blender-host-sandbox-boundary

작성자: nvidia

Blender, USD, OVRTX 및 OVPhysX 작업은 Hermes 터미널과 파일 도구가 OpenShell 샌드박스에서 실행되지만 Blender MCP는 호스트 Blender 프로세스 내부에서 실행될 때 라우팅됩니다.…

npx skills add https://github.com/nvidia/nemoclaw-community --skill blender-host-sandbox-boundary

Blender Host/Sandbox Boundary

Classify every operation by the process that executes it. A path is usable only when that process can see it.

Execution surfaces

SurfaceUse forVisible paths
Hermes terminal and file toolsSandbox-local text, scripts, indexes, and uploaded inputs/sandbox/... and sandbox /tmp/...
Blender MCPThe active scene, bpy, add-ons, render engines, and host artifactsPaths reported by Blender and task-owned host output paths
External operatorCopying files across the boundary with nemohermes sandbox upload or downloadBoth sides, outside this Hermes session

Blender MCP code executes in the host Blender process even though Hermes itself runs in the sandbox. Do not search the sandbox for the Blender executable, bpy, a host add-on, or a host path. Do not ask Blender to open /sandbox/....

Route the task

  1. Read this skill before probing files or software.
  2. Classify the task:
    • MCP-only: Blender can inspect, edit, export, render, or validate the requested result and write it to a task-owned host directory.
    • Sandbox-only: every input has already been uploaded and every tool and output path is sandbox-local.
    • Hybrid: a later step requires a file produced on the other surface.
  3. Probe capabilities on their owning surface. Use Blender MCP for bpy, the active .blend, add-ons, OVRTX, OVPhysX, and host file existence. Use sandbox tools only for sandbox paths and commands.
  4. Execute one surface-local milestone at a time and verify its artifacts on that same surface.
  5. At a hybrid boundary, stop and return TRANSFER_REQUIRED. Hermes cannot run the host-side nemohermes transfer command from inside its sandbox.

In the normal raw-Blender profile, use blender-python-api-verification for unknown Blender behavior: search the sandbox-local offline reference, then verify version-sensitive API names through live Blender RNA over MCP. The bounded handoff profile cannot run arbitrary reference or inspection code; use only its exposed typed operations and report unsupported capabilities.

Prefer bounded workflow tools

When the blender-workflow MCP server is available, use its typed tools before Blender's generic execute-code tool:

  • capability_probe before claiming USD, OVRTX, OVPhysX, or SimReady support;
  • scene_inventory with a task-owned host JSON path for complete scene detail;
  • usd_export for a source-preserving Blender export and hash receipt;
  • usd_inspect for composed-stage metadata, exact prim counts, dependencies, and physics-schema counts;
  • artifact_receipts immediately before reporting any host file as created.

When a typed tool is discovered through tool_search, call tool_describe before its first invocation. Search results contain descriptions, not the full input schema, so never guess or rename argument fields. The path contract is:

  • scene_inventory: optional output_path;
  • usd_export: required output_path, optional selected_objects_only;
  • usd_inspect: required input_path, optional output_path;
  • artifact_receipts: required paths array.

If a tool returns invalid_arguments, call tool_describe, correct the named arguments, and retry once. This is a request validation failure, not evidence that Blender or the MCP server is unreachable.

A workflow operation exists only when tool_search or tool_describe exposes that exact operation. If the bounded tool set has no authoring, packaging, or execution operation required by the prompt, report that milestone as blocked. Search once for a missing operation. If no exact match is returned, stop discovery and report the blocker; do not search again with synonyms. Do not synthesize nested tool_call requests for disabled terminal or file tools, edit an installed skill to create a helper, or repeat USD inspection under new filenames; none of those actions add the missing capability.

When capability_probe reports that a required schema owner or authoring runtime is unsupported, finish only independent read-only milestones already underway, verify their receipts, and then return BLOCKED. Do not attempt dependent overlays, packaging, or validation claims.

Once scene_inventory or usd_inspect writes its detailed JSON and returns a successful receipt, treat that evidence milestone as complete. Do not try to read the host JSON with sandbox file tools, Blender resource URIs, or raw scene tools. The compact typed result is the conversation summary; the host JSON is for independent verification and downstream bounded operations.

Keep tool results compact. Write detailed inventories to task-owned host JSON artifacts and return only counts, paths, sizes, hashes, and blockers in the conversation. Never dump a full scene or stage inventory into the model context. Never author a long Python program inside an MCP JSON argument when a bounded workflow tool exists.

The typed tools intentionally do not emulate SimReady. If capability_probe does not find an enabled supported SimReady add-on, report its authoring and validation milestones as blocked. Do not invent custom properties and call them SimReady or nonvisual-material schema fields.

Transfer receipt

Return this compact structure instead of pretending a file is visible on both sides:

{
  "status": "TRANSFER_REQUIRED",
  "direction": "host_to_sandbox|sandbox_to_host",
  "source_surface": "blender_host|hermes_sandbox",
  "source_path": "exact path on the source surface",
  "destination_path": "requested path on the destination surface",
  "sha256": "hash measured on the source surface",
  "next_milestone": "what becomes possible after transfer"
}

After the external operator confirms the transfer, verify the destination hash before continuing.

Failure rules

  • If a tool reports BLOCKED or says the user denied a command, stop that workflow. Do not retry, rephrase, or seek the same outcome with another sandbox command.
  • Do not use find /, inspect restricted host-looking directories from the sandbox, or install a second Blender to compensate for wrong-surface access.
  • A missing sandbox blender, bpy, add-on, native runtime, or host file does not prove that the host capability is missing. Probe it through Blender MCP.
  • If a required capability is unavailable on its owning surface, return BLOCKED with the exact probe and error. Do not fabricate USD schemas, semantic buffers, simulation results, renders, files, or validation passes.
  • Preserve the source scene and source assets. Use a task-owned copy or output directory for mutating evaluations.
  • A final narrative is not artifact evidence. Report a host output only when artifact_receipts returns present with a nonzero size and SHA-256.

Closeout

Report the selected topology, every execution surface used, host and sandbox paths separately, artifact hashes measured on their owning surfaces, completed transfers, remaining transfer receipts, capability blockers, and any claim that was not independently verified.

nvidia의 다른 스킬

compileiq-debug
nvidia
무언가 잘못되었을 때 사용: Search()가 멈추거나, 모든 평가가 INVALID_SCORE를 반환하거나, 점수가 개선되지 않거나, 모든 설정이 동일한 숫자를 반환하거나, ptxas 오류 등이 발생할 때
create-github-pr
nvidia
gh CLI를 사용하여 GitHub 풀 리퀘스트를 생성합니다. 사용자가 새 PR을 만들거나, 코드 리뷰를 제출하거나, 풀 리퀘스트를 열고자 할 때 사용합니다. 트리거 키워드 -…
nemoclaw-maintainer-cross-issue-sweep
nvidia
다른 열린 이슈들을 스캔하여 주어진 PR이 함께 수정하거나 실수로 망가뜨릴 수 있는 이슈를 찾습니다. 인접 수정 기회와 모순 위험을 file:line…과 함께 출력합니다.
fhir-basics
nvidia
에이전트에게 FHIR R4 API의 작동 방식, 사용 가능한 리소스, 검색 매개변수를 사용한 쿼리 방법, 모든 응답 형식을 올바르게 파싱하는 방법을 가르칩니다…
compileiq-validate-result
nvidia
검색이 완료된 후, 속도 향상을 청구하거나 ACF를 발송하기 전에 사용합니다. dump_results CSV를 로드하고, 상위 K개 후보(단일 목표)를 추출합니다…
changelog-audit
nvidia
릴리스 전에 Warp CHANGELOG.md를 감사합니다: 누락된 항목 복구, 사용자 영향별 정렬, 항목 언어 다듬기, 줄 바꿈, (릴리스 브랜치 모드) 비교 업데이트…
maintain-dynamic-plugins
nvidia
NeMo Relay 동적 플러그인 로더, 매니페스트, Rust 네이티브 SDK, gRPC 워커 프로토콜, Python 워커 SDK, 문서, 테스트 및 릴리스 워크플로 커버리지를 유지 관리합니다.
dgx-diagnose
nvidia
일반적인 DGX Station GB300 문제 진단 — CUDA 충돌, 잘못된 GPU 타겟팅, vLLM/SGLang 컨테이너 버그, MIG 상태 문제, NVLink/Fabric Manager 오류,…