stattic

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent for a hosting/publishing tool, but the actual trust chain is weak: the named CLI could not be matched to verified official command docs, and the `$STATTIC_CLI_BIN` fallback allows any local executable to receive publish inputs and auth tokens. Because an unverifiable binary may handle credentials and file uploads, the skill carries high supply-chain risk even without direct evidence of malicious intent.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
May 11, 2026, 11:28 AM
Package URL
pkg:socket/skills-sh/batuhan%2Fstattic-skill%2Fstattic%2F@0608ef40e11ead76294b102f2c0a369a11ceee68