bitbucket-automation

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely aligned with its stated Bitbucket automation purpose, and the Composio/Rube service appears same-org and legitimate. The main concerns are third-party mediation of Bitbucket OAuth/data through Rube MCP, a docs inconsistency around 'no API keys needed,' mutable remote endpoint trust, and support for destructive actions without enforced approval controls. This is not confirmed malware, but it carries medium security risk due to credential/data routing and real-world write/delete capability.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 26, 2026, 09:37 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fbitbucket-automation%2F@ed6347443482bc7daa074a4cc409e6aa5f64da7e