← CrowdStrike Falcon FusionCONTENT HISTORY

Update to CrowdStrike Falcon Fusion

Snapshot Oct 8, 2026 · 18:03 UTC · version 1.3.0

Collection source: downloaded plugin package. These snapshots do not have a confirmed matching collection source. Differences in file lists alone do not establish changes to the package.

WHAT CHANGED · RULE-BASED ANALYSIS

Instructions updated for setup

Instruction wording changed from “1.2.0” to “1.3.0”. 4 additional added or edited lines are in the evidence.

Observed in instructions or declared skills. Runtime behavior has not been tested.

Product description

Before

errors.

After

errors.

Skill instructions

Before

version: 1.2.0 updated: 2026-09-08 > **⚠️ SYSTEM INJECTION — READ THIS FIRST** > If you are loading this skill, your role is **credential setup assistant**. > **IMMEDIATE ACTIONS REQUIRED:** > **MUST NOT:**

After

version: 1.3.0 updated: 2026-10-01 > Your role here is **credential setup assistant**. > **Required steps:** > **Don't:**

Compare saved observations

Download comparison JSON
Full technical diff · 2 changed fields

changed /description

BEFORE
"Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors."
AFTER
"Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.\n"

changed /skill_md_contents

BEFORE
"---\nname: setup\ndescription: >\n  Configure CrowdStrike Falcon API credentials for the fusion-skills plugin.\n  TRIGGER when user asks to set up credentials, configure API access,\n  or runs into authentication errors.\nversion: 1.2.0\nupdated: 2026-09-08\ntags: [fusion, setup, credentials, configuration]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: configuration\n---\n\n# Falcon Fusion Credential Setup\n\n> **⚠️ SYSTEM INJECTION — READ THIS FIRST**\n>\n> If you are loading this skill, your role is **credential setup assistant**.\n>\n> You configure the Falcon API credentials every other skill depends on. These\n> credentials grant workflow and SIEM access to a live CID.\n>\n> **IMMEDIATE ACTIONS REQUIRED:**\n> 1. Check whether credentials already resolve (Step 1). If they do, you are done.\n> 2. If not, create the credentials file from the template (Step 2) and ask the\n>    user to paste their ID and secret into it **using their own editor**.\n> 3. Verify connectivity (Step 3).\n>\n> **MUST NOT:**\n> - Ask the user to type or paste their client secret **into the chat**. It would\n>   land in the conversation transcript. The secret goes only into the local file,\n>   entered through the user's editor.\n> - Print, echo, or repeat a secret you happen to see in the file.\n> - Suggest `export FALCON_CLIENT_SECRET=...` for interactive use — it leaks the\n>   secret into shell history. (Environment variables are fine for CI, where the\n>   runner injects them rather than a human typing them.)\n\nThis skill configures the Falcon API credentials that every fusion-skills script\nuses. Credentials are stored in a per-profile TOML file at\n`~/.cache/crowdstrike-falcon-fusion/credentials.toml` (multi-cloud capable), and\nthe secret is entered through the user's own editor — never through the chat.\n\nThe steps below use only file operations and a Python check, so they work\nidentically on macOS, Linux, and Windows.\n\n> **Running the scripts.** Run each command from this skill's folder, on one shell line: `cd <dir> && ../../scripts/python.sh ../../common/scripts/auth.py`. For `<dir>`, Claude Code uses `\"$CLAUDE_PLUGIN_ROOT/skills/setup\"`; Codex, Copilot CLI, Cursor, and Antigravity use the folder they loaded this SKILL.md from (e.g. `~/.agents/skills/setup`). The wrapper bootstraps its own Python venv.\n\n## Step 1 — Check for existing credentials\n\nRun the auth self-test. If it already succeeds, credentials are configured and you\nare done — report success and stop.\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n- **\"Authentication successful\"** for both clients → done.\n- **An error about missing credentials** → continue to Step 2.\n- **An authentication failure** (creds present but rejected) → the file exists but\n  the values are wrong; go to Step 2 and have the user correct them.\n\n## Step 2 — Create the credentials file and have the user fill it in\n\nCreate `~/.cache/crowdstrike-falcon-fusion/credentials.toml` **only if it does not\nalready exist** (never overwrite existing profiles). Write this template with the\nWrite tool:\n\n```toml\n# CrowdStrike Falcon API credentials for fusion-skills.\n# Fill in client_id and client_secret below, then save this file.\n#\n# Create an API client in the Falcon console:\n#   Support and resources -> API clients and keys -> Create API client\n# Required scopes:\n# Required scopes (names as shown in the console):\n#   Workflow             read/write   - workflow authoring & deployment\n#   NGSIEM Lookup Files   read/write   - lookup-file operations (lookup-files skill only)\n# Maintainers only (not needed for regular skill use):\n#   NGSIEM                read/write   - CQL match() verification of a lookup\n#                                        (verify_lookup.py / verify-workflows.sh --lookup-dir)\n\ndefault = \"us-2\"\n\n[us-2]\nclient_id = \"\"\nclient_secret = \"\"\nbase_url = \"https://api.us-2.crowdstrike.com\"\n\n# Add more clouds as needed (change `default` above to switch):\n# [us-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.crowdstrike.com\"\n#\n# [us-3]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.us-3.crowdstrike.com\"\n#\n# [eu-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.eu-1.crowdstrike.com\"\n#\n# [us-gov-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.laggar.gcw.crowdstrike.com\"\n```\n\nAfter creating the file, restrict its permissions (skip on Windows, where the user\nprofile directory is already access-controlled):\n\n```bash\nchmod 700 ~/.cache/crowdstrike-falcon-fusion\nchmod 600 ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n```\n\nThen tell the user, in your own words:\n\n> I created your credentials file at\n> `~/.cache/crowdstrike-falcon-fusion/credentials.toml`. Open it in your editor,\n> paste your **client ID** and **client secret** into the `us-2` section, set the\n> `base_url` for your cloud, and save. Then tell me to verify — don't paste the\n> secret here.\n\n**Offer to open the file for them.** Many terminals don't make the path clickable,\nso ask \"Want me to open it for you?\" and, if yes, run the opener for their OS:\n\n```bash\n# macOS\nopen ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Linux\nxdg-open ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Windows\nexplorer.exe %USERPROFILE%\\.cache\\crowdstrike-falcon-fusion\\credentials.toml\n```\n\nPick the command for the user's platform (check `uname` / the OS if unsure). This\njust opens the file in their default editor — the secret is still typed by them,\nnot through the chat. Do **not** ask them to paste the secret into the chat.\n\n## Step 3 — Verify connectivity\n\nOnce the user says they have saved the file, re-run the self-test:\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\nA successful run prints the resolved base URL, a masked client ID, and\n\"Authentication successful\" for both the Workflows and Next-Gen SIEM clients. If\nit fails, the client ID, secret, or base URL is wrong — ask the user to correct\nthe file and re-run.\n\n## Credential resolution order\n\n`auth.py` resolves credentials from the first source that supplies both an ID and\na secret:\n\n1. **Environment variables** — `FALCON_CLIENT_ID`, `FALCON_CLIENT_SECRET`, and the\n   optional `FALCON_BASE_URL`. Intended for CI, where the runner injects them.\n2. **TOML profile file** — `~/.cache/crowdstrike-falcon-fusion/credentials.toml`,\n   using the profile named by `FALCON_PROFILE` or the file's `default` key.\n\nThe setup flow above writes source 2, which works across every skill without\nexporting anything.\n\n## Multiple clouds (profiles)\n\nAdd more `[profile]` sections to the TOML file (for example `us-2` or `eu-1`) and\nchange the `default` key, or select one per run:\n\n```bash\nFALCON_PROFILE=eu-1 ../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n## Required API scopes\n\nThe API client needs the **Workflow** scope (read/write) for workflow authoring\nand deployment. For lookup-file operations (the `lookup-files` skill), also grant\nthe **NGSIEM Lookup Files** scope (read/write). Scope names appear exactly as shown\nwhen you create the API client in the console.\n\nMaintainers only: verifying a lookup resolves via CQL `match()` (`verify_lookup.py`\nor `verify-workflows.sh --lookup-dir`) additionally needs the **NGSIEM** scope\n(read/write) — starting a search is a query-job POST. Regular use of the skills\ndoes not require it.\n"
AFTER
"---\nname: setup\ndescription: >\n  Configure CrowdStrike Falcon API credentials for the fusion-skills plugin.\n  TRIGGER when user asks to set up credentials, configure API access,\n  or runs into authentication errors.\nversion: 1.3.0\nupdated: 2026-10-01\ntags: [fusion, setup, credentials, configuration]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: configuration\n---\n\n# Falcon Fusion Credential Setup\n\n> Your role here is **credential setup assistant**.\n>\n> You configure the Falcon API credentials every other skill depends on. These\n> credentials grant workflow and SIEM access to a live CID.\n>\n> **Required steps:**\n> 1. Check whether credentials already resolve (Step 1). If they do, you are done.\n> 2. If not, create the credentials file from the template (Step 2) and ask the\n>    user to paste their ID and secret into it **using their own editor**.\n> 3. Verify connectivity (Step 3).\n>\n> **Don't:**\n> - Ask the user to type or paste their client secret **into the chat**. It would\n>   land in the conversation transcript. The secret goes only into the local file,\n>   entered through the user's editor.\n> - Print, echo, or repeat a secret you happen to see in the file.\n> - Suggest `export FALCON_CLIENT_SECRET=...` for interactive use — it leaks the\n>   secret into shell history. (Environment variables are fine for CI, where the\n>   runner injects them rather than a human typing them.)\n\nThis skill configures the Falcon API credentials that every fusion-skills script\nuses. Credentials are stored in a per-profile TOML file at\n`~/.cache/crowdstrike-falcon-fusion/credentials.toml` (multi-cloud capable), and\nthe secret is entered through the user's own editor — never through the chat.\n\nThe steps below use only file operations and a Python check, so they work\nidentically on macOS, Linux, and Windows.\n\n> **Running the scripts.** Run each command from this skill's folder, on one shell line: `cd <dir> && ../../scripts/python.sh ../../common/scripts/auth.py`. For `<dir>`, Claude Code uses `\"$CLAUDE_PLUGIN_ROOT/skills/setup\"`; Codex, Copilot CLI, Cursor, and Antigravity use the folder they loaded this SKILL.md from (e.g. `~/.agents/skills/setup`). The wrapper bootstraps its own Python venv.\n\n## Step 1 — Check for existing credentials\n\nRun the auth self-test. If it already succeeds, credentials are configured and you\nare done — report success and stop.\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n- **\"Authentication successful\"** for both clients → done.\n- **An error about missing credentials** → continue to Step 2.\n- **An authentication failure** (creds present but rejected) → the file exists but\n  the values are wrong; go to Step 2 and have the user correct them.\n\n## Step 2 — Create the credentials file and have the user fill it in\n\nCreate `~/.cache/crowdstrike-falcon-fusion/credentials.toml` **only if it does not\nalready exist** (never overwrite existing profiles). Write this template with the\nWrite tool:\n\n```toml\n# CrowdStrike Falcon API credentials for fusion-skills.\n# Fill in client_id and client_secret below, then save this file.\n#\n# Create an API client in the Falcon console:\n#   Support and resources -> API clients and keys -> Create API client\n# Required scopes:\n# Required scopes (names as shown in the console):\n#   Workflow             read/write   - workflow authoring & deployment\n#   NGSIEM Lookup Files   read/write   - lookup-file operations (lookup-files skill only)\n# Maintainers only (not needed for regular skill use):\n#   NGSIEM                read/write   - CQL match() verification of a lookup\n#                                        (verify_lookup.py / verify-workflows.sh --lookup-dir)\n\ndefault = \"us-2\"\n\n[us-2]\nclient_id = \"\"\nclient_secret = \"\"\nbase_url = \"https://api.us-2.crowdstrike.com\"\n\n# Add more clouds as needed (change `default` above to switch):\n# [us-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.crowdstrike.com\"\n#\n# [us-3]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.us-3.crowdstrike.com\"\n#\n# [eu-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.eu-1.crowdstrike.com\"\n#\n# [us-gov-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.laggar.gcw.crowdstrike.com\"\n```\n\nAfter creating the file, restrict its permissions (skip on Windows, where the user\nprofile directory is already access-controlled):\n\n```bash\nchmod 700 ~/.cache/crowdstrike-falcon-fusion\nchmod 600 ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n```\n\nThen tell the user, in your own words:\n\n> I created your credentials file at\n> `~/.cache/crowdstrike-falcon-fusion/credentials.toml`. Open it in your editor,\n> paste your **client ID** and **client secret** into the `us-2` section, set the\n> `base_url` for your cloud, and save. Then tell me to verify — don't paste the\n> secret here.\n\n**Offer to open the file for them.** Many terminals don't make the path clickable,\nso ask \"Want me to open it for you?\" and, if yes, run the opener for their OS:\n\n```bash\n# macOS\nopen ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Linux\nxdg-open ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Windows\nexplorer.exe %USERPROFILE%\\.cache\\crowdstrike-falcon-fusion\\credentials.toml\n```\n\nPick the command for the user's platform (check `uname` / the OS if unsure). This\njust opens the file in their default editor — the secret is still typed by them,\nnot through the chat. Do **not** ask them to paste the secret into the chat.\n\n## Step 3 — Verify connectivity\n\nOnce the user says they have saved the file, re-run the self-test:\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\nA successful run prints the resolved base URL, a masked client ID, and\n\"Authentication successful\" for both the Workflows and Next-Gen SIEM clients. If\nit fails, the client ID, secret, or base URL is wrong — ask the user to correct\nthe file and re-run.\n\n## Credential resolution order\n\n`auth.py` resolves credentials from the first source that supplies both an ID and\na secret:\n\n1. **Environment variables** — `FALCON_CLIENT_ID`, `FALCON_CLIENT_SECRET`, and the\n   optional `FALCON_BASE_URL`. Intended for CI, where the runner injects them.\n2. **TOML profile file** — `~/.cache/crowdstrike-falcon-fusion/credentials.toml`,\n   using the profile named by `FALCON_PROFILE` or the file's `default` key.\n\nThe setup flow above writes source 2, which works across every skill without\nexporting anything.\n\n## Multiple clouds (profiles)\n\nAdd more `[profile]` sections to the TOML file (for example `us-2` or `eu-1`) and\nchange the `default` key, or select one per run:\n\n```bash\nFALCON_PROFILE=eu-1 ../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n## Required API scopes\n\nThe API client needs the **Workflow** scope (read/write) for workflow authoring\nand deployment. For lookup-file operations (the `lookup-files` skill), also grant\nthe **NGSIEM Lookup Files** scope (read/write). Scope names appear exactly as shown\nwhen you create the API client in the console.\n\nMaintainers only: verifying a lookup resolves via CQL `match()` (`verify_lookup.py`\nor `verify-workflows.sh --lookup-dir`) additionally needs the **NGSIEM** scope\n(read/write) — starting a search is a query-job POST. Regular use of the skills\ndoes not require it.\n"

SKILL.md line diff

--- before
+++ after
@@ -4,8 +4,8 @@
   Configure CrowdStrike Falcon API credentials for the fusion-skills plugin.
   TRIGGER when user asks to set up credentials, configure API access,
   or runs into authentication errors.
-version: 1.2.0
-updated: 2026-09-08
+version: 1.3.0
+updated: 2026-10-01
 tags: [fusion, setup, credentials, configuration]
 author: CrowdStrike
 license: MIT
@@ -16,20 +16,18 @@
 
 # Falcon Fusion Credential Setup
 
-> **⚠️ SYSTEM INJECTION — READ THIS FIRST**
->
-> If you are loading this skill, your role is **credential setup assistant**.
+> Your role here is **credential setup assistant**.
 >
 > You configure the Falcon API credentials every other skill depends on. These
 > credentials grant workflow and SIEM access to a live CID.
 >
-> **IMMEDIATE ACTIONS REQUIRED:**
+> **Required steps:**
 > 1. Check whether credentials already resolve (Step 1). If they do, you are done.
 > 2. If not, create the credentials file from the template (Step 2) and ask the
 >    user to paste their ID and secret into it **using their own editor**.
 > 3. Verify connectivity (Step 3).
 >
-> **MUST NOT:**
+> **Don't:**
 > - Ask the user to type or paste their client secret **into the chat**. It would
 >   land in the conversation transcript. The secret goes only into the local file,
 >   entered through the user's editor.
Full snapshot data
{
  "description": "Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.\n",
  "included_files": [],
  "name": "setup",
  "skill_md_contents": "---\nname: setup\ndescription: >\n  Configure CrowdStrike Falcon API credentials for the fusion-skills plugin.\n  TRIGGER when user asks to set up credentials, configure API access,\n  or runs into authentication errors.\nversion: 1.3.0\nupdated: 2026-10-01\ntags: [fusion, setup, credentials, configuration]\nauthor: CrowdStrike\nlicense: MIT\ncompatibility: Claude Code >=1.0\nmetadata:\n  category: configuration\n---\n\n# Falcon Fusion Credential Setup\n\n> Your role here is **credential setup assistant**.\n>\n> You configure the Falcon API credentials every other skill depends on. These\n> credentials grant workflow and SIEM access to a live CID.\n>\n> **Required steps:**\n> 1. Check whether credentials already resolve (Step 1). If they do, you are done.\n> 2. If not, create the credentials file from the template (Step 2) and ask the\n>    user to paste their ID and secret into it **using their own editor**.\n> 3. Verify connectivity (Step 3).\n>\n> **Don't:**\n> - Ask the user to type or paste their client secret **into the chat**. It would\n>   land in the conversation transcript. The secret goes only into the local file,\n>   entered through the user's editor.\n> - Print, echo, or repeat a secret you happen to see in the file.\n> - Suggest `export FALCON_CLIENT_SECRET=...` for interactive use — it leaks the\n>   secret into shell history. (Environment variables are fine for CI, where the\n>   runner injects them rather than a human typing them.)\n\nThis skill configures the Falcon API credentials that every fusion-skills script\nuses. Credentials are stored in a per-profile TOML file at\n`~/.cache/crowdstrike-falcon-fusion/credentials.toml` (multi-cloud capable), and\nthe secret is entered through the user's own editor — never through the chat.\n\nThe steps below use only file operations and a Python check, so they work\nidentically on macOS, Linux, and Windows.\n\n> **Running the scripts.** Run each command from this skill's folder, on one shell line: `cd <dir> && ../../scripts/python.sh ../../common/scripts/auth.py`. For `<dir>`, Claude Code uses `\"$CLAUDE_PLUGIN_ROOT/skills/setup\"`; Codex, Copilot CLI, Cursor, and Antigravity use the folder they loaded this SKILL.md from (e.g. `~/.agents/skills/setup`). The wrapper bootstraps its own Python venv.\n\n## Step 1 — Check for existing credentials\n\nRun the auth self-test. If it already succeeds, credentials are configured and you\nare done — report success and stop.\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n- **\"Authentication successful\"** for both clients → done.\n- **An error about missing credentials** → continue to Step 2.\n- **An authentication failure** (creds present but rejected) → the file exists but\n  the values are wrong; go to Step 2 and have the user correct them.\n\n## Step 2 — Create the credentials file and have the user fill it in\n\nCreate `~/.cache/crowdstrike-falcon-fusion/credentials.toml` **only if it does not\nalready exist** (never overwrite existing profiles). Write this template with the\nWrite tool:\n\n```toml\n# CrowdStrike Falcon API credentials for fusion-skills.\n# Fill in client_id and client_secret below, then save this file.\n#\n# Create an API client in the Falcon console:\n#   Support and resources -> API clients and keys -> Create API client\n# Required scopes:\n# Required scopes (names as shown in the console):\n#   Workflow             read/write   - workflow authoring & deployment\n#   NGSIEM Lookup Files   read/write   - lookup-file operations (lookup-files skill only)\n# Maintainers only (not needed for regular skill use):\n#   NGSIEM                read/write   - CQL match() verification of a lookup\n#                                        (verify_lookup.py / verify-workflows.sh --lookup-dir)\n\ndefault = \"us-2\"\n\n[us-2]\nclient_id = \"\"\nclient_secret = \"\"\nbase_url = \"https://api.us-2.crowdstrike.com\"\n\n# Add more clouds as needed (change `default` above to switch):\n# [us-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.crowdstrike.com\"\n#\n# [us-3]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.us-3.crowdstrike.com\"\n#\n# [eu-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.eu-1.crowdstrike.com\"\n#\n# [us-gov-1]\n# client_id = \"\"\n# client_secret = \"\"\n# base_url = \"https://api.laggar.gcw.crowdstrike.com\"\n```\n\nAfter creating the file, restrict its permissions (skip on Windows, where the user\nprofile directory is already access-controlled):\n\n```bash\nchmod 700 ~/.cache/crowdstrike-falcon-fusion\nchmod 600 ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n```\n\nThen tell the user, in your own words:\n\n> I created your credentials file at\n> `~/.cache/crowdstrike-falcon-fusion/credentials.toml`. Open it in your editor,\n> paste your **client ID** and **client secret** into the `us-2` section, set the\n> `base_url` for your cloud, and save. Then tell me to verify — don't paste the\n> secret here.\n\n**Offer to open the file for them.** Many terminals don't make the path clickable,\nso ask \"Want me to open it for you?\" and, if yes, run the opener for their OS:\n\n```bash\n# macOS\nopen ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Linux\nxdg-open ~/.cache/crowdstrike-falcon-fusion/credentials.toml\n# Windows\nexplorer.exe %USERPROFILE%\\.cache\\crowdstrike-falcon-fusion\\credentials.toml\n```\n\nPick the command for the user's platform (check `uname` / the OS if unsure). This\njust opens the file in their default editor — the secret is still typed by them,\nnot through the chat. Do **not** ask them to paste the secret into the chat.\n\n## Step 3 — Verify connectivity\n\nOnce the user says they have saved the file, re-run the self-test:\n\n```bash\n../../scripts/python.sh ../../common/scripts/auth.py\n```\n\nA successful run prints the resolved base URL, a masked client ID, and\n\"Authentication successful\" for both the Workflows and Next-Gen SIEM clients. If\nit fails, the client ID, secret, or base URL is wrong — ask the user to correct\nthe file and re-run.\n\n## Credential resolution order\n\n`auth.py` resolves credentials from the first source that supplies both an ID and\na secret:\n\n1. **Environment variables** — `FALCON_CLIENT_ID`, `FALCON_CLIENT_SECRET`, and the\n   optional `FALCON_BASE_URL`. Intended for CI, where the runner injects them.\n2. **TOML profile file** — `~/.cache/crowdstrike-falcon-fusion/credentials.toml`,\n   using the profile named by `FALCON_PROFILE` or the file's `default` key.\n\nThe setup flow above writes source 2, which works across every skill without\nexporting anything.\n\n## Multiple clouds (profiles)\n\nAdd more `[profile]` sections to the TOML file (for example `us-2` or `eu-1`) and\nchange the `default` key, or select one per run:\n\n```bash\nFALCON_PROFILE=eu-1 ../../scripts/python.sh ../../common/scripts/auth.py\n```\n\n## Required API scopes\n\nThe API client needs the **Workflow** scope (read/write) for workflow authoring\nand deployment. For lookup-file operations (the `lookup-files` skill), also grant\nthe **NGSIEM Lookup Files** scope (read/write). Scope names appear exactly as shown\nwhen you create the API client in the console.\n\nMaintainers only: verifying a lookup resolves via CQL `match()` (`verify_lookup.py`\nor `verify-workflows.sh --lookup-dir`) additionally needs the **NGSIEM** scope\n(read/write) — starting a search is a query-job POST. Regular use of the skills\ndoes not require it.\n"
}

SHA-256 of public snapshot: 6105fdf45970970f782d1752bf6d8f958377316297b7a72217e6315dfd52ece4