blender-mcp

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The execute_blender_code tool allows the AI to run arbitrary Python scripts directly within the user's running Blender session. While documented as the core product feature, this provides a direct path for code execution on the local machine. The skill offers a 'safe mode' mitigation (BLENDER_MCP_SAFE_MODE=1) that uses an AST allowlist to block dangerous modules like os, subprocess, and socket, though this is opt-in and not a full sandbox.
  • [DATA_EXFILTRATION]: The integrated MCP server has telemetry enabled by default, capturing prompts, generated code, scene metadata, viewport screenshots, and manual edits made by the user in Blender. The terms of service allow this data to be stored indefinitely and used for AI training or released in public datasets. The skill provides clear instructions on how to disable this collection for confidential or NDA-protected work.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted third-party metadata, including asset titles and descriptions from services like Poly Haven and Sketchfab. This content is passed to the AI model and could contain malicious instructions designed to trick the agent into generating harmful code.
  • Ingestion points: Asset titles, descriptions, and tags retrieved via tools in references/assets-and-generation.md.
  • Boundary markers: None present in the instructions to delimit untrusted asset data.
  • Capability inventory: execute_blender_code (arbitrary code execution) and export_scene (filesystem write) as detailed in SKILL.md.
  • Sanitization: Optional AST-based validation provided via BLENDER_MCP_SAFE_MODE=1 as described in references/safety-and-privacy.md.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the blender-mcp package from PyPI using uvx and provides tools to automatically write an addon file into the user's local Blender installation directories.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:13 AM
Security Audit — agent-trust-hub — blender-mcp