blender-production
Pass
Audited by Gen Agent Trust Hub on Oct 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
sequence_tools.pyscript utilizes thesubprocessmodule to callffmpegandffprobefor media processing tasks. Found inscripts/sequence_tools.pywhere it constructs command lists for encoding image sequences into MP4 files. The commands are executed using list-based arguments without a shell, preventing common command injection vectors. - [DYNAMIC_EXECUTION]: The
file_bridge.pyscript provides a mechanism to execute Python scripts within an active Blender process for automation. Evidence:runpy.run_path(str(script))is used inscripts/file_bridge.pyto process requests from a file queue. The implementation includes several safety checks: it validates a session-specific UUID, verifies the process ID (PID) of the Blender instance, and strictly limits execution to scripts located within a user-defined allowed directory. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from logs, image files, and an ephemeral command queue, presenting a potential surface for indirect injection. Ingestion points: JSONL files in
scripts/benchmark.py, PNG image chunks inscripts/sequence_tools.py, and JSON request files inscripts/file_bridge.py. Boundary markers:file_bridge.pyutilizes a session-lock file containing a UUID and PID to delimit authorized agent requests. Capability inventory: Includes file system read/write for project assets, execution of local Python scripts within Blender, and invocation of the systemffmpegutility. Sanitization: JSON payloads are validated for expected structure, script paths are checked against directory boundaries, and PNG files undergo CRC and header signature verification.
Audit Metadata