bitbucket-cloud

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructs the agent to store authentication tokens in the Git configuration by embedding them in the remote URL (e.g., git remote set-url origin "https://${ENCODED_USER}:${ENCODED_PASS}@bitbucket.org/..."). This results in sensitive credentials (BITBUCKET_TOKEN) being stored in plain text within the .git/config file.\n- [COMMAND_EXECUTION]: The skill provides several command-line snippets for the agent to execute, including Git commands and inline Python scripts for URL encoding. These commands are intended for task automation but involve direct shell execution and manipulation of environment variables.\n- [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection as the agent interacts with potentially attacker-controlled repository data and API responses while possessing capabilities like file modification and network access.\n
  • Ingestion points: API responses from api.bitbucket.org and Git command outputs (git branch, git remote -v) referenced in SKILL.md.\n
  • Boundary markers: Absent. There are no instructions for the agent to use delimiters or ignore instructions embedded in the processed repository data.\n
  • Capability inventory: Access to BITBUCKET_TOKEN, network operations via curl (referenced in SKILL.md), file system modifications via git commit, and pull request management via the create_bitbucket_pr tool.\n
  • Sanitization: Absent. The skill does not describe any sanitization, filtering, or validation logic for data retrieved from Bitbucket before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:07 PM
Security Audit — agent-trust-hub — bitbucket-cloud