Skip to content

Add focused CrowdStrike CQL agent skills - #89

Closed
yayalingo wants to merge 1 commit into
ByteRay-Labs:mainfrom
yayalingo:add-vscode-cql-agent-skills
Closed

yayalingo wants to merge 1 commit into
ByteRay-Labs:mainfrom
yayalingo:add-vscode-cql-agent-skills

Conversation

@yayalingo

Copy link
Copy Markdown

No description provided.

@yayalingo

Copy link
Copy Markdown
Author

Summary

Add workspace-scoped VS Code Agent Skills for writing and adapting CrowdStrike Falcon CQL.

  • Add a core skill for CQL syntax, query structure, aggregation, and troubleshooting.
  • Add eight focused skills for process hunting, extended process patterns, identity, network, endpoint inventory, host integrity, data movement, and scheduled tasks.
  • Embed 95 CQL query bodies directly in the skills, so agents can use them without following external query links.
  • Leave the existing queries/ catalog and website query format unchanged.

Validation

  • Verified skill frontmatter, directory names, Markdown fences, and file lengths.
  • Confirmed all 95 embedded query entries are unique.
  • Queries were not run against a Falcon tenant; field and telemetry availability may vary.

This is an optional agent-tooling contribution alongside the existing query catalog.

@dweissbacher

Copy link
Copy Markdown
Collaborator

Thanks for putting this together. Making the hub easier for agents to use is something we've been thinking about too.

We've decided not to take this route for now, for two reasons:

  1. Maintenance on our side. The skills embed copies of the queries, so every new submission or fix would also need a matching skill update. We could automate that with a script, but it adds a second artifact to keep in sync with queries/ on every merge.
  2. Maintenance on the user's side. Anyone who installs the skills gets a snapshot. To see new submissions they'd have to pull and update the skills every time, and most people won't, so their agents would quietly work from an outdated set.

We do want to support AI agents properly. A likely direction is a MCP server, so agents can search and fetch queries live without a local copy that goes stale.

I'll close this for now. Thanks again for the time you put into it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants