
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@staticbot/mcp
Advanced tools
Give Codex, Claude, Cursor, and other MCP-compatible agents safe access to Staticbot. The server exposes typed tools for deploying websites, migrating application backends, and operating continuous sync while Staticbot keeps credentials and long-running workflow state outside the model context.
Connect the hosted server — no install, no API key. Point an MCP client that supports remote servers with OAuth at:
https://mcp.staticbot.dev/mcp
You sign in to Staticbot, choose what to grant, and the client stores the connection. If you do not have a Staticbot account yet, one is created when you first connect.
Run it locally — for clients that launch MCP servers as a local process. Needs Node.js 20 or newer and a Staticbot API key from app.staticbot.dev/developer.
Both expose the same tools. The hosted server acts as the person who authorized it and never sees an API key; the local server uses the API key you give it.
This repository is also a Codex plugin. Its manifest bundles the Staticbot MCP server with three intent-focused skills:
deploy-web-app-with-staticbot deploys a repository without making the agent choose a cloud provider. Staticbot analyzes the repo, classifies the workload, and selects the supported AWS or Cloudflare target plus its customer-owned or Staticbot-managed ownership model.migrate-vibe-coded-app moves Base44, Lovable, Bolt, or Firebase backends to customer-owned Supabase infrastructure with discovery and approval gates.sync-vibe-coded-app keeps migrated projects synchronized while preserving destructive-change review.The general staticbot skill remains available as a direct REST API fallback.
Claude Code does not require Staticbot to be accepted into a central plugin registry. Add the self-hosted marketplace directly from this GitHub repository, then install the plugin:
/plugin marketplace add bitfiction/staticbot-mcp
/plugin install staticbot@staticbot
Set STATICBOT_API_KEY in the environment that launches Claude Code. The plugin starts the published @staticbot/mcp package with npx and inherits that environment; STATICBOT_API_URL remains optional for self-hosted or local Staticbot APIs.
The installed skills are namespaced by the plugin. For example, use /staticbot:deploy-web-app-with-staticbot, /staticbot:migrate-vibe-coded-app, or /staticbot:sync-vibe-coded-app. Restart Claude Code or run /reload-plugins after installation if the plugin is not immediately available.
For clients that support remote MCP servers, add https://mcp.staticbot.dev/mcp and authorize when
prompted. The client discovers where to sign in from the server itself; there is nothing to copy or
paste, and no credential is stored on your machine.
Add the published package to your project or global MCP configuration:
{
"mcpServers": {
"staticbot": {
"command": "npx",
"args": ["-y", "@staticbot/mcp"],
"env": {
"STATICBOT_API_KEY": "sk-your-api-key-here"
}
}
}
}
Hosted Staticbot at https://app.staticbot.dev is the default. Do not set STATICBOT_API_URL for the hosted service; override it only when using a self-hosted or local Staticbot API.
Keep the API key in your MCP client's secret or environment configuration. Do not paste it into chat or commit it to a repository.
The server groups its tools around user outcomes:
The tool schemas and descriptions are the runtime contract seen by MCP clients. They contain the operational instructions an agent needs at the moment it selects a tool.
Staticbot tools are designed around explicit human control:
list_rollback_versions and require confirmation.When a migration response contains pendingAction, the client should treat it as the source of truth for the next step. Clients should not hard-code Staticbot's internal pipeline phases.
The repository includes focused deployment, migration, and Continuous Sync skills plus a general Staticbot Skill for Codex or Claude environments that can operate the REST API directly without an MCP server. The direct-API workflow fetches the live OpenAPI contract and applies the same approval and credential-handling rules.
Use the MCP package when your client supports MCP. Use the Skill when direct API access from a command-line agent is more appropriate.
These apply to the local server. The hosted server needs none of them.
| Variable | Required | Default | Purpose |
|---|---|---|---|
STATICBOT_API_KEY | Yes | — | Authenticates requests to Staticbot |
STATICBOT_API_URL | No | https://app.staticbot.dev | Override only for a self-hosted or local API |
MIT
FAQs
MCP server for the Staticbot API
The npm package @staticbot/mcp receives a total of 69 weekly downloads. As such, @staticbot/mcp popularity was classified as not popular.
We found that @staticbot/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.