three.ws Blender
NPM · @THREE-WS/BLENDER-MCP · SCANNED OCT 4
Drive a local Blender headlessly: inspect, convert, render and script 3D files.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 32 of 99 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency48
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (Apache-2.0).Pass
- Actively maintained (last published 22 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability65
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2076 tokens (~296/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the three.ws Blender MCP server?
three.ws Blender runs locally as an npm package, launched with npx -y @three-ws/blender-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · @three-ws/blender-mcp
claude mcp add nirholas-blender-mcp -- npx -y @three-ws/blender-mcp
{
"mcpServers": {
"nirholas-blender-mcp": {
"command": "npx",
"args": [
"-y",
"@three-ws/blender-mcp"
]
}
}
} {
"servers": {
"nirholas-blender-mcp": {
"command": "npx",
"args": [
"-y",
"@three-ws/blender-mcp"
]
}
}
} codex mcp add nirholas-blender-mcp -- npx -y @three-ws/blender-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"nirholas-blender-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"@three-ws/blender-mcp"
],
"enabled": true
}
}
} openclaw mcp add nirholas-blender-mcp --command npx --arg -y --arg @three-ws/blender-mcp
mcp_servers:
nirholas-blender-mcp:
command: "npx"
args: ["-y", "@three-ws/blender-mcp"] {
"McpServers": {
"nirholas-blender-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"@three-ws/blender-mcp"
]
}
}
} assistant mcp add nirholas-blender-mcp -t stdio -c npx -a -y @three-ws/blender-mcp
{
"mcpServers": {
"nirholas-blender-mcp": {
"command": "npx",
"args": [
"-y",
"@three-ws/blender-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 1 Oct 26 +15
- Malware scan: unverified → pass ▲ security
- 30 Sept 26 54
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Oct 2026 · Analysed npm/@three-ws/blender-mcp@0.5.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 99 packages
| Packages resolved | 99 |
|---|---|
| Stale | 32 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
blender_convert Convert a 3D file between formats ~243
Convert a 3D file from any format Blender can import to any format it can export, driven entirely by the file extensions: .glb, .gltf, .fbx, .obj, .stl, .ply, .dae, .abc, .usd/.usda/.usdc/.usdz, .x3d, and .blend on both sides. Modifiers are applied on export by default, and an optional uniform scale is baked in. Returns the output path, its size, the resulting geometry counts, and the world-space bounds. The input file is never modified; omit "output" and the result lands in the server workdir.
| Name | Type | Req | Description |
|---|---|---|---|
| apply_modifiers | boolean | – | Apply modifiers (subdivision, decimate, mirror) to the exported geometry. Default true. |
| input | string | yes | Path to the source 3D file. |
| output | string | – | Destination path. Its extension selects the export format. Defaults to a .glb in the server workdir. |
| scale | number | – | Uniform scale factor baked into the export, e.g. 0.01 to convert centimetre units to metres. |
No output schema declared.
No examples provided.
blender_forge_import Generate a 3D model with three.ws and open it in Blender ~385
Generate a 3D model from a text prompt OR a reference image on the public three.ws Forge pipeline, then bring it into Blender. Pass "prompt" to describe it, "image" for a local PNG/JPEG/WebP, or "image_url" for one already public; an image plus a prompt uses the prompt to steer the reconstruction. The default image lane (FLUX to TRELLIS) is free and needs no key, wallet, or account. The GLB is saved locally, and if the output path asks for another format (.blend, .fbx, .obj, .usd) Blender converts it on the way in. Returns the local path, the hosted GLB URL, and the geometry counts. Generation runs on a shared GPU lane and typically takes tens of seconds to a couple of minutes. Describe ONE subject per call.
| Name | Type | Req | Description |
|---|---|---|---|
| aspect_ratio | string | – | Reference image aspect ratio. Default "1:1". |
| backend | string | – | Pin a specific backend. Omit to let the deployment choose for the tier. |
| image | string | – | Local PNG, JPEG or WebP to reconstruct from. Uploaded straight to storage on a presigned PUT. |
| image_url | string | – | A public https image to reconstruct from, instead of uploading one. |
| lane | string | – | Pipeline lane. "image" (default) is free. "geometry" uses Meshy/Tripo and needs THREE_WS_FORGE_PROVIDER_KEY. |
| output | string | – | Where to save it. The extension picks the format (.glb keeps the original bytes). Defaults to a .glb in the workdir. |
| prompt | string | – | What to generate. One subject, e.g. "a weathered brass diving helmet". Required unless an image is given. |
| tier | string | – | Generation quality. Default "standard". |
No output schema declared.
No examples provided.
blender_info Inspect the local Blender install ~67
Report the local Blender this server drives: executable path, version, bundled Python, available render engines, and the import/export formats this build actually supports. Call it first when a tool fails, or to check that Blender is installed at all. Read-only: it opens no file and writes nothing.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
blender_optimize Shrink a 3D model for delivery ~255
Make a model web-ready in one call: decimate every mesh proportionally to hit a triangle budget, scale oversized textures down, purge datablocks nothing references, and compress the mesh streams with meshopt (or Draco) on the way out. Returns before and after triangle counts, texture bytes and file size, plus what each step did, so the trade is visible rather than guessed. The input file is never modified. Decimation is collapse-based and preserves vertex groups, but a heavily decimated skinned mesh should be checked with blender_render before shipping.
| Name | Type | Req | Description |
|---|---|---|---|
| compress | string | – | Mesh compression for a .glb/.gltf output. "meshopt" (default) is what the three.ws runtime and every major web viewer decode. Ignored for other formats. |
| input | string | yes | Path to the model to optimize. |
| max_texture_px | integer | – | Longest edge any texture may keep, e.g. 1024. Omit to leave textures untouched. |
| max_triangles | integer | – | Triangle budget for the whole scene. Omit to leave geometry untouched. |
| output | string | – | Destination. The extension picks the format. Defaults to a .glb in the server workdir. |
No output schema declared.
No examples provided.
blender_render Render a preview image of a 3D file ~414
Render a still PNG of any 3D file Blender can open (.blend, .glb, .fbx, .obj, .usd and the rest). If the scene has no camera, one is created and framed to the model; if it has no light, a key light and a lit world are added, so a bare asset file renders as a usable preview with no setup. A scene that already has its own camera and lighting is rendered as authored. The rendered image is returned INLINE alongside the JSON, so you can actually look at the model in this one call without needing filesystem access, while the full-resolution PNG is written to disk. Ask for several views and it orbits the model, rendering every angle in the same Blender launch. Use it to see a model, check a conversion, or produce a thumbnail.
| Name | Type | Req | Description |
|---|---|---|---|
| engine | string | – | Render engine. "auto" (default) picks CYCLES, which renders on CPU. EEVEE is far faster but needs a GPU context. Call blender_info to see what this build offers. |
| inline_image | boolean | – | Return the image inline so you can see it, downscaled to fit the context. Default true. |
| input | string | yes | Path to the 3D file to render. |
| output | string | – | Destination PNG path. Defaults to a .png in the server workdir. |
| resolution | array | – | Output size as [width, height]. Default [960, 960]. |
| samples | integer | – | Sample count. Default 32: enough for a preview. |
| transparent | boolean | – | Render with a transparent background instead of the world. Default false. |
| views | integer | – | How many angles to render, orbiting the model, all in one Blender launch and all returned inline. Default 1. Use 4 to see whether the back of a model is modelled at all. A set always orbits its own c… |
No output schema declared.
No examples provided.
blender_run_python Run a Python script inside Blender ~224
Execute a Python script inside Blender with the full bpy API available. Optionally open a 3D file first (any format Blender imports) and export the edited scene afterwards, chosen by the output extension. Anything printed is returned as stdout, and assigning a JSON-serializable value to a variable named `result` returns it as structured data. Use this for scene edits the other tools do not cover: decimating meshes, joining or renaming objects, editing armatures, baking animation, cleaning materials. The script runs with the permissions of this server and can read and write the local filesystem.
| Name | Type | Req | Description |
|---|---|---|---|
| apply_modifiers | boolean | – | Apply modifiers when exporting. Default true. |
| code | string | yes | Python source to execute. `bpy`, `math`, and `Vector` are already imported. |
| input | string | – | 3D file to open before running the script. Omit to start from an empty scene. |
| output | string | – | Export the scene here after the script runs; the extension selects the format. Omit to discard it. |
No output schema declared.
No examples provided.
blender_scene_info Describe a 3D file with Blender ~236
Open a 3D file with Blender and report what is inside it: object list with types, parents, dimensions and modifiers; evaluated triangle and vertex counts; materials; armature bone names; animation actions with their frame ranges; a texture inventory with each image's resolution and byte size plus the total, which is usually what decides whether an asset is deliverable; and world-space bounds. Accepts .blend plus every format this Blender can import (.glb, .gltf, .fbx, .obj, .stl, .ply, .dae, .abc, .usd*, .x3d). Counts describe the file AS LOADED, so a GLB reports more vertices than the .blend it came from (glTF splits vertices at UV and normal seams) while the triangle count is identical. Read-only: the file is never modified.
| Name | Type | Req | Description |
|---|---|---|---|
| include_objects | boolean | – | Include the per-object breakdown. Set false on very large scenes to get totals only. Default true. |
| input | string | yes | Path to the 3D file to inspect. Absolute, or relative to the server working directory. |
No output schema declared.
No examples provided.
What is the three.ws Blender MCP server?
three.ws Blender is an MCP server listed in the public MCP registry as io.github.nirholas/blender-mcp. Drive a local Blender headlessly: inspect, convert, render and script 3D files. This page covers its npm package (@three-ws/blender-mcp).
Is the three.ws Blender MCP server safe to use?
three.ws Blender scores 69 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the three.ws Blender MCP server expose?
three.ws Blender exposes 7 tools: blender_info, blender_scene_info, blender_convert, blender_optimize, blender_render, and 2 more. Their descriptions and schemas cost roughly 1,824 tokens of context every time the server is loaded.
Is the three.ws Blender MCP server still maintained?
three.ws Blender is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the three.ws Blender MCP server under?
three.ws Blender declares the Apache-2.0 licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.