Bitbucket Pipelines CI/CD (AWS ECR + EC2/ECS)

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources, including official Atlassian Bitbucket Pipes (e.g., atlassian/aws-ecr-push-image, atlassian/ssh-run, atlassian/aws-ecs-deploy) and standard Docker images (e.g., node:22-alpine). These are well-known, trusted resources for CI/CD workflows.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were found. The skill explicitly instructs users to use 'Secured' Repository variables and avoid direct exposure in logs, which is a security best practice.
  • [COMMAND_EXECUTION]: The skill provides examples of shell commands for building Docker images and running deployment scripts. These commands are typical for the described CI/CD tasks and are intended to be executed within the user's controlled pipeline environment.
  • [DATA_EXFILTRATION]: There are no patterns suggesting unauthorized data exfiltration. Network operations described (pushing to ECR, SSH to EC2, updating ECS) are the primary purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 06:07 AM
Security Audit — agent-trust-hub — Bitbucket Pipelines CI/CD (AWS ECR + EC2/ECS)