Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add WYRE-AI/msp-claude-plugins --skill usersgit clone --depth 1 https://github.com/WYRE-AI/msp-claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/wyre-ai/msp-claude-plugins/users)<a href="https://agentmods.dev/skills/wyre-ai/msp-claude-plugins/users"><img src="https://agentmods.dev/badge/skills/wyre-ai/msp-claude-plugins/users.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00033 | $0.00649 |
| Opus 5 | $0.00016 | $0.00324 |
| Sonnet 5 | $0.00007 | $0.00130 |
| Haiku 4.5 | $0.00003 | $0.00065 |
Grade A, and why
Blumira Users scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 90 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Blumira Users
Overview
Blumira users are organization members who can access the portal, investigate findings, and manage the environment. This skill covers user listing and lookup, primarily for finding assignment workflows.
Anti-triggers
- The end user named in a finding — these are Blumira portal
members (your analysts), not the M365 or AD account that triggered a
detection. Look that account up in
cipp-usersorinforcer-identity-governance. - Creating, disabling, or offboarding anyone — Blumira's user
surface is list-only; account lifecycle is
cipp-users. - Users in a managed client account —
blumira_users_listis an/org/*call; useblumira_msp_users_listinblumira-msp.
Key Concepts
User Roles
Users have roles that determine their permissions within the Blumira organization. The API exposes user identity and metadata for assignment and audit purposes.
User IDs
User IDs (UUIDs) are required when assigning findings to specific analysts. Use blumira_users_list to look up IDs.
API Patterns
List Users
blumira_users_list
page_size=50
Response includes user ID, name, email, and role information.
Filter Users
blumira_users_list
[email protected]
Common Workflows
Find User for Assignment
blumira_users_listto get all users- Identify the appropriate analyst by name or role
- Use their
user_idwithblumira_findings_assign
User Access Audit
blumira_users_listwith full pagination- Review all users with access to the organization
- Cross-reference with HR/directory for offboarded users
- Report any discrepancies
Error Handling
Empty User List
Cause: Token may not have permission to list users Solution: Verify JWT token has appropriate scope for user management.
Best Practices
- Cache user lists during triage sessions to avoid repeated API calls
- Use email filtering to quickly find specific users
- For MSP environments, use
blumira_msp_users_listwith account context - Document user-to-role mappings for escalation workflows
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 90 lines · 33 tokens per session scan A 9bd1d2d2a7c1
Blumira Users is a skill published in the GitHub repository WYRE-AI/msp-claude-plugins (44 stars, last pushed 4d ago), licensed Apache-2.0. It adds 33 tokens to every session and 649 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.
Other skills, from other repositories
live-preview
Mid-build visual verification loop. Takes screenshots of components during construction, not just after. Catches visual regressions and invisible features before they compound. Requires Playwright or similar screenshot tool.
review
5-pass structured code review — correctness, security, performance, readability, consistency.
design-copywriting
A copywriting workflow for marketing and product pages that uses a brand voice and returns structured text for page sections.
content-card-news
A planning tool for four-card social media carousels on Instagram, Threads, and Kakao Channel, combining card copy, design guidance, image prompts, captions, and hashtags.
cs-voc-triage
A customer-feedback analysis tool that combines reviews and support contacts from multiple channels. VOC means “voice of the customer”: the comments, questions, complaints, and praise customers leave about a business.
data-realestate
A lookup tool for reported South Korean property transactions using Ministry of Land data. It covers sales and rental deals for apartments, officetels, multi-family homes, houses, and commercial or office properties.