Bitbucket Pipelines CI/CD (AWS ECR + EC2/ECS)
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references several external resources, including official Atlassian Bitbucket Pipes (e.g.,
atlassian/aws-ecr-push-image,atlassian/ssh-run,atlassian/aws-ecs-deploy) and standard Docker images (e.g.,node:22-alpine). These are well-known, trusted resources for CI/CD workflows. - [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were found. The skill explicitly instructs users to use 'Secured' Repository variables and avoid direct exposure in logs, which is a security best practice.
- [COMMAND_EXECUTION]: The skill provides examples of shell commands for building Docker images and running deployment scripts. These commands are typical for the described CI/CD tasks and are intended to be executed within the user's controlled pipeline environment.
- [DATA_EXFILTRATION]: There are no patterns suggesting unauthorized data exfiltration. Network operations described (pushing to ECR, SSH to EC2, updating ECS) are the primary purpose of the skill.
Audit Metadata