repomix

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill description is coherent with its stated purpose of repository packaging and AI-friendly context generation. It outlines standard installation paths, remote processing capabilities, and security-conscious features (Secretlint integration) without presenting suspicious or malicious behavior. The data flows are appropriate for a packaging/audit tool, and while remote processing introduces network considerations, there is no evidence of covert data exfiltration. Overall risk is low-to-moderate given the capability set, with emphasis on proper handling of sensitive outputs via .repomixignore and security checks.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:31 PM
Package URL
pkg:socket/skills-sh/mrgoonie%2Fxxxnaper%2Frepomix%2F@4ea05fc92a34ccf053cf10398ddb935305cdc915