bkt — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited bkt (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
bkt is a unified CLI for Bitbucket Data Center and Bitbucket Cloud. It mirrors gh ergonomics and provides structured JSON/YAML output for automation.
1. Verify installation — always check before running any bkt command:
bkt --versionIf not installed:
| Platform | Command |
|---|---|
| macOS/Linux | brew install avivsinai/tap/bitbucket-cli |
| Windows | scoop bucket add avivsinai https://github.com/avivsinai/scoop-bucket && scoop install bitbucket-cli |
| Go | go install github.com/avivsinai/bitbucket-cli/cmd/bkt@latest |
| Binary | Download from GitHub Releases |
2. Check authentication — most commands require an active session:
bkt auth statusBitbucket Cloud Token Requirements:
read:user:bitbucket)For config-free use in containers and CI pipelines, see headless authentication.
If not authenticated, log in:
# Data Center (PAT-based)
bkt auth login https://bitbucket.example.com --username alice --token <PAT>
# Bitbucket Cloud — OAuth (official binaries open browser out of the box)
bkt auth login https://bitbucket.org --kind cloud --web
# Bitbucket Cloud — API token (--web-token opens Atlassian's token creation page)
bkt auth login https://bitbucket.org --kind cloud --web-tokenFor source and Nix builds, set BKT_OAUTH_CLIENT_ID and BKT_OAUTH_CLIENT_SECRET env vars before running --web.
3. Set up a context — contexts bind a host to a project/workspace and optional default repo, so you don't repeat flags on every command:
# Data Center
bkt context create dc-prod --host bitbucket.example.com --project ABC --set-active
# Cloud
bkt context create cloud-team --host bitbucket.org --workspace myteam --set-activeSome commands are Data Center only or Cloud only — check the command reference for *(DC)* and *(Cloud)* badges. Key splits:
| Feature | Data Center | Cloud |
|---|---|---|
| Pull requests | yes | yes |
| Repositories | yes | yes |
| Branches (list) | yes | yes |
| Branches (create/delete/protect) | yes | — |
| Issues | — | yes |
| Pipelines | — | yes |
| Permissions | yes | — |
| Webhooks | yes | yes |
| Auto-merge, tasks, reactions | yes | — |
| Variables | — | yes |
When a user's context is DC, do not suggest Cloud-only commands (and vice versa). If the platform is unknown, ask or check with bkt auth status.
bkt pr create --title "feat: add caching" --target mainSource branch, title, and target default to sensible values from git state. Add --draft for work-in-progress, --reviewer alice to request review.
bkt pr checks 42 --wait # Wait for CI to pass
bkt pr approve 42 # Approve
bkt pr merge 42 # Merge (closes source branch by default)bkt pr checkout 42 # Creates pr/42 branchAll commands support --json, --yaml, --jq, and --template:
bkt pr list --mine --json | jq '.pull_requests[].title'For endpoints without a dedicated command:
bkt api /rest/api/1.0/projects --param limit=100 --jsonEvery command accepts these inherited flags:
| Flag | Short | Purpose |
|---|---|---|
--context | -c | Use a specific named context |
--json | JSON output | |
--yaml | YAML output | |
--jq | Apply a jq expression (requires --json) | |
--template | Render with Go template |
<!-- auto-generated by cmd/docgen — do not edit below this line -->
<!-- end auto-generated -->
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.