---
title: "crowdstrike-falcon-foundry"
description: "Build Falcon Foundry apps with guided workflows for UI, functions, collections, Falcon Fusion SOAR workflows, and API integrations."
canonical: https://agentpluginsdirectory.com/plugins/crowdstrike-falcon-foundry
last-updated: 2026-10-02
---

# crowdstrike-falcon-foundry
Build Falcon Foundry apps with guided workflows for UI, functions, collections, Falcon Fusion SOAR workflows, and API integrations.
- Slug: crowdstrike-falcon-foundry
- Publisher: CrowdStrike
- Repository: https://github.com/CrowdStrike/foundry-skills
- Manifest: plugin.json
- Version: 1.6.0
- License: MIT
- Category (editorial): integrations
- Skills: 12 (ai-agents-development, api-integrations, collections-development, debugging-workflows, development-workflow, e2e-testing, functions-development, functions-falcon-api, fusion-redirect, security-patterns, ui-development, workflows-development)
- MCP servers: 0
- Stars: 28
- Repository created: 2026-04-07
- Repository last pushed: 2026-10-01
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/crowdstrike-falcon-foundry
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What crowdstrike-falcon-foundry does, in the publisher's words

AI coding assistant skills for building CrowdStrike Falcon Foundry apps. Build Foundry apps from a natural language prompt, API integrations, workflows, UI pages, functions, and collections, all scaffolded with the Foundry CLI and deployed to the Falcon console.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/CrowdStrike/foundry-skills/HEAD/README.md

## Skills

- ai-agents-development
- api-integrations: Expose external APIs to Falcon Foundry via OpenAPI specs. TRIGGER when user asks to "create an API integration", "adapt an OpenAPI spec for Foundry", "expose an API to workflows", "connect to a third-party API", or runs `foundry api-integrations create`. Also trigger when user has an OpenAPI/Swagge…
- collections-development: Design JSON Schema collections and CRUD patterns for Falcon Foundry apps. TRIGGER when user asks to "create a collection", "define a JSON schema", "store data in Foundry", runs `foundry collections create`, or needs help with indexable fields, FQL queries, or collection access patterns. DO NOT TRIG…
- debugging-workflows: Systematic troubleshooting for Falcon Foundry CLI errors, manifest validation failures, deploy failures, artifact runtime errors, and development server issues. TRIGGER when user encounters CLI errors, `foundry ui run` not working, deploy failures, authentication issues, function execution failures…
- development-workflow: Orchestrates the complete Falcon Foundry app lifecycle from requirements through deployment. TRIGGER when user asks to "create a Foundry app", "build a Foundry app", "plan a Foundry app", runs any `foundry apps` CLI command, or discusses Foundry app architecture. DO NOT TRIGGER when user is working…
- e2e-testing: End-to-end testing for Falcon Foundry apps using Playwright and @crowdstrike/foundry-playwright. TRIGGER when user asks to "add e2e tests", "add playwright tests", "write end-to-end tests", "test my app", or mentions "e2e", "playwright", or "end-to-end" in the context of testing a Foundry app. DO N…
- functions-development: Build serverless Go or Python functions for Falcon Foundry apps. TRIGGER when user asks to "create a function", "write a serverless function", "build backend logic", runs `foundry functions create`, or needs help with FDK handler patterns, function testing, or collection integration from functions.…
- functions-falcon-api: Call CrowdStrike Falcon platform APIs (detections, alerts, hosts, RTR) from within Foundry function handlers. TRIGGER when user asks to "call Falcon APIs from a function", "use FalconPy in a function", "use gofalcon in a function", or needs to integrate Falcon platform APIs within serverless functi…
- fusion-redirect: TRIGGER when user asks for a "standalone Falcon Fusion workflow" that needs NO Foundry app, just a trigger plus actions that already exist in their CID, with no UI, function, collection, or custom API integration to build. DO NOT TRIGGER when the request needs anything built (a custom action, a UI…
- security-patterns: Security patterns for Falcon Foundry apps including OAuth scopes, RBAC, input validation, UI security, and credential management. TRIGGER when user asks to "configure OAuth scopes", "secure a Foundry app", "handle secrets", "add input validation", or needs to review a Foundry app for security conce…
- ui-development: Build UI pages and extensions for Falcon Foundry apps using React or Vue with the Shoelace design system and Foundry-JS. TRIGGER when user asks to "create a UI page", "build a UI extension", "add a Shoelace component", "call an API from the UI", runs `foundry ui pages create` or `foundry ui run`, o…
- workflows-development: Create and configure Falcon Fusion SOAR workflow YAML for Falcon Foundry apps. TRIGGER when user asks to "create a workflow", "build an automation", "configure Fusion SOAR", "add an on-demand workflow", runs `foundry workflows create`, or needs help with Fusion YAML syntax, triggers, actions, or va…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
