blender
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill provides the
execute_blender_codetool, which allows for the execution of arbitrary Python code within the connected Blender instance using thebpyAPI. - This capability gives the agent full control over the Blender environment and access to the permissions of the underlying Blender process.
- [COMMAND_EXECUTION]: The skill includes tools suffixed with
_for_clithat execute theblenderbinary in background mode from the systemPATHor a specified location. - This relies on the presence of a local Blender installation and executes commands via the host system's shell.
- [EXTERNAL_DOWNLOADS]: The skill instructions specify fetching the MCP server source code from an official Blender project repository.
- The download targets
https://projects.blender.org/lab/blender_mcpand is pinned to a specific Git revision (2cea8d566dde07fbac28a61d698909d69724e853). - The process uses
uvto manage and install Python dependencies from the network during the initial server startup. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection through the ingestion of untrusted data from Blender scene objects.
- Ingestion points: Scene data is read into the agent's context through the
get_objects_summarytool. - Boundary markers: The instructions do not specify explicit delimiters or "ignore" instructions for data retrieved from the scene.
- Capability inventory: The skill has high-impact capabilities, including arbitrary Python execution via
execute_blender_codeand command execution viablender --backgroundcalls. - Sanitization: There is no evidence of sanitization or filtering for names, metadata, or properties retrieved from the Blender scene before they are processed by the agent.
Audit Metadata