bitbucket

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and uses a verifiable same-org npm CLI, but it routes Bitbucket access and action execution through ClawLink as a third-party intermediary that stores/uses the effective Bitbucket auth. That broader trust and mediated data flow are not inherently malicious, yet they are materially higher risk than a direct official Bitbucket integration.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:43 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fbitbucket%2F@5043cd8c52db0f68308607762e37bb7bff19e6c665ad061f7f7f01a02107baaf
Security Audit — socket — bitbucket