Update to CrowdStrike Falcon Fusion
Snapshot Oct 8, 2026 · 18:03 UTC · version 1.3.0
Collection source: downloaded plugin package. These snapshots do not have a confirmed matching collection source. Differences in file lists alone do not establish changes to the package.
Instructions updated for foundry-redirect
Instruction wording changed from “Claude” to “plugin”. 7 additional added or edited lines are in the evidence.
Observed in instructions or declared skills. Runtime behavior has not been tested.
Product description
Claude Code hooks; it yields to the real Foundry plugin when that plugin is also installed.
plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.
Skill instructions
Claude Code hooks; it yields to the real Foundry plugin when that plugin is also installed. version: 1.2.0 updated: 2026-09-08 prompt never loads it. On Claude Code a hook covers that gap; on Codex, Copilot CLI, Cursor, and the Agent S...
plugin hooks; it yields to the real Foundry plugin when that plugin is also installed. version: 1.3.0 updated: 2026-10-01 prompt never loads it. On Claude Code, Codex, Copilot CLI, and Cursor a hook covers that gap. On assistants that ...
Compare saved observations
Download comparison JSONFull technical diff · 2 changed fields
changed /description
"TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without Claude Code hooks; it yields to the real Foundry plugin when that plugin is also installed."
"TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n"
changed /skill_md_contents
"---\nname: foundry-redirect\ndescription: >\n TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\",\n mentions manifest.yml, or needs a UI page/extension, serverless function,\n collection, or a custom API integration from a third-party API (Okta, ServiceNow,\n Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires\n together existing actions. This skill declines Foundry-app requests and points to\n the crowdstrike-falcon-foundry plugin, so the redirect works even without Claude\n Code hooks; it yields to the real Foundry plugin when that plugin is also installed.\nversion: 1.2.0\nupdated: 2026-09-08\ntags: [fusion, foundry, redirect, routing]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n category: routing\n---\n\n# Falcon Foundry Redirect\n\nIf this skill triggered, the request is a **Falcon Foundry app**, not a standalone\nFalcon Fusion workflow. It belongs to the sibling Falcon Foundry plugin — the\n`fusion-skills` plugin builds Fusion workflows only.\n\nWhy this skill exists: the `workflows` orchestrator declines Foundry-app requests too,\nbut its description matches *Fusion workflow* language, so a \"build a Foundry app\"\nprompt never loads it. On Claude Code a hook covers that gap; on Codex, Copilot CLI,\nCursor, and the Agent SDK there are no hooks, so this skill — whose description matches\nFoundry-app language directly — is what makes the redirect reachable.\n\n## What to do\n\nDo NOT author workflow YAML. Do NOT scaffold an app yourself. Respond with all three:\n\n1. State plainly that this request needs a Falcon Foundry app, not a standalone Fusion workflow.\n2. Name the plugin: **`crowdstrike-falcon-foundry`**.\n3. How to install it: `/plugin install crowdstrike-falcon-foundry`, or clone https://github.com/CrowdStrike/foundry-skills.\n\n## When both plugins are installed\n\nIf `crowdstrike-falcon-foundry` is present, its own `development-workflow` skill matches\nFoundry-app requests directly and handles them — a stronger match than this one, so the\nagent picks it and this redirect never fires. That is correct: this skill is the safety\nnet for when the Foundry plugin is absent, not a competitor with it when present.\n\n## Foundry app vs. standalone workflow\n\n| Signal in the request | Route |\n|---|---|\n| \"Foundry app\", `manifest.yml`, a UI page/extension, serverless function, collection, or custom third-party API integration | **Here** — redirect to foundry-skills |\n| A trigger plus existing Fusion actions only (no UI, function, collection, or custom integration) | **`workflows`** — handle it as a standalone workflow |\n| \"a workflow inside a Foundry app\" | **Here** — the app owns the workflow; Foundry scaffolds it |\n| Fetch/summarize a population of alerts/detections the workflow doesn't already hold | **`workflows`** — a standalone CrowdStrike HTTP Request handles this without an app |\n"
"---\nname: foundry-redirect\ndescription: >\n TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\",\n mentions manifest.yml, or needs a UI page/extension, serverless function,\n collection, or a custom API integration from a third-party API (Okta, ServiceNow,\n Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires\n together existing actions. This skill declines Foundry-app requests and points to\n the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin\n hooks; it yields to the real Foundry plugin when that plugin is also installed.\nversion: 1.3.0\nupdated: 2026-10-01\ntags: [fusion, foundry, redirect, routing]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n category: routing\n---\n\n# Falcon Foundry Redirect\n\nIf this skill triggered, the request is a **Falcon Foundry app**, not a standalone\nFalcon Fusion workflow. It belongs to the sibling Falcon Foundry plugin — the\n`fusion-skills` plugin builds Fusion workflows only.\n\nWhy this skill exists: the `workflows` orchestrator declines Foundry-app requests too,\nbut its description matches *Fusion workflow* language, so a \"build a Foundry app\"\nprompt never loads it. On Claude Code, Codex, Copilot CLI, and Cursor a hook covers that gap. On\nassistants that do not load plugin hooks, this skill's description matches Foundry-app\nlanguage directly and makes the redirect reachable.\n\n## What to do\n\nDo NOT author workflow YAML. Do NOT scaffold an app yourself. Respond with all three:\n\n1. State plainly that this request needs a Falcon Foundry app, not a standalone Fusion workflow.\n2. Name the plugin: **`crowdstrike-falcon-foundry`**.\n3. How to install it: `/plugin install crowdstrike-falcon-foundry` in Claude Code, `/plugins` in Codex, `copilot plugin install CrowdStrike/foundry-skills` in Copilot CLI, `/add-plugin crowdstrike-falcon-foundry` in Cursor, or clone https://github.com/CrowdStrike/foundry-skills.\n\n## When both plugins are installed\n\nIf `crowdstrike-falcon-foundry` is present, its own `development-workflow` skill matches\nFoundry-app requests directly and handles them — a stronger match than this one, so the\nagent picks it and this redirect never fires. That is correct: this skill is the safety\nnet for when the Foundry plugin is absent, not a competitor with it when present.\n\n## Foundry app vs. standalone workflow\n\n| Signal in the request | Route |\n|---|---|\n| \"Foundry app\", `manifest.yml`, a UI page/extension, serverless function, collection, or custom third-party API integration | **Here** — redirect to foundry-skills |\n| A trigger plus existing Fusion actions only (no UI, function, collection, or custom integration) | **`workflows`** — handle it as a standalone workflow |\n| \"a workflow inside a Foundry app\" | **Here** — the app owns the workflow; Foundry scaffolds it |\n| Fetch/summarize a population of alerts/detections the workflow doesn't already hold | **`workflows`** — a standalone CrowdStrike HTTP Request handles this without an app |\n"
SKILL.md line diff
--- before +++ after @@ -6,10 +6,10 @@ collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to - the crowdstrike-falcon-foundry plugin, so the redirect works even without Claude - Code hooks; it yields to the real Foundry plugin when that plugin is also installed. -version: 1.2.0 -updated: 2026-09-08 + the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin + hooks; it yields to the real Foundry plugin when that plugin is also installed. +version: 1.3.0 +updated: 2026-10-01 tags: [fusion, foundry, redirect, routing] author: CrowdStrike license: MIT @@ -26,9 +26,9 @@ Why this skill exists: the `workflows` orchestrator declines Foundry-app requests too, but its description matches *Fusion workflow* language, so a "build a Foundry app" -prompt never loads it. On Claude Code a hook covers that gap; on Codex, Copilot CLI, -Cursor, and the Agent SDK there are no hooks, so this skill — whose description matches -Foundry-app language directly — is what makes the redirect reachable. +prompt never loads it. On Claude Code, Codex, Copilot CLI, and Cursor a hook covers that gap. On +assistants that do not load plugin hooks, this skill's description matches Foundry-app +language directly and makes the redirect reachable. ## What to do @@ -36,7 +36,7 @@ 1. State plainly that this request needs a Falcon Foundry app, not a standalone Fusion workflow. 2. Name the plugin: **`crowdstrike-falcon-foundry`**. -3. How to install it: `/plugin install crowdstrike-falcon-foundry`, or clone https://github.com/CrowdStrike/foundry-skills. +3. How to install it: `/plugin install crowdstrike-falcon-foundry` in Claude Code, `/plugins` in Codex, `copilot plugin install CrowdStrike/foundry-skills` in Copilot CLI, `/add-plugin crowdstrike-falcon-foundry` in Cursor, or clone https://github.com/CrowdStrike/foundry-skills. ## When both plugins are installed
Full snapshot data
{
"description": "TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n",
"included_files": [],
"name": "foundry-redirect",
"skill_md_contents": "---\nname: foundry-redirect\ndescription: >\n TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\",\n mentions manifest.yml, or needs a UI page/extension, serverless function,\n collection, or a custom API integration from a third-party API (Okta, ServiceNow,\n Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires\n together existing actions. This skill declines Foundry-app requests and points to\n the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin\n hooks; it yields to the real Foundry plugin when that plugin is also installed.\nversion: 1.3.0\nupdated: 2026-10-01\ntags: [fusion, foundry, redirect, routing]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n category: routing\n---\n\n# Falcon Foundry Redirect\n\nIf this skill triggered, the request is a **Falcon Foundry app**, not a standalone\nFalcon Fusion workflow. It belongs to the sibling Falcon Foundry plugin — the\n`fusion-skills` plugin builds Fusion workflows only.\n\nWhy this skill exists: the `workflows` orchestrator declines Foundry-app requests too,\nbut its description matches *Fusion workflow* language, so a \"build a Foundry app\"\nprompt never loads it. On Claude Code, Codex, Copilot CLI, and Cursor a hook covers that gap. On\nassistants that do not load plugin hooks, this skill's description matches Foundry-app\nlanguage directly and makes the redirect reachable.\n\n## What to do\n\nDo NOT author workflow YAML. Do NOT scaffold an app yourself. Respond with all three:\n\n1. State plainly that this request needs a Falcon Foundry app, not a standalone Fusion workflow.\n2. Name the plugin: **`crowdstrike-falcon-foundry`**.\n3. How to install it: `/plugin install crowdstrike-falcon-foundry` in Claude Code, `/plugins` in Codex, `copilot plugin install CrowdStrike/foundry-skills` in Copilot CLI, `/add-plugin crowdstrike-falcon-foundry` in Cursor, or clone https://github.com/CrowdStrike/foundry-skills.\n\n## When both plugins are installed\n\nIf `crowdstrike-falcon-foundry` is present, its own `development-workflow` skill matches\nFoundry-app requests directly and handles them — a stronger match than this one, so the\nagent picks it and this redirect never fires. That is correct: this skill is the safety\nnet for when the Foundry plugin is absent, not a competitor with it when present.\n\n## Foundry app vs. standalone workflow\n\n| Signal in the request | Route |\n|---|---|\n| \"Foundry app\", `manifest.yml`, a UI page/extension, serverless function, collection, or custom third-party API integration | **Here** — redirect to foundry-skills |\n| A trigger plus existing Fusion actions only (no UI, function, collection, or custom integration) | **`workflows`** — handle it as a standalone workflow |\n| \"a workflow inside a Foundry app\" | **Here** — the app owns the workflow; Foundry scaffolds it |\n| Fetch/summarize a population of alerts/detections the workflow doesn't already hold | **`workflows`** — a standalone CrowdStrike HTTP Request handles this without an app |\n"
}SHA-256 of public snapshot: 2dde0ebb6d4d9efd37e4a70f93e7c2429438a8db4abcb737cfb5432142e4ebf0