bitbucket

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This file is an operational/instructional skill to manage Bitbucket resources using a BITBUCKET_TOKEN. It is not overtly malicious, but it contains security-risk guidance: specifically, instructing embedding the token in a git remote URL and unqualified use of an external create_bitbucket_pr tool. These practices increase the probability of credential leakage or credential forwarding to an untrusted component. Recommendations: avoid embedding tokens in URLs, prefer credential helpers or short-lived/minimal-scope tokens, verify the provenance and behavior of create_bitbucket_pr before forwarding credentials, and require explicit user confirmation for push/PR actions. Overall: moderate security risk centered on credential handling rather than malicious intent.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:33 PM
Package URL
pkg:socket/skills-sh/openhands%2Fextensions%2Fbitbucket%2F@0e8efe5c6c2499fc337ad5e06ea479faff04e5c2