Audit History
bitbucket-automation - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Aug 14, 2026, 10:32 AM | 2 confirmed | 1 | No capability change |
| v4 | Jul 5, 2026, 11:30 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 5, 2026, 11:30 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 01:12 PM | 1 confirmed | 1 | External commands |
| v1 | Feb 25, 2026, 04:19 AM | No confirmed findings | 0 | Baseline |
Aug 14, 2026, 10:32 AM
All 118 shell-execution alerts are false positives caused by Markdown backticks, and the key-file and reconnaissance alerts are also false positives. The skill still requires an external MCP connection with Bitbucket OAuth and supports irreversible remote deletion.
Confirmed security concerns (2)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (50)
🌐 Network access (1)
Jul 5, 2026, 11:30 PM
The static analyzer flagged Markdown inline code spans, a documented MCP endpoint, a BBQL project.key example, and BBQL field guidance. Manual review found no prompt injection, credential exposure, hidden command execution, or malicious intent in SKILL.md.
Risk Factors
⚙️ External commands (118)
🌐 Network access (1)
Jul 5, 2026, 11:30 PM
The static analyzer flagged Markdown inline code spans, a documented MCP endpoint, a BBQL project.key example, and BBQL field guidance. Manual review found no prompt injection, credential exposure, hidden command execution, or malicious intent in SKILL.md.
Risk Factors
⚙️ External commands (118)
🌐 Network access (1)
Jun 30, 2026, 01:12 PM
Static command-execution, weak-crypto, certificate, and reconnaissance findings are false positives caused by Markdown backticks, tool names, BBQL examples, and SHA1 commit-hash documentation. The confirmed risks are legitimate third-party MCP network access and documented irreversible Bitbucket delete operations, so the skill should publish with a warning.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (3)
Detected Patterns
Feb 25, 2026, 04:19 AM
All 271 static findings are false positives from Markdown code formatting. The file is documentation-only with no executable code. External command detections are backticks around tool names, not actual execution. The single network reference is a legitimate MCP endpoint URL. Skill safely provides Bitbucket automation workflows through Rube MCP server.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.