# LimaCharlie — AI Connector

LimaCharlie publishes 175 MCP tools to Claude. Marketplace availability, tool surface, verification tier, and what Node8 measured against the live endpoint.

Source: https://node8.ai/ai-connectors/other/limacharlie/

---

[AI Connectors](https://node8.ai/ai-connectors/) · [Other](https://node8.ai/ai-connectors/other/)

# LimaCharlie

SecOps automation across EDR, XDR, vulnerability and cloud security

Listed in Claude · 175 published tools · Community-listed

[Claude connector docs](https://doc.limacharlie.io/) [limacharlie.io](https://limacharlie.io/)

Overview

## What LimaCharlie does

LimaCharlie is a security operations platform covering EDR, XDR, vulnerability management and cloud security, and this connector automates against it.

The surface is unusually large, and its shape reflects a platform rather than a product: detection and response rules can be set, investigations and cases managed, LCQL queries run against telemetry, cloud security graphs traversed for public access and neighbour relationships, and CVEs mapped to affected hosts. Administration is included down to groups, secrets, quota usage and billing plans. Community tier, documentation published.

### Who it is for

Security operations teams automating detection, response and cloud posture work.

### Tool surface

Three hundred and thirty-nine tools answered against 175 claimed, a gap of well over a hundred. They span detection rules such as set\_rule and set\_dr\_managed\_rule, investigations and cases, LCQL queries, cloud security graph traversal, vulnerability-to-host mapping, and tenant administration down to billing plans and quotas.

Availability

## Where LimaCharlie is listed

LimaCharlie is listed in the Claude connectors directory only. LimaCharlie has no app under the same domain in the ChatGPT directory; 392 of the 3,150 products here are on both marketplaces, and this is not one of them.

The MCP server behind a Claude connector is usually the same server a ChatGPT app would need, so the absence is a distribution decision rather than a technical one.

Claude listing

## In the Claude connectors directory

LimaCharlie publishes 175 tools to Claude. Only 8 of the 1,253 Claude-listed connectors expose more, one of the widest tool surfaces in the directory.

The median Claude-listed connector filed under the Other bucket publishes 10, so this one runs 165 tools above its bucket's median and ranks 1st of 22 by tool count.

It falls in the 51+ tools band, which holds 9.6% of the Claude directory.

### Measured against the live endpoint

A direct call to the endpoint returned 339 tools, 164 more than the 175 the listing publishes. Probed 2026-08-07.

#### Tools the server actually returns

-   `vulnerability_cve_hosts`
-   `cloudsec_get_public_access`
-   `delete_saved_query`
-   `get_drivers`
-   `list_investigations`
-   `add_case_entity`
-   `set_dr_managed_rule`
-   `set_rule`
-   `get_quota_usage`
-   `cloudsec_get_graph_neighbors`
-   `run_lcql_query_free`
-   `set_exfil_watch_rule`
-   `create_group`
-   `list_billing_plans`
-   `disable_secret`
-   `cloudsec_export_csv`
-   `analyze_lcql_query`
-   `get_process_modules`
-   `get_autoruns`
-   `get_packages`
-   `add_tag`
-   `expand_investigation`
-   `delete_ai_skill`
-   `run_lcql_query`
-   `get_usage_stats`
-   `remove_feedback_channel`
-   `generate_dr_rule_respond`
-   `generate_detection_summary`
-   `lc_call_tool`
-   `cloudsec_get_fleet_overview`
-   `get_dr_managed_rule`
-   `enable_fp_rule`
-   `get_lookup`
-   `set_hive_record_comment`
-   `cloudsec_list_caasm_assets`
-   `get_process_strings`
-   `remove_org_from_group`
-   `start_ai_session`
-   `list_ai_usage`
-   `cloudsec_run_query`
-   `find_sensors_by_tag`
-   `get_case_report`
-   `vulnerability_bulk_set_finding_resolution`
-   `validate_hive_record`
-   `yara_scan_directory`
-   `search_case_entities`
-   `add_org_user`
-   `query_lookup`
-   `delete_extension_config`
-   `list_feedback_channels`
-   `get_adapter_sensors`
-   `delete_ai_memory`
-   `delete_reliable_task`
-   `add_case_telemetry`
-   `set_org_note`
-   `get_saved_query`
-   `delete_cloud_sensor`
-   `cloudsec_test_provider`
-   `vulnerability_snapshot_list`
-   `run_saved_query`
-   `cloudsec_set_finding_ticket`
-   `list_playbooks`
-   `list_api_keys`
-   `request_feedback_ack`
-   `generate_dr_rule_detection`
-   `isolate_network`
-   `get_fp_rule`
-   `get_mitre_report`
-   `get_org_note`
-   `get_artifact`
-   `task_sensor`
-   `get_case_dashboard`
-   `delete_dr_service_rule`
-   `delete_rule`
-   `cloudsec_get_identity_facets`
-   `cloudsec_get_policy_vocabulary`
-   `reliable_tasking`
-   `get_users_permissions`
-   `list_audit_logs`
-   `list_payloads`
-   `delete_org_note`
-   `list_available_extensions`
-   `list_dr_service_rules`
-   `set_dr_service_rule`
-   `list_user_orgs`
-   `get_installation_key`
-   `get_ai_session_history`
-   `list_external_adapters`
-   `enable_adapter`
-   `get_ai_chat`
-   `search_iocs`
-   `get_billing_details`
-   `get_org_oid_by_name`
-   `list_outputs`
-   `cloudsec_list_attack_paths`
-   `list_sensor_tags`
-   `wait_sensor_online`
-   `set_org_description`
-   `generate_lcql_query`
-   `get_online_sensors`
-   `list_ai_sessions`
-   `cloudsec_list_chokepoints`
-   `cloudsec_list_compliance_frameworks`
-   `get_historic_events`
-   `get_event_by_atom`
-   `dir_find_hash`
-   `enable_dr_rule`
-   `delete_group`
-   `get_sop`
-   `cloudsec_list_changes`
-   `estimate_lcql_query`
-   `get_detection`
-   `set_saved_query`
-   `list_cloud_sensors`
-   `export_sensors`
-   `create_org`
-   `vulnerability_get_cve`
-   `cloudsec_get_overview`
-   `cloudsec_list_finding_causes`
-   `cloudsec_get_identity`
-   `get_sensor_info`
-   `list_with_platform`
-   `get_network_connections`
-   `cloudsec_set_finding_owner`
-   `list_dr_general_rules`
-   `cloudsec_get_risk_trend`
-   `who_am_i`
-   `get_fp_rules`
-   `add_group_member`
-   `set_lookup`
-   `get_extension_config`
-   `set_extension_config`
-   `set_sop`
-   `cloudsec_get_data_security_facets`
-   `set_dr_general_rule`
-   `remove_org_user`
-   `set_ai_memory`
-   `yara_scan_process`
-   `set_fp_rule`
-   `get_secret`
-   `request_feedback_approval`
-   `set_org_value`
-   `get_playbook`
-   `generate_sensor_selector`
-   `cloudsec_get_topology`
-   `cloudsec_list_identities`
-   `cloudsec_get_provider_manifests`
-   `vulnerability_reset_asset_findings`
-   `get_hive_schema`
-   `delete_sensor`
-   `delete_lookup`
-   `get_payload`
-   `resolve_arl`
-   `get_platform_names`
-   `collect_velociraptor_artifact`
-   `get_cloud_sensor`
-   `cloudsec_ingest_caasm_records`
-   `list_extension_subscriptions`
-   `vulnerability_scan`
-   `dir_list`
-   `cloudsec_dismiss_chokepoint`
-   `delete_fp_rule`
-   `vulnerability_dashboard`
-   `set_hive_record_enabled`
-   `batch_search_iocs`
-   `get_group_info`
-   `delete_external_adapter`
-   `vulnerability_query_endpoints`
-   `rename_hive_record`
-   `cloudsec_simulate_finding_match`
-   `get_registry_keys`
-   `merge_cases`
-   `validate_dr_rule_components`
-   `get_os_version`
-   `set_cloud_sensor`
-   `delete_investigation`
-   `get_external_adapter`
-   `vulnerability_query_cves`
-   `reset_event_schemas`
-   `list_saved_queries`
-   `show_velociraptor_artifact`
-   `mass_remove_tag`
-   `upgrade_sensors`
-   `get_detection_rules`
-   `is_online`
-   `test_tool`
-   `delete_yara_rule`
-   `delete_output`
-   `extension_request`
-   `create_case`
-   `get_case`
-   `get_extension_schema`
-   `create_payload`
-   `list_org_notes`
-   `get_event_schema`
-   `get_processes`
-   `list_velociraptor_artifacts`
-   `list_reliable_tasks`
-   `list_cases`
-   `cloudsec_bulk_set_finding_status`
-   `cloudsec_get_scan_status`
-   `delete_dr_general_rule`
-   `list_dr_managed_rules`
-   `list_exfil_rules`
-   `import_dr_rules`
-   `add_user_permission`
-   `delete_api_key`
-   `cloudsec_get_finding_facets`
-   `cloudsec_list_compliance_assignments`
-   `create_installation_key`
-   `disable_fp_rule`
-   `dismiss_org_error`
-   `enable_secret`
-   `get_event_types_with_schemas_for_platform`
-   `add_org_to_group`
-   `list_yara_sources`
-   `list_org_users`
-   `get_ai_chat_history`
-   `get_atom_children`
-   `add_case_detection`
-   `delete_exfil_rule`
-   `replay_dr_rule`
-   `request_feedback_question`
-   `list_ai_chats`
-   `cloudsec_get_caasm_policy`
-   `delete_playbook`
-   `vulnerability_cve_packages`
-   `cloudsec_resolve_sensors`
-   `get_event_schemas_batch`
-   `get_investigation`
-   `bulk_update_cases`
-   `list_yara_rules`
-   `validate_yara_rule`
-   `list_lookups`
-   `validate_lcql_query`
-   `remove_user_permission`
-   `get_org_delete_confirmation`
-   `generate_python_playbook`
-   `get_services`
-   `list_artifacts`
-   `cloudsec_set_caasm_policy`
-   `set_yara_ruleset`
-   `delete_yara_ruleset`
-   `get_org_invoice_url`
-   `subscribe_to_extension`
-   `cloudsec_suggest_policy_values`
-   `get_dr_general_rule`
-   `create_api_key`
-   `vulnerability_host_packages`
-   `disable_adapter`
-   `cloudsec_get_compliance_report`
-   `yara_scan_memory`
-   `get_users`
-   `get_org_urls`
-   `add_case_note`
-   `remove_group_member`
-   `set_secret`
-   `delete_secret`
-   `set_playbook`
-   `get_rule`
-   `get_ai_session`
-   `terminate_ai_session`
-   `cloudsec_list_queries`
-   `cloudsec_list_caasm_coverage`
-   `cloudsec_resolve_assets`
-   `find_strings`
-   `mass_add_tag`
-   `update_case`
-   `list_ai_skills`
-   `delete_org`
-   `get_historic_detections`
-   `cloudsec_list_inventory`
-   `yara_scan_file`
-   `rejoin_network`
-   `delete_installation_key`
-   `get_yara_rule`
-   `validate_usp_mapping`
-   `add_output`
-   `is_isolated`
-   `memory_dump_sensor`
-   `list_installation_keys`
-   `cloudsec_restore_chokepoint`
-   `delete_payload`
-   `cloudsec_get_resource`
-   `get_org_info`
-   `get_group_logs`
-   `set_hive_record_tags`
-   `set_adapter_tags`
-   `list_case_entities`
-   `delete_dr_managed_rule`
-   `get_ai_skill`
-   `get_billing_status`
-   `get_org_value`
-   `cloudsec_simulate_resource_match`
-   `get_time_when_sensor_has_data`
-   `remove_tag`
-   `unsubscribe_from_extension`
-   `list_sops`
-   `add_feedback_channel`
-   `get_adapter_schema`
-   `set_exfil_event_rule`
-   `list_rules`
-   `rename_org`
-   `cloudsec_get_inventory_facets`
-   `set_yara_rule`
-   `set_user_role`
-   `remove_group_owner`
-   `list_secrets`
-   `vulnerability_epss_history`
-   `rekey_extension`
-   `cloudsec_get_finding`
-   `cloudsec_set_finding_status`
-   `add_group_owner`
-   `set_external_adapter`
-   `delete_sop`
-   `vulnerability_list_finding_resolutions`
-   `vulnerability_set_finding_resolution`
-   `get_ai_usage`
-   `test_dr_rule_events`
-   `get_org_errors`
-   `cloudsec_list_findings`
-   `cloudsec_list_finding_classes`
-   `list_extension_configs`
-   `set_ai_skill`
-   `cloudsec_list_data_stores`
-   `cloudsec_get_free_tier_status`
-   `seal_sensor`
-   `add_case_artifact`
-   `get_sku_definitions`
-   `list_groups`
-   `set_group_permissions`
-   `set_org_quota`
-   `list_sensors`
-   `search_hosts`
-   `get_event_types_with_schemas`
-   `unseal_sensor`
-   `set_investigation`
-   `disable_dr_rule`
-   `list_groups_detailed`

LimaCharlie publishes a remote MCP endpoint. Claude connects to it over HTTP; there is nothing to install locally.

Every connector in the Claude directory is remote, all 1,253 of them, so transport is not a differentiator there.

Publisher

LimaCharlie

Verification

Community-listed (61.5% of the Claude directory)

Filed under

Other

Endpoint

`https://mcp.limacharlie.io/mcp`

Documentation

[Publisher setup docs](https://doc.limacharlie.io/)

Published tools

175 · 51+ tools band

Depth rank in Other

1 of 22

Snapshot

August 2026

LimaCharlie is community-listed in the Claude directory, the tier 770 of 1,253 connectors sit in (61.5%). It is the default for a self-published server, and says nothing either way about quality.

In the publisher's words

## How LimaCharlie describes it

> Automate using the LimaCharlie cybersecurity operation platform, from EDR, XDR, Vulnerability, Cloud Security and more.

Quoted from the connector's own Claude directory listing as captured in August 2026. Node8 did not write it and does not vouch for it.

Nearby

## Other Other connectors

### [TaqMan Assay Search](https://node8.ai/ai-connectors/other/taqman-assay-search/)

Search Thermo Fisher TaqMan assays for gene expression work

ChatGPT

### [Tarteel](https://node8.ai/ai-connectors/other/tarteel/)

Quran text, tafsir, recitation, and prayer times

Claude · ChatGPT

### [Tawadoo: Buy, Sell, Auctions](https://node8.ai/ai-connectors/other/tawadoo-buy-sell-auctions/)

Moroccan classifieds and live auction marketplace

ChatGPT

### [Telgani](https://node8.ai/ai-connectors/other/telgani/)

Car rental offers from Telgani in one call

Claude

### [Tessie](https://node8.ai/ai-connectors/other/tessie/)

Tesla vehicle access and control from chat

ChatGPT

### [The Lonely Door](https://node8.ai/ai-connectors/other/the-lonely-door/)

Scripture responses drawn from a large translation corpus

ChatGPT

[All 351 Other connectors](https://node8.ai/ai-connectors/other/)

This is an independent catalogue entry compiled by Node8 from LimaCharlie's public marketplace listing as it stood in August 2026. Listing facts come from the marketplaces; the comparisons against the rest of the directory and any live-endpoint measurements are Node8's. Node8 is not affiliated with LimaCharlie, and inclusion here is not an endorsement.

## Want your company reachable inside ChatGPT and Claude?

Node8 builds MCP servers end to end: deciding which tools are worth exposing, the authentication and permission model, the review submissions, and the onboarding that gets them used. One server serves ChatGPT, Claude, and Microsoft Copilot.

[See how it works](https://node8.ai/mcp) Book a strategy session
