Cross-account Blumira findings, detections, and agents in one offline-searchable store.
BLUMIRA_API_TOKENAPI keyoptionalPre-minted Blumira JWT. An alternative to BLUMIRA_CLIENT_ID + BLUMIRA_CLIENT_SECRET: set this OR the Client ID/Secret pair.
BLUMIRA_CLIENT_IDOAuth appoptionalBlumira API Client ID (Settings > Organization > Generate API Credentials). With BLUMIRA_CLIENT_SECRET, the server mints and auto-refreshes a JWT.
BLUMIRA_CLIENT_SECRETOAuth appoptionalBlumira API Client Secret, paired with BLUMIRA_CLIENT_ID to mint a JWT (OAuth2 client_credentials, audience public-api).
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge has no scan on record for this entry, so it holds no observation of its tool surface. That is an absence of evidence, not evidence that it exposes no tools.
Cross-account Blumira findings, detections, and agents in one offline-searchable store.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.