repomix
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The
EnvLoaderclass inscripts/repomix_batch.pysearches for and reads sensitive.envfiles from multiple hierarchical locations, including parent directories such as.claude/andskills/. This behavior allows the skill to load potentially sensitive credentials into the process environment. - [COMMAND_EXECUTION]: The script
scripts/repomix_batch.pyexecutes shell commands via thesubprocess.runfunction to invoke therepomixandnpxtools using repository paths and configuration arguments provided by the user. - [EXTERNAL_DOWNLOADS]: The skill facilitates the download and processing of remote repository content from external sources (e.g., GitHub) through the
npx repomix --remotecommand functionality. - [INDIRECT_PROMPT_INJECTION]: By packaging entire codebases for AI consumption, the skill creates an attack surface for indirect prompt injection. Malicious instructions hidden in a repository's files could be included in the output and interpreted by an LLM.
- Ingestion points: Local and remote repository paths provided as arguments or via a JSON configuration file in
scripts/repomix_batch.py. - Boundary markers: The tool uses structured output formats (XML, Markdown, JSON) that include file separators to delimit repository content.
- Capability inventory: The skill has the capability to execute shell commands (
subprocess.runinscripts/repomix_batch.py) and perform file system read/write operations. - Sanitization: The tool implements a default security check using Secretlint to identify and warn about hardcoded secrets within the repositories being processed.
Audit Metadata