name: web-ui-link
description: Generate URLs for the LimaCharlie web application interface. Quickly open the web UI for any feature: dashboard, sensors, detections, D&R rules, FP rules, secrets, outputs, lookups, payloads, YARA rules, artifacts, investigations, extensions, adapters, installation keys, billing, users, playbooks, AI agents, and more. For sensor-specific pages: timeline, console, processes, network, file-system, live-feed. For groups: members, organizations, permissions. Use for "open dashboard", "link to detections", "web UI for sensor", "open D&R rules page", "browser link", "app link", "open in web", "show me URL for", "go to".
allowed-tools:
- Task
- Read
Web UI Link Generator
Generate direct URLs to any page in the LimaCharlie web application at https://app.limacharlie.io.
LimaCharlie Integration
Prerequisites: Run /init-lc to initialize LimaCharlie context.
API Access Pattern
All LimaCharlie API calls go through the limacharlie-api-executor sub-agent:
Task(
subagent_type="lc-essentials:limacharlie-api-executor",
model="haiku",
prompt="Execute LimaCharlie API call:
- Function: <function-name>
- Parameters: {<params>}
- Return: RAW | <extraction instructions>
- Script path: {skill_base_directory}/../../scripts/analyze-lc-result.sh"
)
Critical Rules
| Rule |
Wrong |
Right |
| MCP Access |
Call mcp__* directly |
Use limacharlie-api-executor sub-agent |
| OID |
Use org name |
Use UUID (call list_user_orgs if needed) |
When to Use
Invoke this skill when users:
- Ask for a link to a LimaCharlie feature (e.g., "link to the secrets page", "URL for D&R rules")
- Want to open a specific page (e.g., "open the detections dashboard", "go to sensors")
- Need to navigate to a sensor page (e.g., "show me the timeline for sensor X", "processes for DESKTOP-ABC")
- Ask "where can I..." questions about the web interface (e.g., "where can I configure outputs?")
- Request browser/app links to share with team members
Common trigger phrases:
- "link to...", "URL for...", "open...", "go to...", "navigate to..."
- "where is...", "where can I find...", "how do I access..."
- "browser link", "app link", "web UI"
Base URL
All URLs use the base: https://app.limacharlie.io
URL Reference
Organization Routes (/orgs/{oid}/*)
These routes require an Organization ID (OID).
| Feature |
Path |
Aliases/Keywords |
| Dashboard |
/orgs/{oid}/dashboard |
home, overview, main |
| Sensors |
/orgs/{oid}/sensors |
endpoints, agents, hosts, machines |
| Query Console |
/orgs/{oid}/search |
search, query, lcql, hunt |
| Detections |
/orgs/{oid}/detections |
alerts, findings, incidents |
| D&R Rules |
/orgs/{oid}/dr-rules |
detection rules, d&r, dr rules |
| FP Rules |
/orgs/{oid}/fp-rules |
false positive, fp, suppression |
| Secrets Manager |
/orgs/{oid}/secrets-manager |
secrets, credentials, keys |
| Outputs |
/orgs/{oid}/outputs |
output destinations, siem, destinations |
| Lookups |
/orgs/{oid}/lookups |
lookup tables, reference data, ioc lists |
| Payloads |
/orgs/{oid}/payloads |
payload management |
| YARA Rules |
/orgs/{oid}/yara-rules |
yara, malware rules |
| Artifacts |
/orgs/{oid}/artifacts |
collected artifacts, evidence |
| Investigations |
/orgs/{oid}/investigations |
cases, incidents, timelines |
| Extensions |
/orgs/{oid}/extensions |
add-ons, subscriptions |
| External Adapters |
/orgs/{oid}/external-adapters |
adapters, data ingestion |
| Installation Keys |
/orgs/{oid}/installation-keys |
install keys, deployment keys |
| Install Sensors |
/orgs/{oid}/install-sensors |
sensor installation, deploy sensors |
| Users & Roles |
/orgs/{oid}/users |
users, permissions, access, roles |
| Billing & Usage |
/orgs/{oid}/billing-usage |
billing, usage, quota, costs |
| REST API |
/orgs/{oid}/rest-api |
api keys, api configuration |
| Integrations |
/orgs/{oid}/integrations |
third-party integrations |
| AI Agents |
/orgs/{oid}/ai-agents |
ai, agents |
| Playbooks |
/orgs/{oid}/playbooks |
automation, workflows |
| Management Logs |
/orgs/{oid}/logs/management |
audit logs, management logs |
| YARA Service |
/orgs/{oid}/yara |
yara scanning |
| Exfil Control |
/orgs/{oid}/exfil |
exfiltration, data control |
| Sensor Cull |
/orgs/{oid}/sensor-cull |
cleanup, stale sensors |
| Reliable Tasking |
/orgs/{oid}/reliable-tasking |
offline tasking |
| Vulnerabilities |
/orgs/{oid}/vulnerabilities |
vulns, cve, security issues |
| Artifact Collection |
/orgs/{oid}/artifact-collection |
collection rules |
Sensor Routes (/orgs/{oid}/sensors/{sid}/*)
These routes require both Organization ID (OID) and Sensor ID (SID).
| Feature |
Path |
Aliases/Keywords |
| Sensor Overview |
/orgs/{oid}/sensors/{sid}/overview |
sensor info, sensor details |
| Timeline |
/orgs/{oid}/sensors/{sid}/timeline |
events, event timeline, history |
| Sensor Detections |
/orgs/{oid}/sensors/{sid}/detections |
endpoint alerts |
| Live Console |
/orgs/{oid}/sensors/{sid}/console |
console, terminal, shell, cli |
| Processes |
/orgs/{oid}/sensors/{sid}/processes |
running processes, process list, ps |
| Network |
/orgs/{oid}/sensors/{sid}/network |
connections, netstat, network connections |
| File System |
/orgs/{oid}/sensors/{sid}/file-system |
files, file browser, directories |
| Live Feed |
/orgs/{oid}/sensors/{sid}/live-feed |
live events, real-time |
| Sensor Artifacts |
/orgs/{oid}/sensors/{sid}/artifacts |
endpoint artifacts |
| Event Collection |
/orgs/{oid}/sensors/{sid}/event-collection |
collection rules |
| Sensor Extensions |
/orgs/{oid}/sensors/{sid}/extensions |
endpoint extensions |
| OS Users |
/orgs/{oid}/sensors/{sid}/os-users |
local users, user accounts |
| OS Packages |
/orgs/{oid}/sensors/{sid}/os-packages |
installed packages, software, programs |
| OS Services |
/orgs/{oid}/sensors/{sid}/os-services |
services, windows services, daemons |
| Autoruns |
/orgs/{oid}/sensors/{sid}/os-autoruns |
startup, persistence, autostart |
| Analytics |
/orgs/{oid}/sensors/{sid}/analytics |
sensor analytics |
| File Integrity |
/orgs/{oid}/sensors/{sid}/integrity-rules |
fim, file integrity monitoring |
| Drivers |
/orgs/{oid}/sensors/{sid}/os-drivers |
kernel drivers |
Group Routes (/groups/{group_id}/*)
These routes require a Group ID.
| Feature |
Path |
Aliases/Keywords |
| Group Members |
/groups/{gid}/users |
group users, members, owners |
| Group Organizations |
/groups/{gid}/organizations |
group orgs, member orgs |
| Group Permissions |
/groups/{gid}/permissions |
access control |
| Group Activity |
/groups/{gid}/activity-logs |
group logs, audit |
Global Routes (No OID Required)
| Feature |
Path |
Aliases/Keywords |
| Marketplace |
/add-ons |
add-ons, extensions marketplace |
| User Profile |
/profile |
my profile, account settings |
| Create Organization |
/create-org |
new org, new organization |
How to Use
Step 1: Parse the User Request
Extract from the user's request:
- Target feature: What page they want (sensors, detections, secrets, etc.)
- Organization: Name or OID (if provided)
- Sensor: Hostname or SID (if requesting sensor-specific page)
- Group: Group ID (if requesting group page)
Step 2: Resolve Organization ID
If the user provided an organization name instead of OID, or if no organization was specified:
Task(
subagent_type="lc-essentials:limacharlie-api-executor",
model="haiku",
prompt="Execute LimaCharlie API call:
- Function: list_user_orgs
- Parameters: {}
- Return: List of organizations with their OIDs and names"
)
Handling multiple organizations:
- If user has 1 org: Use it automatically
- If user has multiple orgs and none specified: Ask user to select
- If org name was provided: Match by name (case-insensitive)
Step 3: Resolve Sensor ID (if needed)
If the user requested a sensor-specific URL but provided a hostname instead of SID:
Task(
subagent_type="lc-essentials:limacharlie-api-executor",
model="haiku",
prompt="Execute LimaCharlie API call:
- Function: list_sensors
- Parameters: {\"oid\": \"[oid]\"}
- Return: Find sensor with hostname matching '[hostname]' and return its SID"
)
Step 4: Match Feature to URL Path
Use the reference tables above to match the user's request to the correct URL path. Apply keyword/alias matching for flexibility.
Step 5: Construct and Return URL
Build the complete URL by combining:
- Base URL:
https://app.limacharlie.io
- Path with resolved OID/SID/Group ID
Return the URL in a clickable markdown format:
[Feature Name](https://app.limacharlie.io/orgs/{oid}/feature)
Example Usage
Example 1: Simple Organization Feature
User: "Give me the link to the secrets manager"
Steps:
- Feature identified:
secrets-manager
- No org specified - call
list_user_orgs
- If single org, use its OID; if multiple, ask user to select
- Construct URL
Response:
Here's the link to the Secrets Manager:
[Secrets Manager](https://app.limacharlie.io/orgs/c7e8f940-1234-5678-abcd-1234567890ab/secrets-manager)
Example 2: Sensor-Specific URL
User: "Open the timeline for sensor DESKTOP-PROD01 in the production org"
Steps:
- Feature identified:
timeline (sensor route)
- Org name: "production" - resolve to OID via
list_user_orgs
- Hostname: "DESKTOP-PROD01" - resolve to SID via
list_sensors
- Construct sensor timeline URL
Response:
Here's the timeline for DESKTOP-PROD01:
[Sensor Timeline](https://app.limacharlie.io/orgs/a1b2c3d4-5678-90ab-cdef-1234567890ab/sensors/abc123def456/timeline)
Example 3: Multiple URLs Requested
User: "I need links to detections, D&R rules, and the query console"
Response:
Here are your requested links:
- [Detections](https://app.limacharlie.io/orgs/{oid}/detections)
- [D&R Rules](https://app.limacharlie.io/orgs/{oid}/dr-rules)
- [Query Console](https://app.limacharlie.io/orgs/{oid}/search)
Example 4: Ambiguous Request
User: "Link to the rules page"
Response:
There are several types of rules in LimaCharlie. Which one would you like?
1. **D&R Rules** - Detection & Response rules
https://app.limacharlie.io/orgs/{oid}/dr-rules
2. **FP Rules** - False Positive suppression rules
https://app.limacharlie.io/orgs/{oid}/fp-rules
3. **YARA Rules** - Malware detection rules
https://app.limacharlie.io/orgs/{oid}/yara-rules
4. **Artifact Collection Rules** - Data collection rules
https://app.limacharlie.io/orgs/{oid}/artifact-collection
Example 5: Unknown Feature with Suggestions
User: "Link to the threat intel page"
Response:
LimaCharlie doesn't have a dedicated "threat intel" page, but here are related features:
- **Lookups** - Store and query IOC lists, threat intel feeds
https://app.limacharlie.io/orgs/{oid}/lookups
- **D&R Rules** - Create detection rules based on threat intel
https://app.limacharlie.io/orgs/{oid}/dr-rules
- **Query Console** - Hunt for IOCs using LCQL
https://app.limacharlie.io/orgs/{oid}/search
Would you like a link to one of these?
Error Handling
Organization Not Found
Organization "acme-corp" not found. Your available organizations:
- production (a1b2c3d4-5678-...)
- staging (e5f6g7h8-9012-...)
- dev (i9j0k1l2-3456-...)
Please specify which organization you'd like.
Sensor Not Found
No sensor found with hostname "UNKNOWN-HOST" in organization "production".
Would you like me to:
1. List all sensors in this organization
2. Search for sensors with a similar hostname
Missing Required Information
The sensor timeline page requires a sensor ID.
Please provide either:
- A sensor SID (e.g., "abc123def456...")
- OR a hostname (e.g., "DESKTOP-PROD01")
I can also list sensors in your organization if you need to find one.
Notes
- OID Format: Organization IDs are UUIDs (e.g.,
c7e8f940-1234-5678-abcd-1234567890ab)
- SID Format: Sensor IDs are also UUIDs
- Case Sensitivity: Feature matching is case-insensitive
- Multiple Matches: When a request could match multiple features, present all options
- Global Routes: Some pages (marketplace, profile) don't require an organization context
Related Skills
limacharlie-call - For actually interacting with LimaCharlie APIs
lookup-lc-doc - For documentation about LimaCharlie features
sensor-health - For checking sensor status before linking to sensor pages
1---2name: web-ui-link-23description: Generate URLs for the LimaCharlie web application interface. Quickly open the web UI for any feature: dashboard, sensors, detections, D&R rules, FP rules, secrets, outputs, lookups, payloads, YARA rul4---56---7name: web-ui-link8description: Generate URLs for the LimaCharlie web application interface. Quickly open the web UI for any feature: dashboard, sensors, detections, D&R rules, FP rules, secrets, outputs, lookups, payloads, YARA rules, artifacts, investigations, extensions, adapters, installation keys, billing, users, playbooks, AI agents, and more. For sensor-specific pages: timeline, console, processes, network, file-system, live-feed. For groups: members, organizations, permissions. Use for "open dashboard", "link to detections", "web UI for sensor", "open D&R rules page", "browser link", "app link", "open in web", "show me URL for", "go to".9allowed-tools:10 - Task11 - Read12---1314# Web UI Link Generator1516Generate direct URLs to any page in the LimaCharlie web application at `https://app.limacharlie.io`.1718---1920## LimaCharlie Integration2122> **Prerequisites**: Run `/init-lc` to initialize LimaCharlie context.2324### API Access Pattern2526All LimaCharlie API calls go through the `limacharlie-api-executor` sub-agent:2728```29Task(30 subagent_type="lc-essentials:limacharlie-api-executor",31 model="haiku",32 prompt="Execute LimaCharlie API call:33 - Function: <function-name>34 - Parameters: {<params>}35 - Return: RAW | <extraction instructions>36 - Script path: {skill_base_directory}/../../scripts/analyze-lc-result.sh"37)38```3940### Critical Rules4142| Rule | Wrong | Right |43|------|-------|-------|44| **MCP Access** | Call `mcp__*` directly | Use `limacharlie-api-executor` sub-agent |45| **OID** | Use org name | Use UUID (call `list_user_orgs` if needed) |4647---4849## When to Use5051Invoke this skill when users:5253- Ask for a **link to a LimaCharlie feature** (e.g., "link to the secrets page", "URL for D&R rules")54- Want to **open a specific page** (e.g., "open the detections dashboard", "go to sensors")55- Need to **navigate to a sensor page** (e.g., "show me the timeline for sensor X", "processes for DESKTOP-ABC")56- Ask **"where can I..."** questions about the web interface (e.g., "where can I configure outputs?")57- Request **browser/app links** to share with team members5859Common trigger phrases:60- "link to...", "URL for...", "open...", "go to...", "navigate to..."61- "where is...", "where can I find...", "how do I access..."62- "browser link", "app link", "web UI"6364## Base URL6566All URLs use the base: `https://app.limacharlie.io`6768## URL Reference6970### Organization Routes (`/orgs/{oid}/*`)7172These routes require an Organization ID (OID).7374| Feature | Path | Aliases/Keywords |75|---------|------|------------------|76| Dashboard | `/orgs/{oid}/dashboard` | home, overview, main |77| Sensors | `/orgs/{oid}/sensors` | endpoints, agents, hosts, machines |78| Query Console | `/orgs/{oid}/search` | search, query, lcql, hunt |79| Detections | `/orgs/{oid}/detections` | alerts, findings, incidents |80| D&R Rules | `/orgs/{oid}/dr-rules` | detection rules, d&r, dr rules |81| FP Rules | `/orgs/{oid}/fp-rules` | false positive, fp, suppression |82| Secrets Manager | `/orgs/{oid}/secrets-manager` | secrets, credentials, keys |83| Outputs | `/orgs/{oid}/outputs` | output destinations, siem, destinations |84| Lookups | `/orgs/{oid}/lookups` | lookup tables, reference data, ioc lists |85| Payloads | `/orgs/{oid}/payloads` | payload management |86| YARA Rules | `/orgs/{oid}/yara-rules` | yara, malware rules |87| Artifacts | `/orgs/{oid}/artifacts` | collected artifacts, evidence |88| Investigations | `/orgs/{oid}/investigations` | cases, incidents, timelines |89| Extensions | `/orgs/{oid}/extensions` | add-ons, subscriptions |90| External Adapters | `/orgs/{oid}/external-adapters` | adapters, data ingestion |91| Installation Keys | `/orgs/{oid}/installation-keys` | install keys, deployment keys |92| Install Sensors | `/orgs/{oid}/install-sensors` | sensor installation, deploy sensors |93| Users & Roles | `/orgs/{oid}/users` | users, permissions, access, roles |94| Billing & Usage | `/orgs/{oid}/billing-usage` | billing, usage, quota, costs |95| REST API | `/orgs/{oid}/rest-api` | api keys, api configuration |96| Integrations | `/orgs/{oid}/integrations` | third-party integrations |97| AI Agents | `/orgs/{oid}/ai-agents` | ai, agents |98| Playbooks | `/orgs/{oid}/playbooks` | automation, workflows |99| Management Logs | `/orgs/{oid}/logs/management` | audit logs, management logs |100| YARA Service | `/orgs/{oid}/yara` | yara scanning |101| Exfil Control | `/orgs/{oid}/exfil` | exfiltration, data control |102| Sensor Cull | `/orgs/{oid}/sensor-cull` | cleanup, stale sensors |103| Reliable Tasking | `/orgs/{oid}/reliable-tasking` | offline tasking |104| Vulnerabilities | `/orgs/{oid}/vulnerabilities` | vulns, cve, security issues |105| Artifact Collection | `/orgs/{oid}/artifact-collection` | collection rules |106107### Sensor Routes (`/orgs/{oid}/sensors/{sid}/*`)108109These routes require both Organization ID (OID) and Sensor ID (SID).110111| Feature | Path | Aliases/Keywords |112|---------|------|------------------|113| Sensor Overview | `/orgs/{oid}/sensors/{sid}/overview` | sensor info, sensor details |114| Timeline | `/orgs/{oid}/sensors/{sid}/timeline` | events, event timeline, history |115| Sensor Detections | `/orgs/{oid}/sensors/{sid}/detections` | endpoint alerts |116| Live Console | `/orgs/{oid}/sensors/{sid}/console` | console, terminal, shell, cli |117| Processes | `/orgs/{oid}/sensors/{sid}/processes` | running processes, process list, ps |118| Network | `/orgs/{oid}/sensors/{sid}/network` | connections, netstat, network connections |119| File System | `/orgs/{oid}/sensors/{sid}/file-system` | files, file browser, directories |120| Live Feed | `/orgs/{oid}/sensors/{sid}/live-feed` | live events, real-time |121| Sensor Artifacts | `/orgs/{oid}/sensors/{sid}/artifacts` | endpoint artifacts |122| Event Collection | `/orgs/{oid}/sensors/{sid}/event-collection` | collection rules |123| Sensor Extensions | `/orgs/{oid}/sensors/{sid}/extensions` | endpoint extensions |124| OS Users | `/orgs/{oid}/sensors/{sid}/os-users` | local users, user accounts |125| OS Packages | `/orgs/{oid}/sensors/{sid}/os-packages` | installed packages, software, programs |126| OS Services | `/orgs/{oid}/sensors/{sid}/os-services` | services, windows services, daemons |127| Autoruns | `/orgs/{oid}/sensors/{sid}/os-autoruns` | startup, persistence, autostart |128| Analytics | `/orgs/{oid}/sensors/{sid}/analytics` | sensor analytics |129| File Integrity | `/orgs/{oid}/sensors/{sid}/integrity-rules` | fim, file integrity monitoring |130| Drivers | `/orgs/{oid}/sensors/{sid}/os-drivers` | kernel drivers |131132### Group Routes (`/groups/{group_id}/*`)133134These routes require a Group ID.135136| Feature | Path | Aliases/Keywords |137|---------|------|------------------|138| Group Members | `/groups/{gid}/users` | group users, members, owners |139| Group Organizations | `/groups/{gid}/organizations` | group orgs, member orgs |140| Group Permissions | `/groups/{gid}/permissions` | access control |141| Group Activity | `/groups/{gid}/activity-logs` | group logs, audit |142143### Global Routes (No OID Required)144145| Feature | Path | Aliases/Keywords |146|---------|------|------------------|147| Marketplace | `/add-ons` | add-ons, extensions marketplace |148| User Profile | `/profile` | my profile, account settings |149| Create Organization | `/create-org` | new org, new organization |150151## How to Use152153### Step 1: Parse the User Request154155Extract from the user's request:156- **Target feature**: What page they want (sensors, detections, secrets, etc.)157- **Organization**: Name or OID (if provided)158- **Sensor**: Hostname or SID (if requesting sensor-specific page)159- **Group**: Group ID (if requesting group page)160161### Step 2: Resolve Organization ID162163If the user provided an organization **name** instead of OID, or if no organization was specified:164165```166Task(167 subagent_type="lc-essentials:limacharlie-api-executor",168 model="haiku",169 prompt="Execute LimaCharlie API call:170 - Function: list_user_orgs171 - Parameters: {}172 - Return: List of organizations with their OIDs and names"173)174```175176**Handling multiple organizations:**177- If user has **1 org**: Use it automatically178- If user has **multiple orgs** and none specified: Ask user to select179- If org name was provided: Match by name (case-insensitive)180181### Step 3: Resolve Sensor ID (if needed)182183If the user requested a sensor-specific URL but provided a **hostname** instead of SID:184185```186Task(187 subagent_type="lc-essentials:limacharlie-api-executor",188 model="haiku",189 prompt="Execute LimaCharlie API call:190 - Function: list_sensors191 - Parameters: {\"oid\": \"[oid]\"}192 - Return: Find sensor with hostname matching '[hostname]' and return its SID"193)194```195196### Step 4: Match Feature to URL Path197198Use the reference tables above to match the user's request to the correct URL path. Apply keyword/alias matching for flexibility.199200### Step 5: Construct and Return URL201202Build the complete URL by combining:203- Base URL: `https://app.limacharlie.io`204- Path with resolved OID/SID/Group ID205206Return the URL in a clickable markdown format:207```208[Feature Name](https://app.limacharlie.io/orgs/{oid}/feature)209```210211## Example Usage212213### Example 1: Simple Organization Feature214215**User**: "Give me the link to the secrets manager"216217**Steps**:2181. Feature identified: `secrets-manager`2192. No org specified - call `list_user_orgs`2203. If single org, use its OID; if multiple, ask user to select2214. Construct URL222223**Response**:224```225Here's the link to the Secrets Manager:226227[Secrets Manager](https://app.limacharlie.io/orgs/c7e8f940-1234-5678-abcd-1234567890ab/secrets-manager)228```229230### Example 2: Sensor-Specific URL231232**User**: "Open the timeline for sensor DESKTOP-PROD01 in the production org"233234**Steps**:2351. Feature identified: `timeline` (sensor route)2362. Org name: "production" - resolve to OID via `list_user_orgs`2373. Hostname: "DESKTOP-PROD01" - resolve to SID via `list_sensors`2384. Construct sensor timeline URL239240**Response**:241```242Here's the timeline for DESKTOP-PROD01:243244[Sensor Timeline](https://app.limacharlie.io/orgs/a1b2c3d4-5678-90ab-cdef-1234567890ab/sensors/abc123def456/timeline)245```246247### Example 3: Multiple URLs Requested248249**User**: "I need links to detections, D&R rules, and the query console"250251**Response**:252```253Here are your requested links:254255- [Detections](https://app.limacharlie.io/orgs/{oid}/detections)256- [D&R Rules](https://app.limacharlie.io/orgs/{oid}/dr-rules)257- [Query Console](https://app.limacharlie.io/orgs/{oid}/search)258```259260### Example 4: Ambiguous Request261262**User**: "Link to the rules page"263264**Response**:265```266There are several types of rules in LimaCharlie. Which one would you like?2672681. **D&R Rules** - Detection & Response rules269 https://app.limacharlie.io/orgs/{oid}/dr-rules2702712. **FP Rules** - False Positive suppression rules272 https://app.limacharlie.io/orgs/{oid}/fp-rules2732743. **YARA Rules** - Malware detection rules275 https://app.limacharlie.io/orgs/{oid}/yara-rules2762774. **Artifact Collection Rules** - Data collection rules278 https://app.limacharlie.io/orgs/{oid}/artifact-collection279```280281### Example 5: Unknown Feature with Suggestions282283**User**: "Link to the threat intel page"284285**Response**:286```287LimaCharlie doesn't have a dedicated "threat intel" page, but here are related features:288289- **Lookups** - Store and query IOC lists, threat intel feeds290 https://app.limacharlie.io/orgs/{oid}/lookups291292- **D&R Rules** - Create detection rules based on threat intel293 https://app.limacharlie.io/orgs/{oid}/dr-rules294295- **Query Console** - Hunt for IOCs using LCQL296 https://app.limacharlie.io/orgs/{oid}/search297298Would you like a link to one of these?299```300301## Error Handling302303### Organization Not Found304```305Organization "acme-corp" not found. Your available organizations:306307- production (a1b2c3d4-5678-...)308- staging (e5f6g7h8-9012-...)309- dev (i9j0k1l2-3456-...)310311Please specify which organization you'd like.312```313314### Sensor Not Found315```316No sensor found with hostname "UNKNOWN-HOST" in organization "production".317318Would you like me to:3191. List all sensors in this organization3202. Search for sensors with a similar hostname321```322323### Missing Required Information324```325The sensor timeline page requires a sensor ID.326327Please provide either:328- A sensor SID (e.g., "abc123def456...")329- OR a hostname (e.g., "DESKTOP-PROD01")330331I can also list sensors in your organization if you need to find one.332```333334## Notes335336- **OID Format**: Organization IDs are UUIDs (e.g., `c7e8f940-1234-5678-abcd-1234567890ab`)337- **SID Format**: Sensor IDs are also UUIDs338- **Case Sensitivity**: Feature matching is case-insensitive339- **Multiple Matches**: When a request could match multiple features, present all options340- **Global Routes**: Some pages (marketplace, profile) don't require an organization context341342## Related Skills343344- `limacharlie-call` - For actually interacting with LimaCharlie APIs345- `lookup-lc-doc` - For documentation about LimaCharlie features346- `sensor-health` - For checking sensor status before linking to sensor pages