crowdstrike-falcon-fusion
v1.2.0CrowdStrike Falcon Fusion skills for authoring, deploying, and executing Fusion workflows. Includes live action discovery, YAML authoring with schema validation, workflow import and release, execution monitoring, and Falcon Next-Gen SIEM lookup files.
By CrowdStrikeLicense: MIT20 GitHub starsUpdated 1 hour ago
Directory evidence
- Runtimes
- Codex, Claude Code, and Agent Plugins
- Parsed components
- 7 skill or MCP entries
- Source updated
- Sep 29, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install crowdstrike-falcon-fusion for Codex and Claude Code
codex plugin marketplace add CrowdStrike/fusion-skills
codex plugin marketplace upgrade fusion-marketplace
codex plugin add crowdstrike-falcon-fusion@fusion-marketplacePaste and run these commands in a terminal with Codex. They add and refresh the fusion-marketplace catalog, then install this plugin.
Compatibility: the page URL and API slug “crowdstrike-falcon-fusion” remain stable.
- Codex:
crowdstrike-falcon-fusion@agent-plugin-marketplace→crowdstrike-falcon-fusion@fusion-marketplace
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/CrowdStrike/fusion-skillsClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The repository root is the plugin root.
Plugin files
├── .codex-plugin/plugin.json├── .claude-plugin/plugin.json├── plugin.json├── skills/authoring/SKILL.md├── skills/deployment/SKILL.md├── skills/execution/SKILL.md├── skills/foundry-redirect/SKILL.md├── skills/lookup-files/SKILL.md├── skills/setup/SKILL.md└── skills/workflows/SKILL.md
Included Skills7
Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, validate a workflow, use CEL expressions, or needs action discovery. DO NOT TRIGGER for deploying, importing, executing, or monitoring workflows — use deployment or execution skills. DO NOT TRIGGER when the request is for a Falcon Foundry app, a UI extension/page, an API integration, custom actions from a third-party API, or a manifest.yml — those are foundry-skills territory; advise foundry-skills instead of authoring a workflow.
Import, release, and manage Falcon Fusion workflow definitions in a CID. TRIGGER when user asks to import a workflow, release a workflow version, list existing workflows, check for duplicates, or manage workflow definitions. DO NOT TRIGGER for writing YAML (use authoring), executing workflows, or monitoring (use execution).
Trigger Falcon Fusion workflows, monitor execution status, and debug failures. TRIGGER when user asks to run a workflow, check execution status, tail logs, get execution results, or debug a workflow failure. DO NOT TRIGGER for writing YAML (use authoring) or importing/releasing workflows (use deployment).
TRIGGER when the user asks to "build a Foundry app", "create a Foundry app", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow that only wires together existing actions. This skill declines Foundry-app requests and points to the crowdstrike-falcon-foundry plugin, so the redirect works even without Claude Code hooks; it yields to the real Foundry plugin when that plugin is also installed.
Manage Falcon Next-Gen SIEM lookup files (CSV/JSON/TXT) for CQL match() queries. TRIGGER when user asks to create, list, update, or delete lookup files, or needs help with CQL match() function. DO NOT TRIGGER for Fusion workflows, action discovery, or workflow deployment — use the workflows/authoring/deployment skills.
Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.
Orchestrates the full Falcon Fusion workflow lifecycle from discovery through deployment and execution. TRIGGER when user asks to "create a Fusion workflow", "build a Fusion playbook", "automate CrowdStrike actions", or mentions Fusion workflows without specifying a sub-task. DO NOT TRIGGER when user is working in a Foundry app context, mentions manifest.yml, or asks to "build a Foundry app" — use foundry-skills instead.
Plugin manifests3
{
"name": "crowdstrike-falcon-fusion",
"version": "1.2.0",
"description": "CrowdStrike Falcon Fusion skills for authoring, deploying, and executing Fusion workflows. Includes live action discovery, YAML authoring with schema validation, workflow import and release, execution monitoring, and Falcon Next-Gen SIEM lookup files.",
"author": {
"name": "CrowdStrike",
"url": "https://github.com/CrowdStrike"
},
"homepage": "https://github.com/CrowdStrike/fusion-skills",
"repository": "https://github.com/CrowdStrike/fusion-skills",
"license": "MIT",
"keywords": [
"crowdstrike",
"falcon",
"fusion",
"soar",
"workflow",
"automation",
"security"
],
"skills": "./skills/",
"interface": {
"displayName": "CrowdStrike Falcon Fusion",
"shortDescription": "Build Falcon Fusion workflows",
"longDescription": "Discover live Falcon Fusion actions, author workflow YAML with schema validation, import and release workflow definitions to a CID, trigger and monitor executions, and manage Falcon Next-Gen SIEM lookup files.",
"developerName": "CrowdStrike",
"category": "Developer Tools",
"capabilities": [
"Interactive",
"Write"
],
"websiteURL": "https://github.com/CrowdStrike/fusion-skills",
"defaultPrompt": [
"Create a Falcon Fusion workflow",
"Automate a CrowdStrike response",
"Troubleshoot a Fusion workflow"
],
"brandColor": "#E01F3D",
"composerIcon": "./assets/crowdstrike-logo.png",
"logo": "./assets/crowdstrike-logo.png"
}
}{
"name": "crowdstrike-falcon-fusion",
"description": "CrowdStrike Falcon Fusion skills for authoring, deploying, and executing Fusion workflows. Includes live action discovery, YAML authoring with schema validation, workflow import and release, execution monitoring, and Falcon Next-Gen SIEM lookup files.",
"version": "1.2.0",
"author": {
"name": "CrowdStrike"
},
"license": "MIT",
"keywords": [
"crowdstrike",
"falcon",
"fusion",
"soar",
"workflow",
"automation",
"security"
]
}{
"$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
"name": "crowdstrike-falcon-fusion",
"version": "1.2.0",
"description": "CrowdStrike Falcon Fusion skills for authoring, deploying, and executing Fusion workflows. Includes live action discovery, YAML authoring with schema validation, workflow import and release, execution monitoring, and Falcon Next-Gen SIEM lookup files.",
"author": {
"name": "CrowdStrike",
"url": "https://github.com/CrowdStrike"
},
"homepage": "https://github.com/CrowdStrike/fusion-skills",
"repository": "https://github.com/CrowdStrike/fusion-skills",
"license": "MIT",
"keywords": [
"crowdstrike",
"falcon",
"fusion",
"soar",
"workflow",
"automation",
"security"
]
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[crowdstrike-falcon-fusion on Agent Plugins Marketplace](https://pluginsmp.com/plugins/crowdstrike-falcon-fusion)