blender-mcp
Warn
Audited by Socket on Sep 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core Blender-control behavior is coherent with the stated purpose, and the socket data flow is local and proportionate. The main concern is install trust: the skill tells users to curl a raw GitHub addon from a different publisher identity, using an unpinned mutable file instead of the project's safer package-based path.
Confidence: 90%Severity: 58%
Audit Metadata