blender-threejs-export

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/blender-threejs-export.js

This module is a local exporter/viewer generator that implements a high-impact 'execute_code' socket RPC to a Blender service and uses user-controlled values to construct both the export filepath and the generated HTML. There is no clear evidence of overt malware (no exfiltration/credential theft shown), but the design is security-sensitive: a compromised/malicious Blender service or untrusted CLI inputs could lead to arbitrary code execution in the Blender context and potential HTML/JS injection in the produced viewer artifact. Treat as a trusted-tool-only component and add strict validation/escaping and a safer RPC protocol if used in untrusted environments.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 11:51 PM
Package URL
pkg:socket/skills-sh/kevinbadi%2Fblender-skills%2Fblender-threejs-export%2F@240ff2b169af5f3dee197acbefffa47ddb1961b4426ca8207e5badf7aa169be7
Security Audit — socket — blender-threejs-export