blender

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill provides the execute_blender_code tool, which allows for the execution of arbitrary Python code within the connected Blender instance using the bpy API.
  • This capability gives the agent full control over the Blender environment and access to the permissions of the underlying Blender process.
  • [COMMAND_EXECUTION]: The skill includes tools suffixed with _for_cli that execute the blender binary in background mode from the system PATH or a specified location.
  • This relies on the presence of a local Blender installation and executes commands via the host system's shell.
  • [EXTERNAL_DOWNLOADS]: The skill instructions specify fetching the MCP server source code from an official Blender project repository.
  • The download targets https://projects.blender.org/lab/blender_mcp and is pinned to a specific Git revision (2cea8d566dde07fbac28a61d698909d69724e853).
  • The process uses uv to manage and install Python dependencies from the network during the initial server startup.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection through the ingestion of untrusted data from Blender scene objects.
  • Ingestion points: Scene data is read into the agent's context through the get_objects_summary tool.
  • Boundary markers: The instructions do not specify explicit delimiters or "ignore" instructions for data retrieved from the scene.
  • Capability inventory: The skill has high-impact capabilities, including arbitrary Python execution via execute_blender_code and command execution via blender --background calls.
  • Sanitization: There is no evidence of sanitization or filtering for names, metadata, or properties retrieved from the Blender scene before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 11:57 AM