CtrlK
BlogDocsLog inGet started
Tessl Logo

repomix-safe-mixer

Safely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing. Use when packaging code for distribution, creating reference packages, or when the user mentions security concerns about sharing code with repomix.

69

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured skill body with executable commands, explicit validation checkpoints, and verified one-level-deep references. Its main weakness is redundancy: two later sections restate commands from earlier ones, and the secret-pattern catalog is duplicated between the body and the reference file.

Suggestions

Remove or collapse the 'Integration with Repomix' and 'Example Workflows' sections, which restate --config/--output usage and the scan-verify-pack cycle already covered in 'Options' and 'Handling Detected Secrets'.

Trim the 'Detected Secret Types' section to a short example or two and rely on references/common_secrets.md for the catalog, keeping the body a true overview.

Consolidate the post-exposure and security-note guidance, which overlaps in its 'rotate/monitor/audit' advice.

DimensionReasoningScore

Conciseness

Mostly efficient, but several sections are padded: "Integration with Repomix" and "Example Workflows" restate safe_pack.py/--config/--output invocations already shown in "Options" and "Handling Detected Secrets", and the inline secret-type list duplicates references/common_secrets.md. It is above 2 because the bulk of the body still carries real, non-obvious operational detail rather than explaining concepts Claude already knows.

3 / 5

Actionability

Every workflow is copy-paste executable: "python3 scripts/safe_pack.py ./my-project --output package.xml", "python3 scripts/scan_secrets.py ./my-project --json", with flags, expected outputs, and exit codes ("Exit code 1 if secrets found (blocks commit)") fully specified.

5 / 5

Workflow Clarity

The scan → report → block/pack sequence is explicit, and the "Handling Detected Secrets" steps include a real feedback loop: "Run scanner again to confirm secrets removed" followed by "Once clean, package safely", plus the scanner blocks packaging when secrets are found.

5 / 5

Progressive Disclosure

The body is a well-sectioned overview with a clearly signaled one-level-deep reference ("See references/common_secrets.md for complete list and patterns") that exists on disk, plus a Resources index of scripts and references. It misses 5 because the Detected Secret Types section inlines a catalog that largely belongs in the reference file.

4 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capabilities, an explicit 'Use when...' trigger clause with natural phrases, and a distinctive repomix-scoped niche. The only weakness is that a few natural trigger synonyms and downstream behaviors (reporting, blocking) go unmentioned.

DimensionReasoningScore

Specificity

The description names the domain (repomix packaging) and several concrete actions: "package codebases with repomix", "automatically detecting and removing hardcoded credentials before packing". It falls short of 5 because behaviors like reporting findings or blocking the pack are not covered, leaving minor gaps.

4 / 5

Completeness

It clearly answers what it does ("detecting and removing hardcoded credentials before packing" with repomix) and when to use it via an explicit "Use when packaging code for distribution, creating reference packages, or when the user mentions security concerns about sharing code with repomix" clause with concrete trigger phrases.

5 / 5

Trigger Term Quality

"packaging code for distribution", "creating reference packages", and "security concerns about sharing code with repomix" are natural phrases users would say. A few natural variations (e.g., "sharing code", "secrets", "credentials") are missing, so it matches the good-but-not-comprehensive anchor rather than 5.

4 / 5

Distinctiveness Conflict Risk

The repomix-specific framing ("package codebases with repomix", "sharing code with repomix") creates a clear niche with distinct triggers, minimal conflict risk with general secret-scanning or packaging skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
daymade/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.