cli-anything-blender

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the cli-anything-blender Python package. This package is managed by the vendor and is central to the skill's functionality.
  • [DYNAMIC_EXECUTION]: The skill generates and executes Blender Python (bpy) scripts at runtime to perform 3D rendering and scene manipulations. This behavior is the primary intended purpose of the tool.
  • [COMMAND_EXECUTION]: The skill executes shell commands to interact with Blender and the cli-anything-blender harness for scene management, project updates, and preview generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes JSON-formatted scene data to generate executable scripts. While this creates a surface for potential injection if the JSON source is untrusted, the risk is inherent to the tool's design as a 3D automation interface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:46 AM
Security Audit — agent-trust-hub — cli-anything-blender