io.github.Servosity/blumira-mcp

MCPcommunity
v0.1.1io.github.ServosityUnknownUpdated todayGitHub

Cross-account Blumira findings, detections, and agents in one offline-searchable store.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
todayLast update
Reads these credentials
  • BLUMIRA_API_TOKENAPI keyoptional

    Pre-minted Blumira JWT. An alternative to BLUMIRA_CLIENT_ID + BLUMIRA_CLIENT_SECRET: set this OR the Client ID/Secret pair.

  • BLUMIRA_CLIENT_IDOAuth appoptional

    Blumira API Client ID (Settings > Organization > Generate API Credentials). With BLUMIRA_CLIENT_SECRET, the server mints and auto-refreshes a JWT.

  • BLUMIRA_CLIENT_SECRETOAuth appoptional

    Blumira API Client Secret, paired with BLUMIRA_CLIENT_ID to mint a JWT (OAuth2 client_credentials, audience public-api).

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
Authorio.github.Servosity
LicenseUnknown
Version0.1.1
Sourcemcp-registry
Trust Status
F
10/100Untrusted
Listed in Forge index+10/10
Publisher identity verified+0/30
Publisher: run `forge publish` from the repo to claim ownership
Domain verification+0/10
Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
Prompt-injection scan · not run+0/30
Not yet scanned — the repository archive is scanned on the next cron run
Obfuscation / exfil scan · not run+0/20
Not yet scanned — the repository archive is scanned on the next cron run
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain
Provenance
DependenciesNot audited
Tool surface
Security scanNot runHow well does this scan work?
EvalsNone
IndexedAug 26, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

Not scanned yet

Forge has no scan on record for this entry, so it holds no observation of its tool surface. That is an absence of evidence, not evidence that it exposes no tools.

About

Cross-account Blumira findings, detections, and agents in one offline-searchable store.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.