n\nScopes control which Falcon Platform APIs the app can access. Format: `<source>:<operation>` (e.g., `devices:read`, `detects:write`).\n\n| Scopes set automatically | Scopes need explicit addition |\n|--------------------------|-------------------------------|\n| API integrations, Collections, Dashboards, Queries, UI navigation, UI sockets, Workflows | Functions, UI extensions, UI pages, RTR scripts |\n\n```bash\nfoundry auth roles create --name \"Analyst\" --description \"Read-only analyst access\"\nfoundry auth scopes add --scope \"devices:read\" --scope \"detects:read\"\n```\n\nOnly use `foundry auth scopes add` for Falcon Platform API scopes needed by functions, UI extensions, UI pages, or RTR scripts. OAuth scopes for CLI-created artifacts are managed automatically.\n\n### Minimal Scope Principle\n\nRequest only the scopes your app needs. Broad scopes like `alerts:*` or `devices:*` increase the blast radius if the app is compromised.\n\n```yaml\n# manifest.yml\nauth:\n  scopes:\n    - \"alerts:read\"      # Read alerts — avoid \"alerts:write\" unless needed\n    - \"detects:read\"     # Read detections\n    - \"devices:read\"     # Device information (Hosts API)\n```\n\n## Credential Security\n\nCredentials MUST be in environment variables, not in code. FalconPy handles credential discovery automatically inside FDK handlers (see functions-falcon-api):\n\n```python\n# Inside FDK handler — auth is automatic\nfalcon = Alerts()  # Do not pass credentials\n\n# Outside handler (local testing) — use env vars\n# FALCON_CLIENT_ID and FALCON_CLIENT_SECRET read automatically\n```\n\n## Input Validation\n\n### JSON Schema for Collections\n\nUse strict schemas to prevent data corruption and injection:\n\n```json\n{\n  \"type\": \"object\",\n  \"required\": [\"timestamp\", \"event_type\", \"source\"],\n  \"additionalProperties\": false,\n  \"properties\": {\n    \"event_type\": {\n      \"type\": \"string\",\n      \"enum\": [\"alert\", \"detection\", \"incident\"]\n    },\n    \"source\": {\n      \"type\": \"string\",\n      \"pattern\": \"^[a-zA-Z0-9_-]+$\",\n      \"maxLength\": 50\n    }\n  }\n}\n```\n\n### API Response Sanitization\n\nSanitize CrowdStrike API responses before storing in Collections: remove sensitive fields (`raw_log`, `internal_id`, `system_metadata`), strip script injection, escape HTML entities, and truncate strings. See [references/security-examples.md](references/security-examples.md) for full implementation.\n\n### Function Input Validation\n\nValidate that input is a dict and enforce size limits (e.g., 10KB) to prevent abuse. Return generic error messages — MUST NOT expose stack traces or internal state in responses.\n\n## UI Security\n\n### XSS Prevention\n\n- **React:** Use `DOMPurify.sanitize()` before any `dangerouslySetInnerHTML`. React auto-escapes `{}` expressions.\n- **Vue:** Use `DOMPurify.sanitize()` in a computed property before `v-html`. Vue auto-escapes `{{ }}` expressions.\n\nFor complete React and Vue XSS prevention components, see [references/security-examples.md](references/security-examples.md).\n\n### Content Security Policy\n\nConfigure CSP in `manifest.yml` for UI pages:\n\n```yaml\nui:\n  pages:\n    - name: my-page\n      csp:\n        connect_src:\n          - \"'self'\"\n          - \"https://api.crowdstrike.com\"\n        img_src:\n          - \"'self'\"\n          - \"data:\"\n        script_src:\n          - \"'self'\"\n```\n\n### Iframe Security for Extensions\n\nExtensions run in sandboxed iframes. Validate message origins against Falcon console domains:\n\n```typescript\nconst allowedOrigins = [\n  'https://falcon.crowdstrike.com',\n  'https://falcon.eu-1.crowdstrike.com',\n  'https://falcon.us-gov-1.crowdstrike.com',\n];\n\nwindow.addEventListener('message', (event) => {\n  if (!allowedOrigins.includes(event.origin)) return;\n  // Process event.data\n});\n```\n\nFor the full `SecureConsoleMessaging` class, see [references/security-examples.md](references/security-examples.md).\n\n## Manifest Security Configuration\n\n```yaml\napp:\n  name: \"my-security-app\"\n\nauth:\n  scopes:\n    - \"alerts:read\"\n    - \"devices:read\"\n\nfunctions:\n  - name: \"process-alerts\"\n    language: \"python\"\n    max_exec_duration_seconds: 30  # Prevent runaway execution\n    max_exec_memory_mb: 128        # Limit resource usage\n\ncollections:\n  - name: \"audit_logs\"\n    ttl: 86400  # Auto-expire sensitive data (24 hours)\n```\n\n## Test Data Security\n\n- Use only RFC 1918 IPs (`192.168.x.x`, `10.x.x.x`) in mock data\n- Use obviously fake hostnames and users (`test-workstation-01`, `test_user`)\n- Validate mock data does not contain production indicators (`crowdstrike.com`, `falcon-`, `prod-`)\n- Test XSS prevention with known attack vectors (`<script>`, `javascript:`, `onerror=`)\n\nSee [references/security-examples.md](references/security-examples.md) for mock data validation and CI/CD security patterns.\n\n## Pre-Deployment Checklist\n\n- [ ] OAuth scopes: minimal required permissions only\n- [ ] Input validation: JSON schemas enforce strict validation\n- [ ] XSS prevention: all user data sanitized before rendering\n- [ ] CSP headers: Content Security Policy configured\n- [ ] Postmessage security: origin validation implemented\n- [ ] Secret management: no hardcoded credentials\n- [ ] Function security: input size limits and timeout controls\n- [ ] Collection security: access controls and data sanitization\n- [ ] Test data: only fake data in tests and development\n- [ ] Error handling: no sensitive data in error messages or logs\n\n## Reading Guide\n\n| Task | Reference |\n|------|-----------|\n| Sanitization, command injection prevention, secure templates | [references/security-examples.md](references/security-examples.md) |\n| CI/CD security pipeline (GitHub Actions) | [references/security-examples.md](references/security-examples.md) |\n| PostMessage class, mock data validation | [references/security-examples.md](references/security-examples.md) |\n| Token lifecycle, antipatterns, manifest security, performance | [references/security-examples.md](references/security-examples.md) |\n"
}

SHA-256 of public snapshot: a1d77df7819f50fe0ee3c39d010113757fc78c100387e22d81d84ff46cf0ac53