bitbucket
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
npx @useclawlink/clito execute setup and operational commands for Bitbucket management. - [EXTERNAL_DOWNLOADS]: Fetches the official
@useclawlink/clipackage from the npm registry at runtime vianpx. - [CREDENTIALS_UNSAFE]: Standard credential management involves storing authentication tokens in
~/.clawlink/credentials.jsonupon login. - [DATA_EXFILTRATION]: Communicates with the service endpoint at
claw-link.devto proxy Bitbucket requests as part of its primary integration functionality. - [PROMPT_INJECTION]: Analyzed for Indirect Prompt Injection risks, as the skill reads content from external sources (Bitbucket pull requests, issues, and repository files). The instructions include a safety recommendation to confirm actions with the user before performing any write operations.
Audit Metadata