blender-mcp

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior is coherent for a Blender-control skill, but the install path uses an unpinned raw GitHub addon from a different owner than the declared author, and the skill grants very broad arbitrary bpy execution. No clear credential theft or third-party interception is present, so this looks more like a high-power local automation skill with notable supply-chain and execution risk than confirmed malware.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 4, 2026, 05:51 PM
Package URL
pkg:socket/skills-sh/NousResearch%2Fhermes-agent%2Fblender-mcp%2F@726f43ac6b37885e9b7999806996ccaacc5c7ac9