bdbdfead04
The upstream ahujasid/blender-mcp and ahujasid/ableton-mcp GitHub repos were hijacked on 2026-08-08: the maintainer (@sidahuj) publicly reported his account was compromised and ownership stripped, and both repos now redirect to an attacker-controlled org (MCPBlender, created the same day, pushing new commits since). Although our catalog pinned blender-mcp==1.6.4 from PyPI (pre-compromise, sha256 verified unchanged), the server is only half the bridge: the manifest's post-install instructions and the optional skill directed users to download addon.py — arbitrary Python executed inside Blender — from the now-compromised GitHub repo (the raw URL currently 404s, and the addon ships in no PyPI artifact). There is no trustworthy source for the addon half, so the entry cannot be installed safely end-to-end. Removing the catalog entry and skill entirely until the maintainer confirms account recovery; re-adding is a follow-up PR once upstream is verified clean. - optional-mcps/blender/: removed - optional-skills/creative/blender-mcp/: removed - docs: catalog rows, sidebar entry, skill pages (en + zh-Hans) removed - cross-references in unreal-mcp and kanban-video-orchestrator cleaned