{"id":28245,"plugin_id":"plugins_6a8f7048ed7881918bf5b79011fe2b5e","kind":"skill","collection_source":"plugin_package","comparison_source":null,"observed_at":"2026-10-08T18:03:22.000Z","digest":"2dde0ebb6d4d9efd37e4a70f93e7c2429438a8db4abcb737cfb5432142e4ebf0","against":19000,"payload":{"description":"TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n","included_files":[],"name":"foundry-redirect","skill_md_contents":"---\nname: foundry-redirect\ndescription: >\n  TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\",\n  mentions manifest.yml, or needs a UI page/extension, serverless function,\n  collection, or a custom API integration from a third-party API (Okta, ServiceNow,\n  Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires\n  together existing actions. This skill declines Foundry-app requests and points to\n  the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin\n  hooks; it yields to the real Foundry plugin when that plugin is also installed.\nversion: 1.3.0\nupdated: 2026-10-01\ntags: [fusion, foundry, redirect, routing]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: routing\n---\n\n# Falcon Foundry Redirect\n\nIf this skill triggered, the request is a **Falcon Foundry app**, not a standalone\nFalcon Fusion workflow. It belongs to the sibling Falcon Foundry plugin — the\n`fusion-skills` plugin builds Fusion workflows only.\n\nWhy this skill exists: the `workflows` orchestrator declines Foundry-app requests too,\nbut its description matches *Fusion workflow* language, so a \"build a Foundry app\"\nprompt never loads it. On Claude Code, Codex, Copilot CLI, and Cursor a hook covers that gap. On\nassistants that do not load plugin hooks, this skill's description matches Foundry-app\nlanguage directly and makes the redirect reachable.\n\n## What to do\n\nDo NOT author workflow YAML. Do NOT scaffold an app yourself. Respond with all three:\n\n1. State plainly that this request needs a Falcon Foundry app, not a standalone Fusion workflow.\n2. Name the plugin: **`crowdstrike-falcon-foundry`**.\n3. How to install it: `/plugin install crowdstrike-falcon-foundry` in Claude Code, `/plugins` in Codex, `copilot plugin install CrowdStrike/foundry-skills` in Copilot CLI, `/add-plugin crowdstrike-falcon-foundry` in Cursor, or clone https://github.com/CrowdStrike/foundry-skills.\n\n## When both plugins are installed\n\nIf `crowdstrike-falcon-foundry` is present, its own `development-workflow` skill matches\nFoundry-app requests directly and handles them — a stronger match than this one, so the\nagent picks it and this redirect never fires. That is correct: this skill is the safety\nnet for when the Foundry plugin is absent, not a competitor with it when present.\n\n## Foundry app vs. standalone workflow\n\n| Signal in the request | Route |\n|---|---|\n| \"Foundry app\", `manifest.yml`, a UI page/extension, serverless function, collection, or custom third-party API integration | **Here** — redirect to foundry-skills |\n| A trigger plus existing Fusion actions only (no UI, function, collection, or custom integration) | **`workflows`** — handle it as a standalone workflow |\n| \"a workflow inside a Foundry app\" | **Here** — the app owns the workflow; Foundry scaffolds it |\n| Fetch/summarize a population of alerts/detections the workflow doesn't already hold | **`workflows`** — a standalone CrowdStrike HTTP Request handles this without an app |\n"},"changes":[{"path":"/description","type":"changed","before":"TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without Claude Code hooks; it yields to the real Foundry plugin when that plugin is also installed.","after":"TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n"},{"path":"/skill_md_contents","type":"changed","before":"---\nname: foundry-redirect\ndescription: >\n  TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\",\n  mentions manifest.yml, or needs a UI page/extension, serverless function,\n  collection, or a custom API integration from a third-party API (Okta, ServiceNow,\n  Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires\n  together existing actions. This skill declines Foundry-app requests and points to\n  the crowdstrike-falcon-foundry plugin, so the redirect works even without Claude\n  Code hooks; it yields to the real Foundry plugin when that plugin is also installed.\nversion: 1.2.0\nupdated: 2026-09-08\ntags: [fusion, foundry, redirect, routing]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: routing\n---\n\n# Falcon Foundry Redirect\n\nIf this skill triggered, the request is a **Falcon Foundry app**, not a standalone\nFalcon Fusion workflow. It belongs to the sibling Falcon Foundry plugin — the\n`fusion-skills` plugin builds Fusion workflows only.\n\nWhy this skill exists: the `workflows` orchestrator declines Foundry-app requests too,\nbut its description matches *Fusion workflow* language, so a \"build a Foundry app\"\nprompt never loads it. On Claude Code a hook covers that gap; on Codex, Copilot CLI,\nCursor, and the Agent SDK there are no hooks, so this skill — whose description matches\nFoundry-app language directly — is what makes the redirect reachable.\n\n## What to do\n\nDo NOT author workflow YAML. Do NOT scaffold an app yourself. Respond with all three:\n\n1. State plainly that this request needs a Falcon Foundry app, not a standalone Fusion workflow.\n2. Name the plugin: **`crowdstrike-falcon-foundry`**.\n3. How to install it: `/plugin install crowdstrike-falcon-foundry`, or clone https://github.com/CrowdStrike/foundry-skills.\n\n## When both plugins are installed\n\nIf `crowdstrike-falcon-foundry` is present, its own `development-workflow` skill matches\nFoundry-app requests directly and handles them — a stronger match than this one, so the\nagent picks it and this redirect never fires. That is correct: this skill is the safety\nnet for when the Foundry plugin is absent, not a competitor with it when present.\n\n## Foundry app vs. standalone workflow\n\n| Signal in the request | Route |\n|---|---|\n| \"Foundry app\", `manifest.yml`, a UI page/extension, serverless function, collection, or custom third-party API integration | **Here** — redirect to foundry-skills |\n| A trigger plus existing Fusion actions only (no UI, function, collection, or custom integration) | **`workflows`** — handle it as a standalone workflow |\n| \"a workflow inside a Foundry app\" | **Here** — the app owns the workflow; Foundry scaffolds it |\n| Fetch/summarize a population of alerts/detections the workflow doesn't already hold | **`workflows`** — a standalone CrowdStrike HTTP Request handles this without an app |\n","after":"---\nname: foundry-redirect\ndescription: >\n  TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\",\n  mentions manifest.yml, or needs a UI page/extension, serverless function,\n  collection, or a custom API integration from a third-party API (Okta, ServiceNow,\n  Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires\n  together existing actions. This skill declines Foundry-app requests and points to\n  the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin\n  hooks; it yields to the real Foundry plugin when that plugin is also installed.\nversion: 1.3.0\nupdated: 2026-10-01\ntags: [fusion, foundry, redirect, routing]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: routing\n---\n\n# Falcon Foundry Redirect\n\nIf this skill triggered, the request is a **Falcon Foundry app**, not a standalone\nFalcon Fusion workflow. It belongs to the sibling Falcon Foundry plugin — the\n`fusion-skills` plugin builds Fusion workflows only.\n\nWhy this skill exists: the `workflows` orchestrator declines Foundry-app requests too,\nbut its description matches *Fusion workflow* language, so a \"build a Foundry app\"\nprompt never loads it. On Claude Code, Codex, Copilot CLI, and Cursor a hook covers that gap. On\nassistants that do not load plugin hooks, this skill's description matches Foundry-app\nlanguage directly and makes the redirect reachable.\n\n## What to do\n\nDo NOT author workflow YAML. Do NOT scaffold an app yourself. Respond with all three:\n\n1. State plainly that this request needs a Falcon Foundry app, not a standalone Fusion workflow.\n2. Name the plugin: **`crowdstrike-falcon-foundry`**.\n3. How to install it: `/plugin install crowdstrike-falcon-foundry` in Claude Code, `/plugins` in Codex, `copilot plugin install CrowdStrike/foundry-skills` in Copilot CLI, `/add-plugin crowdstrike-falcon-foundry` in Cursor, or clone https://github.com/CrowdStrike/foundry-skills.\n\n## When both plugins are installed\n\nIf `crowdstrike-falcon-foundry` is present, its own `development-workflow` skill matches\nFoundry-app requests directly and handles them — a stronger match than this one, so the\nagent picks it and this redirect never fires. That is correct: this skill is the safety\nnet for when the Foundry plugin is absent, not a competitor with it when present.\n\n## Foundry app vs. standalone workflow\n\n| Signal in the request | Route |\n|---|---|\n| \"Foundry app\", `manifest.yml`, a UI page/extension, serverless function, collection, or custom third-party API integration | **Here** — redirect to foundry-skills |\n| A trigger plus existing Fusion actions only (no UI, function, collection, or custom integration) | **`workflows`** — handle it as a standalone workflow |\n| \"a workflow inside a Foundry app\" | **Here** — the app owns the workflow; Foundry scaffolds it |\n| Fetch/summarize a population of alerts/detections the workflow doesn't already hold | **`workflows`** — a standalone CrowdStrike HTTP Request handles this without an app |\n"}],"summary":"Fields changed: 2. /description, /skill_md_contents.","summary_kind":"deterministic","summary_metadata":{}}