blender-mcp-skills

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall purpose and capabilities are mostly coherent for a Blender MCP development skill, and there is no clear credential theft or exfiltration behavior. The main concern is install/execution trust: the skill depends on an unverified external `blender-mcp` toolchain and references a non-official raw GitHub setup guide, so this is best classified as suspicious but not malicious.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
May 13, 2026, 03:39 PM
Package URL
pkg:socket/skills-sh/psiQAQ%2Fblender_mcp-setup-guide%2Fblender-mcp-skills%2F@c5c222a37eba036637b35fd27d4e5c8afeab01f7
Security Audit — socket — blender-mcp-skills