bitbucket-automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s Bitbucket automation purpose matches its capabilities, but it routes OAuth and all Bitbucket operations through a third-party hosted MCP service controlled by Composio/Rube rather than direct Atlassian APIs. That makes the footprint coherent but raises medium security risk due to credential delegation, broad workspace/admin scope, and remote service trust outside the skill publisher.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/ranbot-ai%2Fawesome-skills%2Fbitbucket-automation%2F@4cbd24d0e5b9e781109ec9361630f24268871aaf