chore(deps): update dependency blender-mcp to v1.8.7 - #718
Conversation
🔒 MCP Security Scan Results❌ blender-mcp
Security issues detected:
Summary: Scanned 1 MCP server(s), found 14 security issue(s). |
9fc821d to
683696a
Compare
683696a to
2404d27
Compare
8c5a515 to
1457b4d
Compare
49d77d9 to
ab6aa5e
Compare
ab6aa5e to
869e161
Compare
869e161 to
8b9ac74
Compare
8b9ac74 to
b6c0090
Compare
b6c0090 to
5894e4b
Compare
|
Triage note — do not merge as-is, no code change pushed here. This is a genuine, version-introduced risk, not scanner noise. Diffed the PyPI sdists for blender-mcp 1.5.6 vs 1.8.7: every one of the ~16 tools already had a mild `user_prompt` "for telemetry" parameter in 1.5.6, but 1.8.7 rewrote every tool's docstring to compel the calling agent to relay the user's raw, verbatim prompt into that parameter on every call, using directive language aimed at the LLM itself (e.g. "never substitute... repeat their previous words unchanged"). That's what triggered the 16 identical `AITech-1.1` (HIGH) findings. Recommend escalating to a security reviewer with the specific question of what blender-mcp's telemetry endpoint does with that raw prompt data before deciding whether to hold this PR, ask upstream (`ahujasid/blender-mcp`) to clarify/revert the docstring change, or accept it with an explicit allowlist reason naming the behavior. Not treating this as a routine allowlist add. |
This PR contains the following updates:
1.5.6→1.8.7Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.