CtrlK
BlogDocsLog inGet started
Tessl Logo

functions-falcon-api

Call CrowdStrike Falcon platform APIs (detections, alerts, hosts, RTR) from within Foundry function handlers. TRIGGER when user asks to "call Falcon APIs from a function", "use FalconPy in a function", "use gofalcon in a function", or needs to integrate Falcon platform APIs within serverless function code. DO NOT TRIGGER when user wants to expose external third-party APIs to Foundry — use api-integrations instead.

89

1.29x
Quality

86%

Does it follow best practices?

Impact

97%

1.29x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

High-value reference content: nearly everything is verified, non-obvious gotcha material with complete executable code for both Python and Go. The main structural weaknesses are a dangling reference to a nonexistent use-cases file, heavy inline sections that belong in the references bundle, and repeated deprecation warnings that cost tokens without adding information.

Suggestions

Fix or remove the dangling reference to `use-cases/python-functions.md` — no use-cases file exists in the bundle, so the pointer dead-ends.

Move the LogScale/NG-SIEM section (query pattern, both gotchas, and the polling implementation) into a reference file like references/advanced-patterns.md, keeping a short pattern summary plus pointer in SKILL.md.

State the Detects deprecation once in a clearly-marked deprecation section and trim the 'Common Pitfalls' bullets that restate guidance already given above, cutting roughly three redundant repetitions.

DimensionReasoningScore

Conciseness

The body is dense with non-inferable material Claude cannot know (the `search=` keyword gotcha with linked issues, the `search-all` repository 403 trap, the verified scope table, the asymmetric `resources`/`body` response keys), so most tokens earn their place. It is not a 5 because of identifiable trim targets: the Detects deprecation warning is stated three times (lines 16–22 banner, the "DEPRECATED API — NEVER USE" block, and again at the Detection Queries heading), the "SYSTEM INJECTION — READ THIS FIRST" role-assignment banner adds no technical content, and several "Common Pitfalls" bullets restate guidance already given above.

4 / 5

Actionability

Every section ships complete, executable code: a full Python FDK handler with query-then-fetch-details flow, a Go handler with `fdk.FalconClientOpts()` auth, a runnable NGSIEM polling function with relative-time params, a `Mock`/`patch` test, local-testing shell commands with `curl`, and manifest YAML for scopes. Examples cover the common cases end-to-end and are copy-paste ready, including error branches with status-code checks.

5 / 5

Workflow Clarity

This is a pattern reference rather than a linear pipeline, and its recurring shape (construct zero-arg client inside handler → call → check `status_code` → branch on error) is consistently modeled with explicit checkpoints, including the 207 Multi-Status embedded-error check for batch actions and a polling loop with timeout for async searches. Not a 5 because there is no sequenced onboarding flow tying sections together (a reader must infer which pattern applies when), and the scope-decision fallback ends in 'ask the user' rather than a verification step.

4 / 5

Progressive Disclosure

The one bundle file, references/advanced-patterns.md, is clearly signaled via a Reference Files table plus inline links and links back to its parent (one level deep) — but the body points to `use-cases/python-functions.md`, which does not exist in the bundle, a dangling reference. Additionally, substantial content that would fit the reference pattern sits inline: the ~110-line LogScale/NGSIEM section (three subsections, two gotchas, a full polling implementation) and the scope/severity tables, while the existing reference file is left carrying only some of this depth.

3 / 5

Total

16

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states a specific capability, gives verbatim natural trigger phrases with SDK synonyms, and draws an explicit boundary against the adjacent api-integrations skill. The only minor gap is that the capability is expressed as one action over several API domains rather than multiple distinct actions.

DimensionReasoningScore

Specificity

"Call CrowdStrike Falcon platform APIs (detections, alerts, hosts, RTR) from within Foundry function handlers" names the domain and enumerates four concrete API areas plus the execution context. It stays at score 4 rather than 5 because the action itself is singular ("call APIs") — the enumerated items are object domains, not distinct actions like the anchor's "extract, fill, merge, convert".

4 / 5

Completeness

The 'what' is explicit (call Falcon platform APIs for detections, alerts, hosts, RTR from within Foundry function handlers) and the 'when' is explicit with concrete trigger phrases ("TRIGGER when user asks to..."). Both halves are answered clearly and concretely, matching the top anchor; nothing is left implicit.

5 / 5

Trigger Term Quality

Quotes natural user phrases verbatim — "call Falcon APIs from a function", "use FalconPy in a function", "use gofalcon in a function" — and adds the synonym path "integrate Falcon platform APIs within serverless function code". Coverage includes SDK names (FalconPy, gofalcon) and the generic phrasing, matching the comprehensive-with-synonyms anchor.

5 / 5

Distinctiveness Conflict Risk

The skill occupies a clear niche (Falcon platform APIs called from inside Foundry functions) and includes an explicit negative boundary — "DO NOT TRIGGER when user wants to expose external third-party APIs to Foundry — use api-integrations instead" — which resolves the nearest-neighbor conflict directly. Minimal conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
CrowdStrike/foundry-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.