Back to skill

Security audit

Blender - Agents Help with 3D work

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Blender automation skill, but users should review the external Flue package before approving its unpinned install and setup command.

Install only after inspecting the Flue project and preferably pinning or verifying the package version. Run it with normal user privileges, confirm setup changes separately, and only allow scripts that match the Blender task you requested.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party Package Installation and Setup Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15
Vulnerability Type: Unpinned third-party dependency installation and execution
Risk Level: Medium

Complete Code Snippet:

markdown
3. **If Flue is not installed:** tell the human. The install command is `pip install flue && flue setup`. Do not install without explicit approval in the current session.

A materially equivalent instruction also appears at FLUE.md:70-71:

markdown
## If Flue Is Not Installed
If Flue appears relevant but is not available on the machine, tell your human as much. Inspect the project at `https://github.com/SFKislev/flue` (PyPI: `https://pypi.org/project/flue`). Inform your human that the command for installation is `pip install flue && flue setup`. Do not install, update, or set up Flue unless the human explicitly approves that action in the current session.

Technical Analysis

The documented command installs the latest package named flue resolved by pip from the configured package index and immediately executes its setup routine. It does not pin a reviewed version, verify a cryptographic hash, use a lockfile, or identify an immutable source revision.

Consequently, the code executed at installation time may differ from the code originally reviewed. Relevant threats include compromise of the publisher account or package, publication of a malicious later release, package-index substitution, and unsafe package-index configuration. Installation can execute package-controlled build or installation behavior, while the subsequent flue setup command explicitly executes the installed dependency.

The dependency is especially sensitive because its declared function is to bridge shell commands into programmable desktop-application runtimes. The documentation states that scripts may be forwarded to Blender through bpy and to other applications through interfaces such as COM, ExtendScript, CEP, and Unity APIs. This creates a broad local execution and ...[truncated 2166 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin Flue to a specific version that has undergone security review rather than installing the latest available release.
  2. Provide a hash-locked requirements file and install with pip's --require-hashes option.
  3. Where practical, identify and verify an immutable source commit or signed release corresponding to the package artifact.
  4. Verify that the PyPI publisher and project metadata correspond to the linked GitHub repository before installation.
  5. Separate installation and setup into distinct commands so the user can inspect the installed files and planned setup changes before executing flue setup.
  6. Document all files, application integrations, services, network listeners, and configuration changes made by the setup process.
  7. Install into an isolated virtual environment and run the bridge with ordinary user privileges; do not use an administrator or root account unless a separately reviewed operation strictly requires it.
  8. For a Blender-specific Skill, offer a minimal Blender-only installation or configuration that excludes unrelated application adapters.
  9. Require explicit confirmation not only before installation but also before setup, updates, adapter activation, and execution of scripts inside an application.
  10. Review the external Flue implementation and its setup routine independently, because those files are not included in the audited project.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.