Bitbucket Public Repository Posture Audit
Reports the public repositories in a Bitbucket workspace that fail its security policy, with each failing check.
What this agent does
This read-only agent audits every public repository in a Bitbucket workspace against the workspace's security policy. It checks branch restrictions and required approvals, the README, the license, public exposure, and write access from outside the workspace. It then reports each repository that fails, with the checks it fails.
The challenge
A public repository exposes its code, its pipelines, and its access settings to everyone. Repositories are made public by mistake, and protections change after a repository is created. A default branch loses its approval requirement, or a user outside the workspace keeps write access. Nobody checks every public repository against the policy. Teams learn about these gaps only when someone finds one by chance.
The solution
The agent checks every public repository against the same short policy on each run. It reports a check it cannot complete as inconclusive, never as a violation. It refuses to report when the repository list is incomplete, so it never presents a partial scan as the whole workspace. Provides a unified list of noncompliant public repositories and the checks to fix.
Workflow
- 01
List repositories
List every public repository in the workspace, and stop when the list is incomplete.
- 02
Check policy
Check each repository for default branch restrictions with required approvals, a README, a license, an approved public listing, and direct write grants.
- 03
Report
Report each noncompliant repository with its failing checks, and track the noncompliant and total counts.
Agent template
# Bitbucket Public Repository Posture Audit
## Measurable outcomes
Every public repository in the workspace that fails the security policy is in the report, with each check it fails. Track the noncompliant count on every run. The count falls as owners fix their repositories.
## Procedure
For a given Bitbucket workspace, list every public repository. Stop and report the failure when the list is shorter than expected. Never present a partial list as the whole workspace. Check each repository against five rules. The default branch has branch restrictions that require a pull request with at least one approval, enforced as a merge check so it blocks the merge. A README exists at the root. A license exists at the root. The repository is on an allowlist of repositories approved to be public. No user has write access or higher through a direct repository grant instead of a workspace group. A repository that fails any rule is noncompliant. When a setting cannot be read, report the check as inconclusive and a token scope problem, not a violation. I maintain the allowlist, and I add a repository only after I review its public exposure.
## Requirements
It needs Bitbucket API read access to the workspace's repositories, their branch restrictions, and their permissions, and nothing more. It never changes a repository, its settings, or its permissions. Related templates
-
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools -
Bitbucket Repository AI-Readiness Audit
Scores each repository in a Bitbucket workspace on how well a coding agent can work in it, and reports the ones below the bar.
Reporting and Compliance 1 tools