Blumira Users

Blumira Users is a skill for Claude Code from WYRE-AI/msp-claude-plugins. It costs 33 tokens per session (649 once invoked), scanned A, original, Apache-2.0.

A skill for listing and filtering users who belong to a Blumira organisation, a security-monitoring service. It also explains user roles and finds the user IDs needed when assigning security findings.

In plain words
What is it for?
Use it to list portal users, check their roles, filter them, and look up IDs for assigning findings.
Why use it?
It prevents confusion between Blumira portal members and the accounts involved in security detections. It also helps operators identify the correct analyst for an assignment.

Skill for Claude Code

Written for Claude Code: when-to-use in frontmatter.

Part of the blumira plugin — 4 skills, 6 commands, 2 agents shipped together

Good fit Use it to list portal users, check their roles, filter them, and…

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/wyre-ai/msp-claude-plugins/users
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add WYRE-AI/msp-claude-plugins --skill users
Clone the repo
git clone --depth 1 https://github.com/WYRE-AI/msp-claude-plugins

Made for: Claude Code.

Or install blumira, the plugin that ships this one along with the rest of its 4 skills, 6 commands, 2 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for Blumira Users

README.md
[![agentmods](https://agentmods.dev/badge/skills/wyre-ai/msp-claude-plugins/users.svg)](https://agentmods.dev/skills/wyre-ai/msp-claude-plugins/users)
Your own site
<a href="https://agentmods.dev/skills/wyre-ai/msp-claude-plugins/users"><img src="https://agentmods.dev/badge/skills/wyre-ai/msp-claude-plugins/users.svg" alt="Measured on agentmods" height="20"></a>
Per session 33 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 649 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00033 $0.00649
Opus 5 $0.00016 $0.00324
Sonnet 5 $0.00007 $0.00130
Haiku 4.5 $0.00003 $0.00065

Measured 2d ago against content hash 9bd1d2d2a7c1, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

Blumira Users scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

msp-claude-plugins/blumira/blumira/skills/users/SKILL.md · 90 lines

How it starts

The opening of the file, as written. The whole thing — 90 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Blumira Users

Overview

Blumira users are organization members who can access the portal, investigate findings, and manage the environment. This skill covers user listing and lookup, primarily for finding assignment workflows.

Anti-triggers

  • The end user named in a finding — these are Blumira portal members (your analysts), not the M365 or AD account that triggered a detection. Look that account up in cipp-users or inforcer-identity-governance.
  • Creating, disabling, or offboarding anyone — Blumira's user surface is list-only; account lifecycle is cipp-users.
  • Users in a managed client accountblumira_users_list is an /org/* call; use blumira_msp_users_list in blumira-msp.

Key Concepts

User Roles

Users have roles that determine their permissions within the Blumira organization. The API exposes user identity and metadata for assignment and audit purposes.

User IDs

User IDs (UUIDs) are required when assigning findings to specific analysts. Use blumira_users_list to look up IDs.

API Patterns

List Users

blumira_users_list
  page_size=50

Response includes user ID, name, email, and role information.

Filter Users

blumira_users_list
  [email protected]

Common Workflows

Find User for Assignment

  1. blumira_users_list to get all users
  2. Identify the appropriate analyst by name or role
  3. Use their user_id with blumira_findings_assign

User Access Audit

  1. blumira_users_list with full pagination
  2. Review all users with access to the organization
  3. Cross-reference with HR/directory for offboarded users
  4. Report any discrepancies

Error Handling

Empty User List

Cause: Token may not have permission to list users Solution: Verify JWT token has appropriate scope for user management.

Best Practices

  • Cache user lists during triage sessions to avoid repeated API calls
  • Use email filtering to quickly find specific users
  • For MSP environments, use blumira_msp_users_list with account context
  • Document user-to-role mappings for escalation workflows

Read the full file on GitHub · 90 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 90 lines · 33 tokens per session scan A 9bd1d2d2a7c1

Subscribe to this mod's changes

Blumira Users is a skill published in the GitHub repository WYRE-AI/msp-claude-plugins (44 stars, last pushed 4d ago), licensed Apache-2.0. It adds 33 tokens to every session and 649 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.