Safely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing. Use when packaging code for distribution, creating reference packages, or when the user mentions security concerns about sharing code with repomix.
89
85%
Does it follow best practices?
Impact
96%
1.81xAverage score across 3 eval scenarios
Risky
Do not use without reviewing
Safe packaging with options
Uses safe_pack.py
0%
100%
Python3 invocation
0%
100%
Output flag used
100%
100%
Config flag used
100%
100%
No --force flag
100%
100%
Pack script exists
100%
100%
Secret cleanup and remediation
Env var substitution
100%
100%
Supabase URL removed
100%
100%
Stripe key removed
100%
100%
.env.example created
100%
100%
Env var validation
0%
0%
Re-scan before pack
0%
100%
Uses safe_pack.py
0%
100%
No --force flag
100%
100%
Standalone secret scanning
Uses scan_secrets.py
0%
100%
Python3 invocation
0%
100%
JSON flag used
0%
100%
Exclude flag used
0%
100%
Correct exit codes
100%
100%
scan-results.json produced
100%
100%
4f0eae8
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.