---
title: "crowdstrike-falcon-fusion"
description: "CrowdStrike Falcon Fusion skills for authoring, deploying, and executing Fusion workflows. Includes live action discovery, YAML authoring with schema validation, workflow import and release, execution monitoring, and Fal"
canonical: https://agentpluginsdirectory.com/plugins/crowdstrike-falcon-fusion
last-updated: 2026-10-02
---

# crowdstrike-falcon-fusion
CrowdStrike Falcon Fusion skills for authoring, deploying, and executing Fusion workflows. Includes live action discovery, YAML authoring with schema validation, workflow import and release, execution monitoring, and Falcon Next-Gen SIEM lookup files.
- Slug: crowdstrike-falcon-fusion
- Publisher: CrowdStrike
- Repository: https://github.com/CrowdStrike/fusion-skills
- Manifest: plugin.json
- Version: 1.3.0
- License: MIT
- Category (editorial): integrations
- Skills: 7 (authoring, deployment, execution, foundry-redirect, lookup-files, setup, workflows)
- MCP servers: 0
- Stars: 20
- Repository created: 2026-06-26
- Repository last pushed: 2026-10-01
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/crowdstrike-falcon-fusion
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What crowdstrike-falcon-fusion does, in the publisher's words

AI coding assistant skills for building CrowdStrike Falcon Fusion workflows. Go from a natural language prompt to a working Fusion workflow, discover real action IDs from the live API, author the YAML, validate it against the platform schema, import it to a CID, and trigger and monitor its execution.

> fusion-skills is a community-driven, open source project, not a CrowdStrike product. As such, it carries no formal support, expressed or implied.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/CrowdStrike/fusion-skills/HEAD/README.md

## Skills

- authoring: Discover Falcon Fusion actions via live API, author workflow YAML with correct schema, validate against Charlotte JSON schema, and use templates/examples. TRIGGER when user asks to write workflow YAML, find actions, validate a workflow, use CEL expressions, or needs action discovery. DO NOT TRIGGER…
- deployment: Import, release, and manage Falcon Fusion workflow definitions in a CID. TRIGGER when user asks to import a workflow, release a workflow version, list existing workflows, check for duplicates, or manage workflow definitions. DO NOT TRIGGER for writing YAML (use authoring), executing workflows, or m…
- execution: Trigger Falcon Fusion workflows, monitor execution status, and debug failures. TRIGGER when user asks to run a workflow, check execution status, tail logs, get execution results, or debug a workflow failure. DO NOT TRIGGER for writing YAML (use authoring) or importing/releasing workflows (use deplo…
- foundry-redirect: TRIGGER when the user asks to "build a Foundry app", "create a Foundry app", mentions manifest.yml, or needs a UI page/extension, serverless function, collection, or a custom API integration from a third-party API (Okta, ServiceNow, Jira, etc.) built. DO NOT TRIGGER for a standalone Fusion workflow…
- lookup-files: Manage Falcon Next-Gen SIEM lookup files (CSV/JSON/TXT) for CQL match() queries. TRIGGER when user asks to create, list, update, or delete lookup files, or needs help with CQL match() function. DO NOT TRIGGER for Fusion workflows, action discovery, or workflow deployment, use the workflows/authori…
- setup: Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.
- workflows: Orchestrates the full Falcon Fusion workflow lifecycle from discovery through deployment and execution. TRIGGER when user asks to "create a Fusion workflow", "build a Fusion playbook", "automate CrowdStrike actions", or mentions Fusion workflows without specifying a sub-task. DO NOT TRIGGER when us…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
