blender-mcp

Warn

Audited by Socket on Sep 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Blender-control behavior is coherent with the stated purpose, and the socket data flow is local and proportionate. The main concern is install trust: the skill tells users to curl a raw GitHub addon from a different publisher identity, using an unpinned mutable file instead of the project's safer package-based path.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Sep 13, 2026, 07:35 PM
Package URL
pkg:socket/skills-sh/aston1690%2Fhermes-creative-skills%2Fblender-mcp%2F@1441d977b0da437581d22732853eefd24086ac44f290259b933598ff95a2d023
Security Audit — socket — blender-mcp