skills/impertio-studio/blender-bonsai-ifcopenshell-sverchok-claude-skill-package/sverchok-syntax-scripting/Socket
sverchok-syntax-scripting
Warn
Audited by Socket on Jul 23, 2026
1 alert found:
AnomalyAnomalyreferences/methods.md
LOWAnomalyLOW
references/methods.md
No explicit malicious behavior is present in the provided text, but the documentation describes an exec()-based dynamic script loading/execution path and broad injection of high-privilege objects (notably bpy) into the script/formula evaluation environment. In a supply-chain scenario (malicious/poisoned scripts or templates), this would enable arbitrary code execution within the Blender process. The static analysis signal is likely tied to these execution mechanisms rather than visible malware in this snippet.
Confidence: 62%Severity: 65%
Audit Metadata