repomix

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The EnvLoader class in scripts/repomix_batch.py searches for and reads sensitive .env files from multiple hierarchical locations, including parent directories such as .claude/ and skills/. This behavior allows the skill to load potentially sensitive credentials into the process environment.
  • [COMMAND_EXECUTION]: The script scripts/repomix_batch.py executes shell commands via the subprocess.run function to invoke the repomix and npx tools using repository paths and configuration arguments provided by the user.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and processing of remote repository content from external sources (e.g., GitHub) through the npx repomix --remote command functionality.
  • [INDIRECT_PROMPT_INJECTION]: By packaging entire codebases for AI consumption, the skill creates an attack surface for indirect prompt injection. Malicious instructions hidden in a repository's files could be included in the output and interpreted by an LLM.
  • Ingestion points: Local and remote repository paths provided as arguments or via a JSON configuration file in scripts/repomix_batch.py.
  • Boundary markers: The tool uses structured output formats (XML, Markdown, JSON) that include file separators to delimit repository content.
  • Capability inventory: The skill has the capability to execute shell commands (subprocess.run in scripts/repomix_batch.py) and perform file system read/write operations.
  • Sanitization: The tool implements a default security check using Secretlint to identify and warn about hardcoded secrets within the repositories being processed.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 05:16 AM
Security Audit — agent-trust-hub — repomix