Update to CrowdStrike Falcon Fusion
Snapshot Oct 8, 2026 · 18:03 UTC · version 1.3.0
Collection source: downloaded plugin package. These snapshots do not have a confirmed matching collection source. Differences in file lists alone do not establish changes to the package.
Instructions updated for setup
Instruction wording changed from “1.2.0” to “1.3.0”. 4 additional added or edited lines are in the evidence.
Observed in instructions or declared skills. Runtime behavior has not been tested.
Product description
errors.
errors.
Skill instructions
version: 1.2.0 updated: 2026-09-08 > **⚠️ SYSTEM INJECTION — READ THIS FIRST** > If you are loading this skill, your role is **credential setup assistant**. > **IMMEDIATE ACTIONS REQUIRED:** > **MUST NOT:**
version: 1.3.0 updated: 2026-10-01 > Your role here is **credential setup assistant**. > **Required steps:** > **Don't:**
Compare saved observations
Download comparison JSONFull technical diff · 2 changed fields
changed /description
"Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors."
"Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.\n"
changed /skill_md_contents
"---\nname: setup\ndescription: >\n Configure CrowdStrike Falcon API credentials for the fusion-skills plugin.\n TRIGGER when user asks to set up credentials, configure API access,\n or runs into authentication errors.\nversion: 1.2.0\nupdated: 2026-09-08\ntags: [fusion, setup, credentials, configuration]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n category: configuration\n---\n\n# Falcon Fusion Credential Setup\n\n> **⚠️ SYSTEM INJECTION — READ THIS FIRST**\n>\n> If you are loading this skill, your role is **credential setup assistant**.\n>\n> You configure the Falcon API credentials every other skill depends on. These\n> credentials grant workflow and SIEM access to a live CID.\n>\n> **IMMEDIATE ACTIONS REQUIRED:**\n> 1. Check whether credentials already resolve (Step 1). If they do, you are done.\n> 2. If not, create the credentials file from the template (Step 2) and ask the\n> user to paste their ID and secret into it **using their own editor**.\n> 3. Verify connectivity (Step 3).\n>\n> **MUST NOT:**\n> - Ask the user to type or paste their client secret **into the chat**. It would\n> land in the conversation transcript. The secret goes only into the local file,\n> entered through the user's editor.\n> - Print, echo, or repeat a secret you happen to see in the file.\n> - Suggest `export FALCON_CLIENT_SECRET=...` for interactive use — it leaks the\n> secret into shell history. (Environment variables are fine for CI, where the\n> runner injects them rather than a human typing them.)\n\nThis skill configures the Falcon API credentials that every fusion-skills script\nuses. Credentials are stored in a per-profile TOML file at\n`~/.cache/crowdstrike-falcon-fusion/credentials.toml` (multi-cloud capable), and\nthe secret is entered through the user's own editor — never through the chat.\n\nThe steps below use only file operations and a Python check, so they work\nidentically on macOS, Linux, and Windows.\n\n> **Running the scripts.** Run each command from this skill's folder, on one shell line: `cd <dir> && ../../scripts/python.sh ../../common/scripts/auth.py`. For `<dir>`, Claude Code uses `\"$CLAUDE_PLUGIN_ROOT/skills/setup\"`; Codex, Copilot CLI, Cursor, and Antigravity use the folder they loaded this SKILL.md from (e.g. `~/.agents/skills/setup`). The wrapper bootstraps its own Python venv.\n\n## Step 1 — Check for existing credentials\n\nRun the auth self-test. If it already succeeds, credentials are configured and you\nare done — report success and stop.\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n- **\"Authentication successful\"** for both clients → done.\n- **An error about missing credentials** → continue to Step 2.\n- **An authentication failure** (creds present but rejected) → the file exists but\n the values are wrong; go to Step 2 and have the user correct them.\n\n## Step 2 — Create the credentials file and have the user fill it in\n\nCreate `~/.cache/crowdstrike-falcon-fusion/credentials.toml` **only if it does not\nalready exist** (never overwrite existing profiles). Write this template with the\nWrite tool:\n\n```toml\n# CrowdStrike Falcon API credentials for fusion-skills.\n# Fill in client_id and client_secret below, then save this file.\n#\n# Create an API client in the Falcon console:\n# Support and resources -> API clients and keys -> Create API client\n# Required scopes:\n# Required scopes (names as shown in the console):\n# Workflow read/write - workflow authoring & deployment\n# NGSIEM Lookup Files read/write - lookup-file operations (lookup-files skill only)\n# Maintainers only (not needed for regular skill use):\n# NGSIEM read/write - CQL match() verification of a lookup\n# (verify_lookup.py / verify-workflows.sh --lookup-dir)\n\ndefault = \"us-2\"\n\n[us-2]\nclient_id = \"\"\nclient_secret = \"\"\nbase_url = \"https://api.us-2.crowdstrike.com\"\n\n# Add more clouds as needed (change `default` above to switch):\n# [us-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.crowdstrike.com\"\n#\n# [us-3]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.us-3.crowdstrike.com\"\n#\n# [eu-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.eu-1.crowdstrike.com\"\n#\n# [us-gov-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.laggar.gcw.crowdstrike.com\"\n```\n\nAfter creating the file, restrict its permissions (skip on Windows, where the user\nprofile directory is already access-controlled):\n\n```bash\nchmod 700 ~/.cache/crowdstrike-falcon-fusion\nchmod 600 ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n```\n\nThen tell the user, in your own words:\n\n> I created your credentials file at\n> `~/.cache/crowdstrike-falcon-fusion/credentials.toml`. Open it in your editor,\n> paste your **client ID** and **client secret** into the `us-2` section, set the\n> `base_url` for your cloud, and save. Then tell me to verify — don't paste the\n> secret here.\n\n**Offer to open the file for them.** Many terminals don't make the path clickable,\nso ask \"Want me to open it for you?\" and, if yes, run the opener for their OS:\n\n```bash\n# macOS\nopen ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Linux\nxdg-open ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Windows\nexplorer.exe %USERPROFILE%\\.cache\\crowdstrike-falcon-fusion\\credentials.toml\n```\n\nPick the command for the user's platform (check `uname` / the OS if unsure). This\njust opens the file in their default editor — the secret is still typed by them,\nnot through the chat. Do **not** ask them to paste the secret into the chat.\n\n## Step 3 — Verify connectivity\n\nOnce the user says they have saved the file, re-run the self-test:\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\nA successful run prints the resolved base URL, a masked client ID, and\n\"Authentication successful\" for both the Workflows and Next-Gen SIEM clients. If\nit fails, the client ID, secret, or base URL is wrong — ask the user to correct\nthe file and re-run.\n\n## Credential resolution order\n\n`auth.py` resolves credentials from the first source that supplies both an ID and\na secret:\n\n1. **Environment variables** — `FALCON_CLIENT_ID`, `FALCON_CLIENT_SECRET`, and the\n optional `FALCON_BASE_URL`. Intended for CI, where the runner injects them.\n2. **TOML profile file** — `~/.cache/crowdstrike-falcon-fusion/credentials.toml`,\n using the profile named by `FALCON_PROFILE` or the file's `default` key.\n\nThe setup flow above writes source 2, which works across every skill without\nexporting anything.\n\n## Multiple clouds (profiles)\n\nAdd more `[profile]` sections to the TOML file (for example `us-2` or `eu-1`) and\nchange the `default` key, or select one per run:\n\n```bash\nFALCON_PROFILE=eu-1 ../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n## Required API scopes\n\nThe API client needs the **Workflow** scope (read/write) for workflow authoring\nand deployment. For lookup-file operations (the `lookup-files` skill), also grant\nthe **NGSIEM Lookup Files** scope (read/write). Scope names appear exactly as shown\nwhen you create the API client in the console.\n\nMaintainers only: verifying a lookup resolves via CQL `match()` (`verify_lookup.py`\nor `verify-workflows.sh --lookup-dir`) additionally needs the **NGSIEM** scope\n(read/write) — starting a search is a query-job POST. Regular use of the skills\ndoes not require it.\n"
"---\nname: setup\ndescription: >\n Configure CrowdStrike Falcon API credentials for the fusion-skills plugin.\n TRIGGER when user asks to set up credentials, configure API access,\n or runs into authentication errors.\nversion: 1.3.0\nupdated: 2026-10-01\ntags: [fusion, setup, credentials, configuration]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n category: configuration\n---\n\n# Falcon Fusion Credential Setup\n\n> Your role here is **credential setup assistant**.\n>\n> You configure the Falcon API credentials every other skill depends on. These\n> credentials grant workflow and SIEM access to a live CID.\n>\n> **Required steps:**\n> 1. Check whether credentials already resolve (Step 1). If they do, you are done.\n> 2. If not, create the credentials file from the template (Step 2) and ask the\n> user to paste their ID and secret into it **using their own editor**.\n> 3. Verify connectivity (Step 3).\n>\n> **Don't:**\n> - Ask the user to type or paste their client secret **into the chat**. It would\n> land in the conversation transcript. The secret goes only into the local file,\n> entered through the user's editor.\n> - Print, echo, or repeat a secret you happen to see in the file.\n> - Suggest `export FALCON_CLIENT_SECRET=...` for interactive use — it leaks the\n> secret into shell history. (Environment variables are fine for CI, where the\n> runner injects them rather than a human typing them.)\n\nThis skill configures the Falcon API credentials that every fusion-skills script\nuses. Credentials are stored in a per-profile TOML file at\n`~/.cache/crowdstrike-falcon-fusion/credentials.toml` (multi-cloud capable), and\nthe secret is entered through the user's own editor — never through the chat.\n\nThe steps below use only file operations and a Python check, so they work\nidentically on macOS, Linux, and Windows.\n\n> **Running the scripts.** Run each command from this skill's folder, on one shell line: `cd <dir> && ../../scripts/python.sh ../../common/scripts/auth.py`. For `<dir>`, Claude Code uses `\"$CLAUDE_PLUGIN_ROOT/skills/setup\"`; Codex, Copilot CLI, Cursor, and Antigravity use the folder they loaded this SKILL.md from (e.g. `~/.agents/skills/setup`). The wrapper bootstraps its own Python venv.\n\n## Step 1 — Check for existing credentials\n\nRun the auth self-test. If it already succeeds, credentials are configured and you\nare done — report success and stop.\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n- **\"Authentication successful\"** for both clients → done.\n- **An error about missing credentials** → continue to Step 2.\n- **An authentication failure** (creds present but rejected) → the file exists but\n the values are wrong; go to Step 2 and have the user correct them.\n\n## Step 2 — Create the credentials file and have the user fill it in\n\nCreate `~/.cache/crowdstrike-falcon-fusion/credentials.toml` **only if it does not\nalready exist** (never overwrite existing profiles). Write this template with the\nWrite tool:\n\n```toml\n# CrowdStrike Falcon API credentials for fusion-skills.\n# Fill in client_id and client_secret below, then save this file.\n#\n# Create an API client in the Falcon console:\n# Support and resources -> API clients and keys -> Create API client\n# Required scopes:\n# Required scopes (names as shown in the console):\n# Workflow read/write - workflow authoring & deployment\n# NGSIEM Lookup Files read/write - lookup-file operations (lookup-files skill only)\n# Maintainers only (not needed for regular skill use):\n# NGSIEM read/write - CQL match() verification of a lookup\n# (verify_lookup.py / verify-workflows.sh --lookup-dir)\n\ndefault = \"us-2\"\n\n[us-2]\nclient_id = \"\"\nclient_secret = \"\"\nbase_url = \"https://api.us-2.crowdstrike.com\"\n\n# Add more clouds as needed (change `default` above to switch):\n# [us-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.crowdstrike.com\"\n#\n# [us-3]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.us-3.crowdstrike.com\"\n#\n# [eu-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.eu-1.crowdstrike.com\"\n#\n# [us-gov-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.laggar.gcw.crowdstrike.com\"\n```\n\nAfter creating the file, restrict its permissions (skip on Windows, where the user\nprofile directory is already access-controlled):\n\n```bash\nchmod 700 ~/.cache/crowdstrike-falcon-fusion\nchmod 600 ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n```\n\nThen tell the user, in your own words:\n\n> I created your credentials file at\n> `~/.cache/crowdstrike-falcon-fusion/credentials.toml`. Open it in your editor,\n> paste your **client ID** and **client secret** into the `us-2` section, set the\n> `base_url` for your cloud, and save. Then tell me to verify — don't paste the\n> secret here.\n\n**Offer to open the file for them.** Many terminals don't make the path clickable,\nso ask \"Want me to open it for you?\" and, if yes, run the opener for their OS:\n\n```bash\n# macOS\nopen ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Linux\nxdg-open ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Windows\nexplorer.exe %USERPROFILE%\\.cache\\crowdstrike-falcon-fusion\\credentials.toml\n```\n\nPick the command for the user's platform (check `uname` / the OS if unsure). This\njust opens the file in their default editor — the secret is still typed by them,\nnot through the chat. Do **not** ask them to paste the secret into the chat.\n\n## Step 3 — Verify connectivity\n\nOnce the user says they have saved the file, re-run the self-test:\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\nA successful run prints the resolved base URL, a masked client ID, and\n\"Authentication successful\" for both the Workflows and Next-Gen SIEM clients. If\nit fails, the client ID, secret, or base URL is wrong — ask the user to correct\nthe file and re-run.\n\n## Credential resolution order\n\n`auth.py` resolves credentials from the first source that supplies both an ID and\na secret:\n\n1. **Environment variables** — `FALCON_CLIENT_ID`, `FALCON_CLIENT_SECRET`, and the\n optional `FALCON_BASE_URL`. Intended for CI, where the runner injects them.\n2. **TOML profile file** — `~/.cache/crowdstrike-falcon-fusion/credentials.toml`,\n using the profile named by `FALCON_PROFILE` or the file's `default` key.\n\nThe setup flow above writes source 2, which works across every skill without\nexporting anything.\n\n## Multiple clouds (profiles)\n\nAdd more `[profile]` sections to the TOML file (for example `us-2` or `eu-1`) and\nchange the `default` key, or select one per run:\n\n```bash\nFALCON_PROFILE=eu-1 ../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n## Required API scopes\n\nThe API client needs the **Workflow** scope (read/write) for workflow authoring\nand deployment. For lookup-file operations (the `lookup-files` skill), also grant\nthe **NGSIEM Lookup Files** scope (read/write). Scope names appear exactly as shown\nwhen you create the API client in the console.\n\nMaintainers only: verifying a lookup resolves via CQL `match()` (`verify_lookup.py`\nor `verify-workflows.sh --lookup-dir`) additionally needs the **NGSIEM** scope\n(read/write) — starting a search is a query-job POST. Regular use of the skills\ndoes not require it.\n"
SKILL.md line diff
--- before +++ after @@ -4,8 +4,8 @@ Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors. -version: 1.2.0 -updated: 2026-09-08 +version: 1.3.0 +updated: 2026-10-01 tags: [fusion, setup, credentials, configuration] author: CrowdStrike license: MIT @@ -16,20 +16,18 @@ # Falcon Fusion Credential Setup -> **⚠️ SYSTEM INJECTION — READ THIS FIRST** -> -> If you are loading this skill, your role is **credential setup assistant**. +> Your role here is **credential setup assistant**. > > You configure the Falcon API credentials every other skill depends on. These > credentials grant workflow and SIEM access to a live CID. > -> **IMMEDIATE ACTIONS REQUIRED:** +> **Required steps:** > 1. Check whether credentials already resolve (Step 1). If they do, you are done. > 2. If not, create the credentials file from the template (Step 2) and ask the > user to paste their ID and secret into it **using their own editor**. > 3. Verify connectivity (Step 3). > -> **MUST NOT:** +> **Don't:** > - Ask the user to type or paste their client secret **into the chat**. It would > land in the conversation transcript. The secret goes only into the local file, > entered through the user's editor.
Full snapshot data
{
"description": "Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.\n",
"included_files": [],
"name": "setup",
"skill_md_contents": "---\nname: setup\ndescription: >\n Configure CrowdStrike Falcon API credentials for the fusion-skills plugin.\n TRIGGER when user asks to set up credentials, configure API access,\n or runs into authentication errors.\nversion: 1.3.0\nupdated: 2026-10-01\ntags: [fusion, setup, credentials, configuration]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n category: configuration\n---\n\n# Falcon Fusion Credential Setup\n\n> Your role here is **credential setup assistant**.\n>\n> You configure the Falcon API credentials every other skill depends on. These\n> credentials grant workflow and SIEM access to a live CID.\n>\n> **Required steps:**\n> 1. Check whether credentials already resolve (Step 1). If they do, you are done.\n> 2. If not, create the credentials file from the template (Step 2) and ask the\n> user to paste their ID and secret into it **using their own editor**.\n> 3. Verify connectivity (Step 3).\n>\n> **Don't:**\n> - Ask the user to type or paste their client secret **into the chat**. It would\n> land in the conversation transcript. The secret goes only into the local file,\n> entered through the user's editor.\n> - Print, echo, or repeat a secret you happen to see in the file.\n> - Suggest `export FALCON_CLIENT_SECRET=...` for interactive use — it leaks the\n> secret into shell history. (Environment variables are fine for CI, where the\n> runner injects them rather than a human typing them.)\n\nThis skill configures the Falcon API credentials that every fusion-skills script\nuses. Credentials are stored in a per-profile TOML file at\n`~/.cache/crowdstrike-falcon-fusion/credentials.toml` (multi-cloud capable), and\nthe secret is entered through the user's own editor — never through the chat.\n\nThe steps below use only file operations and a Python check, so they work\nidentically on macOS, Linux, and Windows.\n\n> **Running the scripts.** Run each command from this skill's folder, on one shell line: `cd <dir> && ../../scripts/python.sh ../../common/scripts/auth.py`. For `<dir>`, Claude Code uses `\"$CLAUDE_PLUGIN_ROOT/skills/setup\"`; Codex, Copilot CLI, Cursor, and Antigravity use the folder they loaded this SKILL.md from (e.g. `~/.agents/skills/setup`). The wrapper bootstraps its own Python venv.\n\n## Step 1 — Check for existing credentials\n\nRun the auth self-test. If it already succeeds, credentials are configured and you\nare done — report success and stop.\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n- **\"Authentication successful\"** for both clients → done.\n- **An error about missing credentials** → continue to Step 2.\n- **An authentication failure** (creds present but rejected) → the file exists but\n the values are wrong; go to Step 2 and have the user correct them.\n\n## Step 2 — Create the credentials file and have the user fill it in\n\nCreate `~/.cache/crowdstrike-falcon-fusion/credentials.toml` **only if it does not\nalready exist** (never overwrite existing profiles). Write this template with the\nWrite tool:\n\n```toml\n# CrowdStrike Falcon API credentials for fusion-skills.\n# Fill in client_id and client_secret below, then save this file.\n#\n# Create an API client in the Falcon console:\n# Support and resources -> API clients and keys -> Create API client\n# Required scopes:\n# Required scopes (names as shown in the console):\n# Workflow read/write - workflow authoring & deployment\n# NGSIEM Lookup Files read/write - lookup-file operations (lookup-files skill only)\n# Maintainers only (not needed for regular skill use):\n# NGSIEM read/write - CQL match() verification of a lookup\n# (verify_lookup.py / verify-workflows.sh --lookup-dir)\n\ndefault = \"us-2\"\n\n[us-2]\nclient_id = \"\"\nclient_secret = \"\"\nbase_url = \"https://api.us-2.crowdstrike.com\"\n\n# Add more clouds as needed (change `default` above to switch):\n# [us-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.crowdstrike.com\"\n#\n# [us-3]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.us-3.crowdstrike.com\"\n#\n# [eu-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.eu-1.crowdstrike.com\"\n#\n# [us-gov-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.laggar.gcw.crowdstrike.com\"\n```\n\nAfter creating the file, restrict its permissions (skip on Windows, where the user\nprofile directory is already access-controlled):\n\n```bash\nchmod 700 ~/.cache/crowdstrike-falcon-fusion\nchmod 600 ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n```\n\nThen tell the user, in your own words:\n\n> I created your credentials file at\n> `~/.cache/crowdstrike-falcon-fusion/credentials.toml`. Open it in your editor,\n> paste your **client ID** and **client secret** into the `us-2` section, set the\n> `base_url` for your cloud, and save. Then tell me to verify — don't paste the\n> secret here.\n\n**Offer to open the file for them.** Many terminals don't make the path clickable,\nso ask \"Want me to open it for you?\" and, if yes, run the opener for their OS:\n\n```bash\n# macOS\nopen ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Linux\nxdg-open ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Windows\nexplorer.exe %USERPROFILE%\\.cache\\crowdstrike-falcon-fusion\\credentials.toml\n```\n\nPick the command for the user's platform (check `uname` / the OS if unsure). This\njust opens the file in their default editor — the secret is still typed by them,\nnot through the chat. Do **not** ask them to paste the secret into the chat.\n\n## Step 3 — Verify connectivity\n\nOnce the user says they have saved the file, re-run the self-test:\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\nA successful run prints the resolved base URL, a masked client ID, and\n\"Authentication successful\" for both the Workflows and Next-Gen SIEM clients. If\nit fails, the client ID, secret, or base URL is wrong — ask the user to correct\nthe file and re-run.\n\n## Credential resolution order\n\n`auth.py` resolves credentials from the first source that supplies both an ID and\na secret:\n\n1. **Environment variables** — `FALCON_CLIENT_ID`, `FALCON_CLIENT_SECRET`, and the\n optional `FALCON_BASE_URL`. Intended for CI, where the runner injects them.\n2. **TOML profile file** — `~/.cache/crowdstrike-falcon-fusion/credentials.toml`,\n using the profile named by `FALCON_PROFILE` or the file's `default` key.\n\nThe setup flow above writes source 2, which works across every skill without\nexporting anything.\n\n## Multiple clouds (profiles)\n\nAdd more `[profile]` sections to the TOML file (for example `us-2` or `eu-1`) and\nchange the `default` key, or select one per run:\n\n```bash\nFALCON_PROFILE=eu-1 ../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n## Required API scopes\n\nThe API client needs the **Workflow** scope (read/write) for workflow authoring\nand deployment. For lookup-file operations (the `lookup-files` skill), also grant\nthe **NGSIEM Lookup Files** scope (read/write). Scope names appear exactly as shown\nwhen you create the API client in the console.\n\nMaintainers only: verifying a lookup resolves via CQL `match()` (`verify_lookup.py`\nor `verify-workflows.sh --lookup-dir`) additionally needs the **NGSIEM** scope\n(read/write) — starting a search is a query-job POST. Regular use of the skills\ndoes not require it.\n"
}SHA-256 of public snapshot: 6105fdf45970970f782d1752bf6d8f958377316297b7a72217e6315dfd52ece4