blender-mcp-integration

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and provides documentation for third-party Blender MCP implementations hosted on GitHub, specifically ahujasid/blender-mcp and sandraschi/blender-mcp. The instructions include transparent warnings regarding the "extra installation, network, credential, and telemetry surface" associated with these community-maintained tools.
  • [REMOTE_CODE_EXECUTION]: The integration layers described in the skill, including the official Blender Lab MCP, support arbitrary Python execution within the Blender environment. The skill acknowledges this capability as a potential risk and advises users to save project states before performing "risky arbitrary-code operations."
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates a workflow that processes data from external 3D asset providers like Poly Haven and Sketchfab. This represents a potential attack surface for indirect prompt injection via asset metadata, though the skill itself focuses on configuration and selection rather than data parsing implementation.
  • [COMMAND_EXECUTION]: The documentation mentions the use of local TCP sockets and stdio for communication between the agent and Blender instances. It provides operational safety advice, such as avoiding port conflicts and using official render tools for validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 05:35 AM
Security Audit — agent-trust-hub — blender-mcp-integration