blender-community-skill-bootstrap
Warn
Audited by Socket on Aug 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches the behavior, but the core action is transitive installation of third-party skills from a personal GitHub repository. Using official OpenAI installer/validator helpers and a pinned commit improves hygiene, yet the imported skill content remains externally sourced and effectively unreviewed, so overall risk is medium-high even without direct credential theft or malware indicators.
Confidence: 89%Severity: 76%
Audit Metadata