NYC

repomix-unmixer

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The described functionality matches the stated purpose (unpacking repomix files). The principal security concern is filesystem safety: documentation indicates brittle parsing (regex for XML) and lacks any mention of path sanitization or sandboxing, creating credible risk of path traversal and arbitrary file overwrite when processing untrusted repomix inputs. No network or credential-theft behaviors are described. Before running on untrusted data, obtain and review the actual scripts/unmix_repomix.py to confirm use of robust parsers and programmatic protections (normalize and constrain extracted paths, disallow absolute/parent-traversal entries, and implement safe overwrite semantics). Treat as suspicious until the code is verified.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:18 PM
Package URL
pkg:socket/skills-sh/daymade%2Fclaude-code-skills%2Frepomix-unmixer%2F@40df9661d6c63ffd7289054017ec460357d1f719