repomix
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and package external code repositories for AI analysis, creating a surface for indirect prompt injection where malicious instructions inside a repository could influence the agent's behavior.
- Ingestion points: Data is ingested from local paths or remote URLs via the
repomixCLI and thescripts/repomix_batch.pyscript. - Boundary markers:
repomixuses structured delimiters (e.g., XML tags) to separate files in its output, providing structural context but not complete protection against adversarial instructions. - Capability inventory: The skill executes shell commands (
repomix,npx) and reads repository content through the packaging process. - Sanitization: While it includes a secret scanner (
Secretlint) to identify and exclude credentials, it does not include sanitization for natural language instructions embedded in the ingested code. - [COMMAND_EXECUTION]: The script
scripts/repomix_batch.pyusessubprocess.runto execute therepomixCLI andnpxtool. - Evidence: The
_build_commandmethod inscripts/repomix_batch.pyconstructs a command list from user-supplied repository paths or URLs, which is then executed viasubprocess.runin theprocess_repositorymethod. - Note: The script includes an environment variable loader that searches for
.envfiles up to three directory levels above its location. This broad search pattern could inadvertently load and expose sensitive environment variables to the subprocess if the script is executed within a nested directory structure on the host machine.
Audit Metadata