AGENT LAB: SKILLS

bitbucket-automation

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The manifest/documentation is a functional and plausible Bitbucket automation skill. It does not contain embedded malware or hard-coded secrets. The principal supply-chain/security risk is architectural: all OAuth credentials and API payloads are brokered through a third-party MCP (https://rube.app/mcp) with no transparency about operator, token handling, retention, or logging. This creates a high-impact trust boundary where exfiltration or unauthorized actions are possible if the MCP is malicious or compromised. Recommended mitigations before adoption: verify MCP operator identity and audit results, insist on minimal OAuth scopes and short-lived tokens, require explicit multi-step confirmation (and re-authentication) for destructive actions, log and monitor actions locally, and prefer direct API calls or a self-hosted trusted proxy when handling sensitive repos.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:08 PM
Package URL
pkg:socket/skills-sh/composiohq%2Fawesome-claude-skills%2Fbitbucket-automation%2F@b94bffa33c3d0fd84e84d0219752f70a55be881a