workflows-development

Design, customize, and deploy Falcon Foundry workflows via YAML.

24|3|Updated Apr 7, 2026
One-click install
npx skills add https://github.com/CrowdStrike/foundry-skills --skill workflows-development
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: workflows-development
Source: https://github.com/CrowdStrike/foundry-skills/tree/main/skills/workflows-development
Command: npx skills add https://github.com/CrowdStrike/foundry-skills --skill workflows-development

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill enables users to create, customize, and manage Falcon Foundry workflows efficiently using YAML definitions, streamlining automation setup and orchestration.

Core Features & Use Cases

  • Workflow Creation and Management: Generate and edit YAML-driven workflows for various automation tasks within Falcon Foundry.
  • Reusable Templates: Develop templates for scheduled, on-demand, or complex multi-step workflows with conditionals and loops.
  • Use Case: Automate threat response by orchestrating multi-step investigative procedures with error handling and dynamic data references.

Quick Start

Use the workflows development skill to define a simple on-demand workflow that prints a greeting message.

Frequently Asked Questions about workflows-development

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build Falcon Foundry workflows with YAML automation?

You can build Falcon Foundry workflows by defining YAML definitions that orchestrate multi-step security and incident response tasks. This approach supports triggers, actions, loops, and conditions to streamline automation setup.

Can I use conditionals and loops in Falcon Foundry YAML workflows?

Yes, Falcon Foundry YAML workflows support complex automation structures including conditionals and loops. You can define multi-step procedures with dynamic data references and error handling for robust security orchestration.

What is the best way to automate threat response in Falcon Foundry?

The best way to automate threat response is designing YAML-driven workflows that orchestrate multi-step investigative procedures. This method integrates error handling and dynamic data references within the Falcon ecosystem.

Does this approach support scheduled and on-demand workflow templates?

Yes, you can develop reusable YAML templates for scheduled, on-demand, or complex multi-step workflows. This ensures proper syntax validation and integration of triggers and actions within Falcon Foundry.

How do I validate syntax and error handling for Falcon Foundry YAML workflows?

Validating syntax and error handling for Falcon Foundry YAML workflows involves ensuring proper integration of triggers, actions, and conditions. The skill facilitates validation to maintain robust security automation and orchestration.