repomix-explorer
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill runs repomix against remote repositories (e.g., via
npx repomix@latest --remote <repo>and examples like--remote facebook/reactorExplore https://github.com/microsoft/vscode) and then reads/analyzes the generated output, which clearly ingests untrusted, user-generated content from public third‑party sites.
Audit Metadata