bitbucket-browser-fetch

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but it achieves it by extracting authenticated Bitbucket cookies through Chrome DevTools and using browser/internal APIs instead of the official API auth path. There is no clear third-party exfiltration or malicious payload, so this is not confirmed malware, but the credential/session handling and remote-debugging dependency create meaningful security risk disproportionate to a normal repository-listing integration.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 8, 2026, 08:23 PM
Package URL
pkg:socket/skills-sh/aholbreich%2Fagent-skills%2Fbitbucket-browser-fetch%2F@2306de9705a3d3a6502524b8da13abcd32431ffd