blender-community-skill-bootstrap

Warn

Audited by Socket on Aug 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches the behavior, but the core action is transitive installation of third-party skills from a personal GitHub repository. Using official OpenAI installer/validator helpers and a pinned commit improves hygiene, yet the imported skill content remains externally sourced and effectively unreviewed, so overall risk is medium-high even without direct credential theft or malware indicators.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Aug 22, 2026, 06:06 PM
Package URL
pkg:socket/skills-sh/nvidia-omniverse%2Fomniverse-labs%2Fblender-community-skill-bootstrap%2F@c0537e4ab19fb3cbbadf67d773fb001c4ed3e24f70c4c615201488159c8f6436
Security Audit — socket — blender-community-skill-bootstrap