{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2026-04-27T22:57:36.680000+00:00","analysis_method":"capability_triage","category":"Desktop Extension","description":"Drive Blender from natural language via its Python API. Runs locally; full Python execution means it can read or write any file Blender's process can access.","did":"ant-dir-gh-blender-blender-mcp","homepage_url":"https://www.blender.org/lab/mcp-server/","icon":"https://claude.ai/api/dxt/extensions/ant.dir.gh.blender.blender-mcp/versions/1.0.1/icon.png","id":"ant.dir.gh.blender.blender-mcp","installs":8266,"last_scanned":"","license":"GPL-3.0-or-later","long_description":"Connects Claude to Blender's Python API so you can drive 3D modeling, scene setup, and animation work from natural-language prompts.\n\nThe extension runs locally and requires the companion Blender add-on. Because it exposes the full Python API, it can execute arbitrary Python in the Blender process - which can read/write any file the Blender process has access to.","name":"Blender","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-gh-blender-blender-mcp&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Blender Lab","publisher_url":"https://www.blender.org/lab/","repository_url":"https://projects.blender.org/lab/blender_mcp","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.","evidence":"1 code execution tools on this connector - e.g. Python API execution.","remediation":{"block_tool_categories":["code_execution"],"steps":["In the tools list below, turn off any tool tagged Block before connecting this to real data or production systems.","If you need code execution, run it on a separate test machine that has no access to your work files, customer data, or saved passwords.","Limit which websites and services that test machine can talk to."]},"risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 0 tools; permissions on claude.ai/directory: \"Local\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"low","title":"Reads your private information"}],"signature_status":"unsigned","source_code_reviewed":false,"tags":["desktop_extension","runs_code","creative_tools"],"tools":[],"tools_count":0,"type":"desktop_extension","url":"","uuid":"5d068dbc-e349-5ee4-8459-67a98e3b95fc","version":"1.0.1"},"query_key":"blender","schema_version":1,"status":"match"}
