bitbucket-cloud
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructs the agent to store authentication tokens in the Git configuration by embedding them in the remote URL (e.g.,
git remote set-url origin "https://${ENCODED_USER}:${ENCODED_PASS}@bitbucket.org/..."). This results in sensitive credentials (BITBUCKET_TOKEN) being stored in plain text within the.git/configfile.\n- [COMMAND_EXECUTION]: The skill provides several command-line snippets for the agent to execute, including Git commands and inline Python scripts for URL encoding. These commands are intended for task automation but involve direct shell execution and manipulation of environment variables.\n- [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection as the agent interacts with potentially attacker-controlled repository data and API responses while possessing capabilities like file modification and network access.\n - Ingestion points: API responses from
api.bitbucket.organd Git command outputs (git branch,git remote -v) referenced inSKILL.md.\n - Boundary markers: Absent. There are no instructions for the agent to use delimiters or ignore instructions embedded in the processed repository data.\n
- Capability inventory: Access to
BITBUCKET_TOKEN, network operations viacurl(referenced inSKILL.md), file system modifications viagit commit, and pull request management via thecreate_bitbucket_prtool.\n - Sanitization: Absent. The skill does not describe any sanitization, filtering, or validation logic for data retrieved from Bitbucket before it is processed by the agent.
Audit Metadata