Command Line Interface¶
The limacharlie cloudsec command group (Python SDK/CLI v2) covers most of
the Cloud Security API surface: the posture and inventory reads, findings
triage, graph queries, policy previews, CSV exports, and the fleet roll-up.
Commands take the global options (--oid,
--output json|yaml|toon|csv|table|jsonl, --filter <jmespath>,
--fields <names>), and every command and subgroup answers --ai-help with
task-oriented guidance. The export subgroup is the one exception: it writes
a server-rendered CSV straight through, so the output, filter, and field
options do not apply to it.
Configuration (providers, policies, saved queries, code rules) is managed with the
standard limacharlie hive commands — see
Configuration; this group is the query and triage
surface.
Install the CLI
Install or upgrade the LimaCharlie CLI:
Installing the CLI does not enable a server capability. Hosted scanning
and advanced evidence features depend on availability in your organization's
data region. Check Code security → Overview, code capabilities and
code status; if you see code_lane_not_enabled_in_datacenter, contact
LimaCharlie before completing hosted-scan setup.
For Code Security (repositories, SBOMs, AutoFix, local scans and pushed results), see Code Security and Bring your own scanner.
At a glance¶
# Posture
limacharlie cloudsec overview --trend-days 90
limacharlie cloudsec changes --limit 100
limacharlie cloudsec risk-trend
limacharlie cloudsec scan-status --provider gcp
limacharlie cloudsec topology
# Findings worklist + triage
limacharlie cloudsec finding list --severity CRITICAL --class toxic_combination --kev
limacharlie cloudsec finding list --sla breached --sort due_at # what is late
limacharlie cloudsec finding facets --status open
limacharlie cloudsec finding classes # the finding_class enum
limacharlie cloudsec finding get fnd_0a1b...
limacharlie cloudsec finding resolve fnd_0a1b... --kind mitigated --reason "SG tightened"
limacharlie cloudsec finding resolve fnd_0a1b... --kind open # reopen
limacharlie cloudsec finding bulk-resolve --finding-id fnd_a --finding-id fnd_b --kind accepted
limacharlie cloudsec finding set-owner fnd_0a1b... --owner alice@acme.com
limacharlie cloudsec finding set-ticket fnd_0a1b... --ticket JIRA-1234
# Attack paths, chokepoints
limacharlie cloudsec attack-path list --severity CRITICAL
limacharlie cloudsec chokepoint list
limacharlie cloudsec chokepoint dismiss "lcrn:..." --reason "bastion by design"
limacharlie cloudsec chokepoint restore "lcrn:..."
# Identity & data
limacharlie cloudsec ciem public-access
limacharlie cloudsec ciem facets
limacharlie cloudsec ciem identity "lcrn:..." # Identity 360
limacharlie cloudsec data-security facets
# Inventory & graph
limacharlie cloudsec inventory list --type <resource-type> --provider gcp -q prod --limit 50
limacharlie cloudsec inventory list --all-accounts --limit 50 # drop per-account scoping
limacharlie cloudsec inventory facets
limacharlie cloudsec resource get "lcrn:..."
limacharlie cloudsec graph neighbors "lcrn:..." --limit 200
limacharlie cloudsec query list
limacharlie cloudsec query run --named public_data_stores
limacharlie cloudsec query run --text 'MATCH (d:DataStore {is_sensitive: true})<-[:has_permission_on]-(i:Identity {is_external: true}) RETURN i, d'
# Compliance
limacharlie cloudsec compliance report --framework cis-gcp
limacharlie cloudsec compliance report --assignment prod-cis
limacharlie cloudsec compliance frameworks
limacharlie cloudsec compliance assignments
# Sensors <-> cloud assets
limacharlie cloudsec resolve sensors $SID1 $SID2
limacharlie cloudsec resolve assets "lcrn:..."
# CAASM
limacharlie cloudsec caasm assets -q laptop
limacharlie cloudsec caasm coverage --status open --sort lc_risk --order desc
limacharlie cloudsec caasm policy get
limacharlie cloudsec caasm policy set --input-file coverage.json
limacharlie cloudsec caasm ingest --source okta --records-file users.json
# Provider preflight + coverage manifest
limacharlie cloudsec provider test --input-file provider.json
limacharlie cloudsec provider manifest --type gcp # "what you get" for a provider
# Code Security
limacharlie cloudsec code repos --with-findings --all
limacharlie cloudsec code status
limacharlie cloudsec code fixes
limacharlie cloudsec code capabilities
limacharlie cloudsec code sbom --repo acme/api -o api-sbom.json.gz
limacharlie cloudsec code rescan acme/api
limacharlie cloudsec code autofix fnd_...
limacharlie cloudsec code scan . --repo acme/api --ingest
limacharlie cloudsec code ingest --repo acme/api --source sarif --file results.sarif
# Policy authoring aids + read-only matcher previews
limacharlie cloudsec policy vocabulary
limacharlie cloudsec policy suggest --dimension name -q prod --limit 10
limacharlie cloudsec simulate resources --input-file rules.yaml --target data_store
limacharlie cloudsec simulate resources --rules-json '[{"name_glob":"prod-*"}]' --resource-type gcp_bucket
limacharlie cloudsec simulate findings --match-json '{"finding_class":"misconfig","max_severity":"LOW"}'
# Full-set CSV export (server-side walk of the entire filtered set)
limacharlie cloudsec export findings -o findings.csv
limacharlie cloudsec export inventory -o inventory.csv
limacharlie cloudsec export compliance --framework cis-gcp -o compliance.csv
limacharlie cloudsec export query --named public_data_stores -o data-stores.csv
# Fleet — cross-tenant (MSSP) roll-up, no single --oid
limacharlie cloudsec fleet overview --oid $OID1 --oid $OID2 --trend-days 30
limacharlie cloudsec fleet overview --group <GROUP_ID> --limit 100
The export subgroup streams the entire filtered set as a CSV
(server-side keyset walk, capped at 100,000 rows) — use it for offline
analysis. It is distinct from the per-page --output csv, which serializes
only the current page of a normal list command. export findings,
export inventory, and export compliance take the same filters as their
finding list / inventory list / compliance report counterparts;
export query takes the same --named / --text / --query-json
selectors as query run.
fleet overview is the multi-org board for MSSPs: pass --oid repeatedly,
or --group <GROUP_ID> — the opaque id of an org group you own or belong to,
not its display name — to roll risk posture up across tenants. Given neither,
it spans every organization your credentials can see. It carries
--trend-days, --limit, and --cursor for paging the tenant list, and is
the one command that does not resolve a single --oid.
What lives outside this command group
The shared-fix cause rollup, the filtered identity list and the paginated
data-store list are finding causes, ciem identities and
data-security stores. For any route without a command, use the generic
limacharlie api <path> escape hatch — see the
API Reference.
Some things that look like missing commands are really something else.
Scheduled queries are not a separate feature: a scheduled query is a
cloudsec_query Hive record carrying a schedule block, authored with
limacharlie hive set --hive-name cloudsec_query (see
Configuration). Custom posture rules
and remediation SLAs are likewise cloudsec_policy Hive records
(policy_type rules and sla) written with
limacharlie hive set --hive-name cloudsec_policy — see
Custom Posture Rules and
Remediation SLAs. Workload groups
are not a view of their own either: they arrive on findings as
source_scope / target_scope in finding list, and as the
ComputeGroup node type in graph queries.
Filtering and pagination¶
finding list carries the full vocabulary — repeatable filters (OR within a
key, AND across keys), free-text search, sorting, and keyset pagination:
limacharlie cloudsec finding list \
--severity CRITICAL --severity HIGH \
--status open -q payment \
--sort lc_risk --order desc \
--limit 50
# ...then pass the returned next_cursor back:
limacharlie cloudsec finding list \
--severity CRITICAL --severity HIGH \
--status open -q payment \
--sort lc_risk --order desc \
--cursor "<next_cursor>" --limit 50
Boolean tri-state flags (--kev/--no-kev, --reachable/--no-reachable)
send the filter only when given, so the server default applies otherwise.
--sla selects on the derived remediation-SLA
state — breached, due_soon,
on_track, exempt, none — and is repeatable like the other filters. It
applies to finding list, finding facets, finding causes, and
export findings. --sort due_at is the matching sort key, and the one key
that defaults to ascending (soonest deadline first), keeping findings with
no due date last rather than dropping them.
The other lists carry a subset, so check --help before assuming a flag is
there. caasm coverage behaves like finding list (repeatable filters,
--sort/--order, paging). caasm assets supports paging and --sort urn or --sort last_seen.
inventory list pages without sorting, and inventory's --type / --provider / --account / --region
each take a single value rather than repeating. attack-path list returns
the headline set in one shot: repeatable filters and -q, but no sorting and
no paging.
Records, files, and stdin¶
The commands that take a record — provider test, caasm policy set, and
both simulate commands — accept it three ways: --input-file (JSON or
YAML), an inline-JSON flag (--provider-json, --policy-json,
--rules-json, --match-json), or piped on stdin:
cat provider.yaml | limacharlie cloudsec provider test
limacharlie cloudsec caasm policy set --policy-json '{"expect":[...]}'
caasm ingest has its own pair: --records-file for a JSON or YAML array of
vendor records, --record-json for a single inline record.
Both simulate commands take --sample-limit (default 25, cap 100) to size
the returned sample, and simulate resources takes a repeatable
--resource-type to narrow the walked types the way an exclusions rule does.
policy suggest takes --limit (default 20, cap 50).
Additional selectors¶
These selectors are available in the CLI. Check each command's --help for
usage; the corresponding REST selectors are in the API reference.
| Command | Additional selectors |
|---|---|
cloudsec image list |
Repeatable --lineage-status (verified, asserted, inferred, ambiguous, unknown). Stale lineage counts as unknown. |
cloudsec image repo-facets |
--lineage-facet adds digest-level lineage counts; these counts are separate from registry placement counts. |
cloudsec caasm assets |
Repeatable --kind, --source, --encryption, --screen-lock, --compromised, --managed, plus --sort urn or --sort last_seen. For a posture dimension, an empty value selects unreported state. |
cloudsec export findings, cloudsec export inventory |
--max-rows bounds a CSV chunk; --cursor resumes it. A trailing # next_cursor=... comment carries the continuation token when more rows remain. Keep all selectors unchanged when resuming. |
cloudsec provider m365-certificate |
Generates and stores an Entra connection key pair and returns only its public certificate. See certificate setup. |
A CSV reader should skip # comment lines before treating the file as a table.
Check for the continuation token before considering a bounded export complete.
Scripting¶
The SDK class behind the CLI is available directly:
from limacharlie.client import Client
from limacharlie.sdk.organization import Organization
from limacharlie.sdk.cloudsec import CloudSec
client = Client(oid="YOUR_OID", api_key="YOUR_API_KEY")
cs = CloudSec(Organization(client))
# Keep the filters identical when requesting each subsequent page.
cursor = None
while True:
page = cs.list_findings(severity=["CRITICAL"], kev=True, limit=100, cursor=cursor)
for finding in page.get("findings", []):
print(finding["lc_risk"], finding["title"], finding["resource_urn"])
cursor = page.get("next_cursor")
if not cursor:
break
Each method mirrors one API route and returns the raw response dict; see the API Reference for response shapes.