bitbucket

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's Bitbucket functionality is broadly aligned with its purpose and the CLI install source appears legitimate, but the integration depends on a Membrane account and routes Bitbucket authentication and API traffic through Membrane rather than directly to official Atlassian endpoints. That third-party credential/data mediation is the main risk and makes the skill higher-risk than a direct Bitbucket client.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 13, 2026, 10:26 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbitbucket%2F@ac41dfcf45d5aa0fc6d20829309bcf962df6fa61