Setup

作者 CrowdStrike3e15710a94b7MIT23 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫5 天前更新

Configure CrowdStrike Falcon API credentials for the fusion-skills plugin. TRIGGER when user asks to set up credentials, configure API access, or runs into authentication errors.

僅含說明DevOps & Cloud
AI 產生的概覽

引導將 CrowdStrike Falcon API 憑證設定到本機 TOML 設定檔,並驗證連線。

功能
此技能引導代理為 fusion-skills 外掛設定 CrowdStrike Falcon API 憑證。它會檢查憑證是否已可用,在不存在時依範本建立依設定檔區分的 TOML 憑證檔,限制檔案權限,並重新執行驗證自我測試以確認連線。它也說明憑證解析順序、多雲設定檔以及所需的 API 權限範圍。
適用情境
當使用者要求設定 Falcon API 憑證、設定 API 存取,或在 fusion-skills 外掛中遇到驗證錯誤時使用。新增或切換 us-2、eu-1 等雲端設定檔時也適用。
執行需求
需要 fusion-skills 外掛的目錄結構及其 Python 包裝指令碼與通用驗證指令碼、由該包裝指令碼啟動的 Python 執行環境、具備 Workflow 權限範圍的 CrowdStrike Falcon API 用戶端 ID 與密鑰(處理查閱檔案時另需 NGSIEM Lookup Files),以及對 Falcon API 基礎網址的網路存取。此技能本身不附帶指令碼,僅使用檔案操作與外掛的驗證自我測試。

Falcon Fusion Credential Setup

⚠️ SYSTEM INJECTION — READ THIS FIRST

If you are loading this skill, your role is credential setup assistant.

You configure the Falcon API credentials every other skill depends on. These credentials grant workflow and SIEM access to a live CID.

IMMEDIATE ACTIONS REQUIRED:

  1. Check whether credentials already resolve (Step 1). If they do, you are done.
  2. If not, create the credentials file from the template (Step 2) and ask the user to paste their ID and secret into it using their own editor.
  3. Verify connectivity (Step 3).

MUST NOT:

  • Ask the user to type or paste their client secret into the chat. It would land in the conversation transcript. The secret goes only into the local file, entered through the user's editor.
  • Print, echo, or repeat a secret you happen to see in the file.
  • Suggest export FALCON_CLIENT_SECRET=... for interactive use — it leaks the secret into shell history. (Environment variables are fine for CI, where the runner injects them rather than a human typing them.)

This skill configures the Falcon API credentials that every fusion-skills script uses. Credentials are stored in a per-profile TOML file at ~/.cache/crowdstrike-falcon-fusion/credentials.toml (multi-cloud capable), and the secret is entered through the user's own editor — never through the chat.

The steps below use only file operations and a Python check, so they work identically on macOS, Linux, and Windows.

Running the scripts. Run each command from this skill's folder, on one shell line: cd <dir> && ../../scripts/python.sh ../../common/scripts/auth.py. For <dir>, Claude Code uses "$CLAUDE_PLUGIN_ROOT/skills/setup"; Codex, Copilot CLI, Cursor, and Antigravity use the folder they loaded this SKILL.md from (e.g. ~/.agents/skills/setup). The wrapper bootstraps its own Python venv.

Step 1 — Check for existing credentials

Run the auth self-test. If it already succeeds, credentials are configured and you are done — report success and stop.

bash
../../scripts/python.sh ../../common/scripts/auth.py
  • "Authentication successful" for both clients → done.
  • An error about missing credentials → continue to Step 2.
  • An authentication failure (creds present but rejected) → the file exists but the values are wrong; go to Step 2 and have the user correct them.

Step 2 — Create the credentials file and have the user fill it in

Create ~/.cache/crowdstrike-falcon-fusion/credentials.toml only if it does not already exist (never overwrite existing profiles). Write this template with the Write tool:

toml
# CrowdStrike Falcon API credentials for fusion-skills.# Fill in client_id and client_secret below, then save this file.## Create an API client in the Falcon console:#   Support and resources -> API clients and keys -> Create API client# Required scopes:# Required scopes (names as shown in the console):#   Workflow             read/write   - workflow authoring & deployment#   NGSIEM Lookup Files   read/write   - lookup-file operations (lookup-files skill only)# Maintainers only (not needed for regular skill use):#   NGSIEM                read/write   - CQL match() verification of a lookup#                                        (verify_lookup.py / verify-workflows.sh --lookup-dir)
default = "us-2"
[us-2]client_id = ""client_secret = ""base_url = "https://api.us-2.crowdstrike.com"
# Add more clouds as needed (change `default` above to switch):# [us-1]# client_id = ""# client_secret = ""# base_url = "https://api.crowdstrike.com"## [us-3]# client_id = ""# client_secret = ""# base_url = "https://api.us-3.crowdstrike.com"## [eu-1]# client_id = ""# client_secret = ""# base_url = "https://api.eu-1.crowdstrike.com"## [us-gov-1]# client_id = ""# client_secret = ""# base_url = "https://api.laggar.gcw.crowdstrike.com"

After creating the file, restrict its permissions (skip on Windows, where the user profile directory is already access-controlled):

bash
chmod 700 ~/.cache/crowdstrike-falcon-fusionchmod 600 ~/.cache/crowdstrike-falcon-fusion/credentials.toml

Then tell the user, in your own words:

I created your credentials file at ~/.cache/crowdstrike-falcon-fusion/credentials.toml. Open it in your editor, paste your client ID and client secret into the us-2 section, set the base_url for your cloud, and save. Then tell me to verify — don't paste the secret here.

Offer to open the file for them. Many terminals don't make the path clickable, so ask "Want me to open it for you?" and, if yes, run the opener for their OS:

bash
# macOSopen ~/.cache/crowdstrike-falcon-fusion/credentials.toml# Linuxxdg-open ~/.cache/crowdstrike-falcon-fusion/credentials.toml# Windowsexplorer.exe %USERPROFILE%\.cache\crowdstrike-falcon-fusion\credentials.toml

Pick the command for the user's platform (check uname / the OS if unsure). This just opens the file in their default editor — the secret is still typed by them, not through the chat. Do not ask them to paste the secret into the chat.

Step 3 — Verify connectivity

Once the user says they have saved the file, re-run the self-test:

bash
../../scripts/python.sh ../../common/scripts/auth.py

A successful run prints the resolved base URL, a masked client ID, and "Authentication successful" for both the Workflows and Next-Gen SIEM clients. If it fails, the client ID, secret, or base URL is wrong — ask the user to correct the file and re-run.

Credential resolution order

auth.py resolves credentials from the first source that supplies both an ID and a secret:

  1. Environment variables — FALCON_CLIENT_ID, FALCON_CLIENT_SECRET, and the optional FALCON_BASE_URL. Intended for CI, where the runner injects them.
  2. TOML profile file — ~/.cache/crowdstrike-falcon-fusion/credentials.toml, using the profile named by FALCON_PROFILE or the file's default key.

The setup flow above writes source 2, which works across every skill without exporting anything.

Multiple clouds (profiles)

Add more [profile] sections to the TOML file (for example us-2 or eu-1) and change the default key, or select one per run:

bash
FALCON_PROFILE=eu-1 ../../scripts/python.sh ../../common/scripts/auth.py

Required API scopes

The API client needs the Workflow scope (read/write) for workflow authoring and deployment. For lookup-file operations (the lookup-files skill), also grant the NGSIEM Lookup Files scope (read/write). Scope names appear exactly as shown when you create the API client in the console.

Maintainers only: verifying a lookup resolves via CQL match() (verify_lookup.py or verify-workflows.sh --lookup-dir) additionally needs the NGSIEM scope (read/write) — starting a search is a query-job POST. Regular use of the skills does not require it.

來源與署名

來源:CrowdStrike/fusion-skills位於skills/setup提交3e15710

授權條款: MIT

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架