repomix

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and package external code repositories for AI analysis, creating a surface for indirect prompt injection where malicious instructions inside a repository could influence the agent's behavior.
  • Ingestion points: Data is ingested from local paths or remote URLs via the repomix CLI and the scripts/repomix_batch.py script.
  • Boundary markers: repomix uses structured delimiters (e.g., XML tags) to separate files in its output, providing structural context but not complete protection against adversarial instructions.
  • Capability inventory: The skill executes shell commands (repomix, npx) and reads repository content through the packaging process.
  • Sanitization: While it includes a secret scanner (Secretlint) to identify and exclude credentials, it does not include sanitization for natural language instructions embedded in the ingested code.
  • [COMMAND_EXECUTION]: The script scripts/repomix_batch.py uses subprocess.run to execute the repomix CLI and npx tool.
  • Evidence: The _build_command method in scripts/repomix_batch.py constructs a command list from user-supplied repository paths or URLs, which is then executed via subprocess.run in the process_repository method.
  • Note: The script includes an environment variable loader that searches for .env files up to three directory levels above its location. This broad search pattern could inadvertently load and expose sensitive environment variables to the subprocess if the script is executed within a nested directory structure on the host machine.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:43 AM
Security Audit — agent-trust-hub — repomix