← CrowdStrike Falcon FusionCONTENT HISTORY

Update to CrowdStrike Falcon Fusion

Snapshot Oct 8, 2026 · 18:03 UTC · version 1.3.0

Collection source: downloaded plugin package. These snapshots do not have a confirmed matching collection source. Differences in file lists alone do not establish changes to the package.

WHAT CHANGED · RULE-BASED ANALYSIS

Instructions updated for foundry-redirect

Instruction wording changed from “Claude” to “plugin”. 7 additional added or edited lines are in the evidence.

Observed in instructions or declared skills. Runtime behavior has not been tested.

Product description

Before

Claude Code hooks; it yields to the real Foundry plugin when that plugin is also installed.

After

plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.

Skill instructions

Before

Claude Code hooks; it yields to the real Foundry plugin when that plugin is also installed. version: 1.2.0 updated: 2026-09-08 prompt never loads it. On Claude Code a hook covers that gap; on Codex, Copilot CLI, Cursor, and the Agent S...

After

plugin hooks; it yields to the real Foundry plugin when that plugin is also installed. version: 1.3.0 updated: 2026-10-01 prompt never loads it. On Claude Code, Codex, Copilot CLI, and Cursor a hook covers that gap. On assistants that ...

Compare saved observations

Download comparison JSON
Full technical diff · 2 changed fields

changed /description

BEFORE
"TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without Claude Code hooks; it yields to the real Foundry plugin when that plugin is also installed."
AFTER
"TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n"

changed /skill_md_contents

BEFORE
"---\nname: foundry-redirect\ndescription: >\n  TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\",\n  mentions manifest.yml, or needs a UI page/extension, serverless function,\n  collection, or a custom API integration from a third-party API (Okta, ServiceNow,\n  Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires\n  together existing actions. This skill declines Foundry-app requests and points to\n  the crowdstrike-falcon-foundry plugin, so the redirect works even without Claude\n  Code hooks; it yields to the real Foundry plugin when that plugin is also installed.\nversion: 1.2.0\nupdated: 2026-09-08\ntags: [fusion, foundry, redirect, routing]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: routing\n---\n\n# Falcon Foundry Redirect\n\nIf this skill triggered, the request is a **Falcon Foundry app**, not a standalone\nFalcon Fusion workflow. It belongs to the sibling Falcon Foundry plugin — the\n`fusion-skills` plugin builds Fusion workflows only.\n\nWhy this skill exists: the `workflows` orchestrator declines Foundry-app requests too,\nbut its description matches *Fusion workflow* language, so a \"build a Foundry app\"\nprompt never loads it. On Claude Code a hook covers that gap; on Codex, Copilot CLI,\nCursor, and the Agent SDK there are no hooks, so this skill — whose description matches\nFoundry-app language directly — is what makes the redirect reachable.\n\n## What to do\n\nDo NOT author workflow YAML. Do NOT scaffold an app yourself. Respond with all three:\n\n1. State plainly that this request needs a Falcon Foundry app, not a standalone Fusion workflow.\n2. Name the plugin: **`crowdstrike-falcon-foundry`**.\n3. How to install it: `/plugin install crowdstrike-falcon-foundry`, or clone https://github.com/CrowdStrike/foundry-skills.\n\n## When both plugins are installed\n\nIf `crowdstrike-falcon-foundry` is present, its own `development-workflow` skill matches\nFoundry-app requests directly and handles them — a stronger match than this one, so the\nagent picks it and this redirect never fires. That is correct: this skill is the safety\nnet for when the Foundry plugin is absent, not a competitor with it when present.\n\n## Foundry app vs. standalone workflow\n\n| Signal in the request | Route |\n|---|---|\n| \"Foundry app\", `manifest.yml`, a UI page/extension, serverless function, collection, or custom third-party API integration | **Here** — redirect to foundry-skills |\n| A trigger plus existing Fusion actions only (no UI, function, collection, or custom integration) | **`workflows`** — handle it as a standalone workflow |\n| \"a workflow inside a Foundry app\" | **Here** — the app owns the workflow; Foundry scaffolds it |\n| Fetch/summarize a population of alerts/detections the workflow doesn't already hold | **`workflows`** — a standalone CrowdStrike HTTP Request handles this without an app |\n"
AFTER
"---\nname: foundry-redirect\ndescription: >\n  TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\",\n  mentions manifest.yml, or needs a UI page/extension, serverless function,\n  collection, or a custom API integration from a third-party API (Okta, ServiceNow,\n  Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires\n  together existing actions. This skill declines Foundry-app requests and points to\n  the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin\n  hooks; it yields to the real Foundry plugin when that plugin is also installed.\nversion: 1.3.0\nupdated: 2026-10-01\ntags: [fusion, foundry, redirect, routing]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: routing\n---\n\n# Falcon Foundry Redirect\n\nIf this skill triggered, the request is a **Falcon Foundry app**, not a standalone\nFalcon Fusion workflow. It belongs to the sibling Falcon Foundry plugin — the\n`fusion-skills` plugin builds Fusion workflows only.\n\nWhy this skill exists: the `workflows` orchestrator declines Foundry-app requests too,\nbut its description matches *Fusion workflow* language, so a \"build a Foundry app\"\nprompt never loads it. On Claude Code, Codex, Copilot CLI, and Cursor a hook covers that gap. On\nassistants that do not load plugin hooks, this skill's description matches Foundry-app\nlanguage directly and makes the redirect reachable.\n\n## What to do\n\nDo NOT author workflow YAML. Do NOT scaffold an app yourself. Respond with all three:\n\n1. State plainly that this request needs a Falcon Foundry app, not a standalone Fusion workflow.\n2. Name the plugin: **`crowdstrike-falcon-foundry`**.\n3. How to install it: `/plugin install crowdstrike-falcon-foundry` in Claude Code, `/plugins` in Codex, `copilot plugin install CrowdStrike/foundry-skills` in Copilot CLI, `/add-plugin crowdstrike-falcon-foundry` in Cursor, or clone https://github.com/CrowdStrike/foundry-skills.\n\n## When both plugins are installed\n\nIf `crowdstrike-falcon-foundry` is present, its own `development-workflow` skill matches\nFoundry-app requests directly and handles them — a stronger match than this one, so the\nagent picks it and this redirect never fires. That is correct: this skill is the safety\nnet for when the Foundry plugin is absent, not a competitor with it when present.\n\n## Foundry app vs. standalone workflow\n\n| Signal in the request | Route |\n|---|---|\n| \"Foundry app\", `manifest.yml`, a UI page/extension, serverless function, collection, or custom third-party API integration | **Here** — redirect to foundry-skills |\n| A trigger plus existing Fusion actions only (no UI, function, collection, or custom integration) | **`workflows`** — handle it as a standalone workflow |\n| \"a workflow inside a Foundry app\" | **Here** — the app owns the workflow; Foundry scaffolds it |\n| Fetch/summarize a population of alerts/detections the workflow doesn't already hold | **`workflows`** — a standalone CrowdStrike HTTP Request handles this without an app |\n"

SKILL.md line diff

--- before
+++ after
@@ -6,10 +6,10 @@
   collection, or a custom API integration from a third-party API (Okta, ServiceNow,
   Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires
   together existing actions. This skill declines Foundry-app requests and points to
-  the crowdstrike-falcon-foundry plugin, so the redirect works even without Claude
-  Code hooks; it yields to the real Foundry plugin when that plugin is also installed.
-version: 1.2.0
-updated: 2026-09-08
+  the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin
+  hooks; it yields to the real Foundry plugin when that plugin is also installed.
+version: 1.3.0
+updated: 2026-10-01
 tags: [fusion, foundry, redirect, routing]
 author: CrowdStrike
 license: MIT
@@ -26,9 +26,9 @@
 
 Why this skill exists: the `workflows` orchestrator declines Foundry-app requests too,
 but its description matches *Fusion workflow* language, so a "build a Foundry app"
-prompt never loads it. On Claude Code a hook covers that gap; on Codex, Copilot CLI,
-Cursor, and the Agent SDK there are no hooks, so this skill — whose description matches
-Foundry-app language directly — is what makes the redirect reachable.
+prompt never loads it. On Claude Code, Codex, Copilot CLI, and Cursor a hook covers that gap. On
+assistants that do not load plugin hooks, this skill's description matches Foundry-app
+language directly and makes the redirect reachable.
 
 ## What to do
 
@@ -36,7 +36,7 @@
 
 1. State plainly that this request needs a Falcon Foundry app, not a standalone Fusion workflow.
 2. Name the plugin: **`crowdstrike-falcon-foundry`**.
-3. How to install it: `/plugin install crowdstrike-falcon-foundry`, or clone https://github.com/CrowdStrike/foundry-skills.
+3. How to install it: `/plugin install crowdstrike-falcon-foundry` in Claude Code, `/plugins` in Codex, `copilot plugin install CrowdStrike/foundry-skills` in Copilot CLI, `/add-plugin crowdstrike-falcon-foundry` in Cursor, or clone https://github.com/CrowdStrike/foundry-skills.
 
 ## When both plugins are installed
 
Full snapshot data
{
  "description": "TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n",
  "included_files": [],
  "name": "foundry-redirect",
  "skill_md_contents": "---\nname: foundry-redirect\ndescription: >\n  TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\",\n  mentions manifest.yml, or needs a UI page/extension, serverless function,\n  collection, or a custom API integration from a third-party API (Okta, ServiceNow,\n  Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires\n  together existing actions. This skill declines Foundry-app requests and points to\n  the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin\n  hooks; it yields to the real Foundry plugin when that plugin is also installed.\nversion: 1.3.0\nupdated: 2026-10-01\ntags: [fusion, foundry, redirect, routing]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: routing\n---\n\n# Falcon Foundry Redirect\n\nIf this skill triggered, the request is a **Falcon Foundry app**, not a standalone\nFalcon Fusion workflow. It belongs to the sibling Falcon Foundry plugin — the\n`fusion-skills` plugin builds Fusion workflows only.\n\nWhy this skill exists: the `workflows` orchestrator declines Foundry-app requests too,\nbut its description matches *Fusion workflow* language, so a \"build a Foundry app\"\nprompt never loads it. On Claude Code, Codex, Copilot CLI, and Cursor a hook covers that gap. On\nassistants that do not load plugin hooks, this skill's description matches Foundry-app\nlanguage directly and makes the redirect reachable.\n\n## What to do\n\nDo NOT author workflow YAML. Do NOT scaffold an app yourself. Respond with all three:\n\n1. State plainly that this request needs a Falcon Foundry app, not a standalone Fusion workflow.\n2. Name the plugin: **`crowdstrike-falcon-foundry`**.\n3. How to install it: `/plugin install crowdstrike-falcon-foundry` in Claude Code, `/plugins` in Codex, `copilot plugin install CrowdStrike/foundry-skills` in Copilot CLI, `/add-plugin crowdstrike-falcon-foundry` in Cursor, or clone https://github.com/CrowdStrike/foundry-skills.\n\n## When both plugins are installed\n\nIf `crowdstrike-falcon-foundry` is present, its own `development-workflow` skill matches\nFoundry-app requests directly and handles them — a stronger match than this one, so the\nagent picks it and this redirect never fires. That is correct: this skill is the safety\nnet for when the Foundry plugin is absent, not a competitor with it when present.\n\n## Foundry app vs. standalone workflow\n\n| Signal in the request | Route |\n|---|---|\n| \"Foundry app\", `manifest.yml`, a UI page/extension, serverless function, collection, or custom third-party API integration | **Here** — redirect to foundry-skills |\n| A trigger plus existing Fusion actions only (no UI, function, collection, or custom integration) | **`workflows`** — handle it as a standalone workflow |\n| \"a workflow inside a Foundry app\" | **Here** — the app owns the workflow; Foundry scaffolds it |\n| Fetch/summarize a population of alerts/detections the workflow doesn't already hold | **`workflows`** — a standalone CrowdStrike HTTP Request handles this without an app |\n"
}

SHA-256 of public snapshot: 2dde0ebb6d4d9efd37e4a70f93e7c2429438a8db4abcb737cfb5432142e4ebf0