Security patterns for Falcon Foundry apps including OAuth scopes, RBAC, input validation, UI security, and credential management. TRIGGER when user asks to "configure OAuth scopes", "secure a Foundry app", "handle secrets", "add input validation", or needs to review a Foundry app for security concerns (XSS, CSP, credential management). Also trigger during pre-deployment security reviews.
68
83%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Part of a suite. If
development-workflowhas not already run, and this is a new app or its first capability, load thedevelopment-workflowskill first — it owns the CLI prerequisite check, scaffolding order, and manifest coordination.
Security patterns for Falcon Foundry app development covering authentication, input validation, UI security, and platform-specific considerations. Foundry apps run on a cybersecurity platform — security is a core requirement.
| Capability | RBAC Supported |
|---|---|
| Collections | Yes |
| Dashboards | Yes |
| Functions | Yes |
| UI extensions / pages / navigation | Yes |
| RTR scripts | Yes |
| API integrations | No |
| Queries | No |
| Workflows | No |
Scopes control which Falcon Platform APIs the app can access. Format: <source>:<operation> (e.g., devices:read, detects:write).
| Scopes set automatically | Scopes need explicit addition |
|---|---|
| API integrations, Collections, Dashboards, Queries, UI navigation, UI sockets, Workflows | Functions, UI extensions, UI pages, RTR scripts |
foundry auth roles create --name "Analyst" --description "Read-only analyst access"
foundry auth scopes add --scope "devices:read" --scope "detects:read"Only use foundry auth scopes add for Falcon Platform API scopes needed by functions, UI extensions, UI pages, or RTR scripts. OAuth scopes for CLI-created artifacts are managed automatically.
Request only the scopes your app needs. Broad scopes like alerts:* or devices:* increase the blast radius if the app is compromised.
# manifest.yml
auth:
scopes:
- "alerts:read" # Read alerts — avoid "alerts:write" unless needed
- "detects:read" # Read detections
- "devices:read" # Device information (Hosts API)Credentials MUST be in environment variables, not in code. FalconPy handles credential discovery automatically inside FDK handlers (see functions-falcon-api):
# Inside FDK handler — auth is automatic
falcon = Alerts() # Do not pass credentials
# Outside handler (local testing) — use env vars
# FALCON_CLIENT_ID and FALCON_CLIENT_SECRET read automaticallyUse strict schemas to prevent data corruption and injection:
{
"type": "object",
"required": ["timestamp", "event_type", "source"],
"additionalProperties": false,
"properties": {
"event_type": {
"type": "string",
"enum": ["alert", "detection", "incident"]
},
"source": {
"type": "string",
"pattern": "^[a-zA-Z0-9_-]+$",
"maxLength": 50
}
}
}Sanitize CrowdStrike API responses before storing in Collections: remove sensitive fields (raw_log, internal_id, system_metadata), strip script injection, escape HTML entities, and truncate strings. See references/security-examples.md for full implementation.
Validate that input is a dict and enforce size limits (e.g., 10KB) to prevent abuse. Return generic error messages — MUST NOT expose stack traces or internal state in responses.
DOMPurify.sanitize() before any dangerouslySetInnerHTML. React auto-escapes {} expressions.DOMPurify.sanitize() in a computed property before v-html. Vue auto-escapes {{ }} expressions.For complete React and Vue XSS prevention components, see references/security-examples.md.
Configure CSP in manifest.yml for UI pages:
ui:
pages:
- name: my-page
csp:
connect_src:
- "'self'"
- "https://api.crowdstrike.com"
img_src:
- "'self'"
- "data:"
script_src:
- "'self'"Extensions run in sandboxed iframes. Validate message origins against Falcon console domains:
const allowedOrigins = [
'https://falcon.crowdstrike.com',
'https://falcon.eu-1.crowdstrike.com',
'https://falcon.us-gov-1.crowdstrike.com',
];
window.addEventListener('message', (event) => {
if (!allowedOrigins.includes(event.origin)) return;
// Process event.data
});For the full SecureConsoleMessaging class, see references/security-examples.md.
app:
name: "my-security-app"
auth:
scopes:
- "alerts:read"
- "devices:read"
functions:
- name: "process-alerts"
language: "python"
max_exec_duration_seconds: 30 # Prevent runaway execution
max_exec_memory_mb: 128 # Limit resource usage
collections:
- name: "audit_logs"
ttl: 86400 # Auto-expire sensitive data (24 hours)192.168.x.x, 10.x.x.x) in mock datatest-workstation-01, test_user)crowdstrike.com, falcon-, prod-)<script>, javascript:, onerror=)See references/security-examples.md for mock data validation and CI/CD security patterns.
| Task | Reference |
|---|---|
| Sanitization, command injection prevention, secure templates | references/security-examples.md |
| CI/CD security pipeline (GitHub Actions) | references/security-examples.md |
| PostMessage class, mock data validation | references/security-examples.md |
| Token lifecycle, antipatterns, manifest security, performance | references/security-examples.md |
61572f3
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.