bkt

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install the bkt CLI tool from repositories owned by the author (avivsinai), including Homebrew taps, Scoop buckets, and Go package installations from github.com/avivsinai/bitbucket-cli.
  • [COMMAND_EXECUTION]: The skill invokes local git commands (e.g., during bkt branch rebase) and provides a mechanism to execute CLI extensions. These are documented as core functionalities of the tool.
  • [CREDENTIALS_UNSAFE]: The skill manages Bitbucket authentication tokens. It prioritizes secure storage in the OS keychain and provides explicit warnings against passing tokens as command-line arguments to avoid exposure in shell history.
  • [REMOTE_CODE_EXECUTION]: The bkt extension install command allows downloading and running code from external Git repositories. The skill documents security mitigations, such as stripping sensitive configuration variables from the environment before an extension process starts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 05:36 AM
Security Audit — agent-trust-hub — bkt