← CrowdStrike Falcon FusionCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
changed
changed
Update to CrowdStrike Falcon Fusion
Snapshot Oct 9, 2026 · 00:07 UTC · version 1.3.0
Package or technical metadata updated
Discoverability changed from “UNLISTED” to “LISTED”.
Observed in package metadata. These changes alone do not establish a new customer-facing feature.
Discoverability
Before
UNLISTED
After
LISTED
Share url
Before
Not present
After
https://chatgpt.com/plugins/plugins_6a8f7048ed7881918bf5b79011fe2b5e?open_in_app
Compare saved observations
Download comparison JSONFull technical diff · 2 changed fields
changed /discoverability
BEFORE
"UNLISTED"
AFTER
"LISTED"
changed /share_url
BEFORE
null
AFTER
"https://chatgpt.com/plugins/plugins_6a8f7048ed7881918bf5b79011fe2b5e?open_in_app"
Full snapshot data
{
"canonical_app_id": null,
"connector_id": null,
"created_at": "2026-08-26T23:15:34.926040Z",
"discoverability": "LISTED",
"id": "plugins_6a8f7048ed7881918bf5b79011fe2b5e",
"is_template": false,
"name": "crowdstrike-falcon-fusion",
"release": {
"app_ids": [],
"app_manifest": null,
"app_templates": [],
"description": "CrowdStrike Falcon Fusion skills for authoring, deploying, and executing Fusion workflows. Includes live action discovery, YAML authoring with schema validation, workflow import and release, execution monitoring, and Falcon Next-Gen SIEM lookup files.",
"display_name": "CrowdStrike Falcon Fusion",
"id": "pluginrel_57619d69555c8191a9e539f6151a75f7",
"interface": {
"brand_color": "#E01F3D",
"capabilities": [
"Interactive",
"Write"
],
"category": "Developer Tools",
"composer_icon_dark_url": null,
"composer_icon_url": "https://files.openai.com/content?id=file_0000000030c882109d902ec296ec6892",
"default_prompt": "Create a Falcon Fusion workflow",
"default_prompts": [
"Create a Falcon Fusion workflow",
"Automate a CrowdStrike response",
"Troubleshoot a Fusion workflow"
],
"developer_name": "CrowdStrike",
"logo_url": "https://files.openai.com/content?id=file_0000000085548210b5020baf0b7205d6",
"logo_url_dark": null,
"long_description": "Discover live Falcon Fusion actions, author workflow YAML with schema validation, import and release workflow definitions to a CID, trigger and monitor executions, and manage Falcon Next-Gen SIEM lookup files.",
"plugin_category_id": "developer tools",
"privacy_policy_url": null,
"screenshot_urls": [],
"short_description": "Build Falcon Fusion workflows",
"terms_of_service_url": null,
"website_url": "https://github.com/CrowdStrike/fusion-skills"
},
"keywords": [
"crowdstrike",
"falcon",
"fusion",
"soar",
"workflow",
"automation",
"security"
],
"mcp_servers": [],
"onboarding_skill_name": null,
"requires_local_executor": false,
"skills": [
{
"description": "Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, validate a workflow, use CEL expressions, or needs action discovery. DO NOT TRIGGER for deploying, importing, executing, or monitoring workflows — use deployment or execution skills. DO NOT TRIGGER when the request is for a Falcon Foundry app, a UI extension/page, an API integration, custom actions from a third-party API, or a manifest.yml — those are foundry-skills territory; advise foundry-skills instead of authoring a workflow.\n",
"interface": {
"brand_color": null,
"default_prompt": null,
"display_name": "authoring",
"icon_large_url": null,
"icon_small_url": null,
"iconography": "hierarchy",
"short_description": "Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, validate a workflow, use CEL expressions, or needs action discovery. DO NOT TRIGGER for deploying, importing, executing, or monitoring workflows — use deployment or execution skills. DO NOT TRIGGER when the request is for a Falcon Foundry app, a UI extension/page, an API integration, custom actions from a third-party API, or a manifest.yml — those are foundry-skills territory; advise foundry-skills instead of authoring a workflow.\n"
},
"name": "authoring",
"plugin_release_skill_id": "pluginrsk_6abfb6043420819184444eb18d030d12"
},
{
"description": "Import, release, and manage Falcon Fusion workflow definitions in a CID. TRIGGER when user asks to import a workflow, release a workflow version, list existing workflows, check for duplicates, or manage workflow definitions. DO NOT TRIGGER for writing YAML (use authoring), executing workflows, or monitoring (use execution).\n",
"interface": {
"brand_color": null,
"default_prompt": null,
"display_name": "deployment",
"icon_large_url": null,
"icon_small_url": null,
"iconography": "bolt",
"short_description": "Import, release, and manage Falcon Fusion workflow definitions in a CID. TRIGGER when user asks to import a workflow, release a workflow version, list existing workflows, check for duplicates, or manage workflow definitions. DO NOT TRIGGER for writing YAML (use authoring), executing workflows, or monitoring (use execution).\n"
},
"name": "deployment",
"plugin_release_skill_id": "pluginrsk_6abfb6024dc88191bd8c7de58985a597"
},
{
"description": "Trigger Falcon Fusion workflows, monitor execution status, and debug failures. TRIGGER when user asks to run a workflow, check execution status, tail logs, get execution results, or debug a workflow failure. DO NOT TRIGGER for writing YAML (use authoring) or importing/releasing workflows (use deployment).\n",
"interface": {
"brand_color": null,
"default_prompt": null,
"display_name": "execution",
"icon_large_url": null,
"icon_small_url": null,
"iconography": "bolt",
"short_description": "Trigger Falcon Fusion workflows, monitor execution status, and debug failures. TRIGGER when user asks to run a workflow, check execution status, tail logs, get execution results, or debug a workflow failure. DO NOT TRIGGER for writing YAML (use authoring) or importing/releasing workflows (use deployment).\n"
},
"name": "execution",
"plugin_release_skill_id": "pluginrsk_6abfb60355508191b220675fbd7310f7"
},
{
"description": "TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n",
"interface": {
"brand_color": null,
"default_prompt": null,
"display_name": "foundry-redirect",
"icon_large_url": null,
"icon_small_url": null,
"iconography": "code",
"short_description": "TRIGGER when the user asks to \"build a Foundry app\", \"create a Foundry app\", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without plugin hooks; it yields to the real Foundry plugin when that plugin is also installed.\n"
},
"name": "foundry-redirect",
"plugin_release_skill_id": "pluginrsk_6abfb602294481919af9990a29f3a9ca"
},
{
"description": "Manage Falcon Next-Gen SIEM lookup files (CSV/JSON/TXT) for CQL match() queries. TRIGGER when user asks to create, list, update, or delete lookup files, or needs help with CQL match() function. DO NOT TRIGGER for Fusion workflows, action discovery, or workflow deployment — use the workflows/authoring/deployment skills.\n",
"interface": {
"brand_color": null,
"default_prompt": null,
"display_name": "lookup-files",
"icon_large_url": null,
"icon_small_url": null,
"iconography": "search",
"short_description": "Manage Falcon Next-Gen SIEM lookup files (CSV/JSON/TXT) for CQL match() queries. TRIGGER when user asks to create, list, update, or delete lookup files, or needs help with CQL match() function. DO NOT TRIGGER for Fusion workflows, action discovery, or workflow deployment — use the workflows/authoring/deployment skills.\n"
},
"name": "lookup-files",
"plugin_release_skill_id": "pluginrsk_6abfb6030e088191a8f1ed5d6d72c69b"
},
{
"description": "Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.\n",
"interface": {
"brand_color": null,
"default_prompt": null,
"display_name": "setup",
"icon_large_url": null,
"icon_small_url": null,
"iconography": "bolt",
"short_description": "Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.\n"
},
"name": "setup",
"plugin_release_skill_id": "pluginrsk_6abfb60240d88191ab3870dcb0a6488a"
},
{
"description": "Orchestrates the full Falcon Fusion workflow lifecycle from discovery through deployment and execution. TRIGGER when user asks to \"create a Fusion workflow\", \"build a Fusion playbook\", \"automate CrowdStrike actions\", or mentions Fusion workflows without specifying a sub-task. DO NOT TRIGGER when user is working in a Foundry app context, mentions manifest.yml, or asks to \"build a Foundry app\" — use foundry-skills instead.\n",
"interface": {
"brand_color": null,
"default_prompt": null,
"display_name": "workflows",
"icon_large_url": null,
"icon_small_url": null,
"iconography": "hierarchy",
"short_description": "Orchestrates the full Falcon Fusion workflow lifecycle from discovery through deployment and execution. TRIGGER when user asks to \"create a Fusion workflow\", \"build a Fusion playbook\", \"automate CrowdStrike actions\", or mentions Fusion workflows without specifying a sub-task. DO NOT TRIGGER when user is working in a Foundry app context, mentions manifest.yml, or asks to \"build a Foundry app\" — use foundry-skills instead.\n"
},
"name": "workflows",
"plugin_release_skill_id": "pluginrsk_6abfb6021848819193522c43055a4d84"
}
],
"version": "1.3.0"
},
"scope": "GLOBAL",
"share_url": "https://chatgpt.com/plugins/plugins_6a8f7048ed7881918bf5b79011fe2b5e?open_in_app",
"status": "ENABLED"
}SHA-256 of public snapshot: 4654cc873f592cdc30530ba39feffc937c7ac81ac9c9bd2733e752aa9fad7c53