Atlas / MCP servers / vxasi / Blender VXAI

Blender VXAIBLOCK

mcp/vxasi/blender-vxai
Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
2 1r · 1w · 0d
Transport
—
License
MIT
Stars
300
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Pro Tip: You can use this to ask your agent to export the 3d model directly into the project you are working on to use them in your app instantly. Demo

Description

Blender MCP VXAI a powerful integration that allows you to control Blender using natural language through MCP Clients. This tool enables you to create, modify, and manipulate 3D models, animations, and scenes in Blender by simply describing what you want to do. It bridges the gap between AI language models and 3D creation, making Blender more accessible and efficient for both beginners and experienced users. This is a simple tool where the agent can let the AI agent create scripts for you while getting feedback and building the exact scene you want.

Important: If you are using uvx blender-mcp-vxai, please ensure you are using the latest addon file from the repository. Otherwise, make sure to use the correct version. Most setups should use version 1.0.5, though the latest available is 1.0.7.

  • To get the exact file goto https://github.com/VxASI/blender-mcp-vxai/tree/v1.0.7 (replace the version with the version you want), and download that addon file.

Join Discord Community

Discord Link

  • For questions
  • Suggestions
  • Feedback
  • Fast responses

Overview

Blender MCP VXAI bridges the gap between AI and 3D modeling. Whether you're a seasoned artist or just starting out, you can now:

  • Create and Modify in Real-Time: Use plain language to instruct Blender on what to build or alter.
  • Streamline Your Workflow: Automate complex operations and get immediate visual feedback.
  • Export Instantly: Directly integrate your 3D models into your app or project.

Latest Release: v1.0.7 *Note: Repeat the addon step with the new addon file and update your MCP server from uv if needed. Check the release notes for more details [Demo](https://youtu.be/3e3h6rN194I?si=E7cuDK

Read from source at commit 00e0823b9ebeOBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add blender-mcp-vxai -- uvx blender-mcp-vxai
claude-desktop
{
  "mcpServers": {
    "blender-mcp-vxai": {
      "command": "uvx",
      "args": [
        "blender-mcp-vxai"
      ]
    }
  }
}
03

Exposed tools (2)

1 read · 1 write · 0 destructive.

ToolRiskDescription
get_scene_inforead
run_scriptwrite
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (5)

CRITICALObfuscation / stealth · obf.decode_then_exec · CWE-506, CWE-94
blender_mcp_addon.py:242
b64decode( ...  exec(
Why it matters. decodes a payload and executes it
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
blender_mcp_addon.py:252
exec(script_decoded, {'bpy': bpy, 'math': math, 'random': random}, script_locals)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
dist/blender_mcp_vxai-1.0.5-py3-none-any.whl
blender_mcp_vxai-1.0.5-py3-none-any.whl
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
dist/blender_mcp_vxai-1.0.5.tar.gz
blender_mcp_vxai-1.0.5.tar.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
blender_mcp_addon.py:242
script_decoded = base64.b64decode(script).decode('utf-8')

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha 00e0823b9ebefull audit observations/trust-audit/mcp-server/vxasi__blender-vxai.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0500e0823b9ebeBLOCKD69first audit
06

Questions

What tools does Blender VXAI expose?

2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Blender VXAI safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Blender VXAI need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (00e0823b9ebe), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement