Repomix fixes a small, constant annoyance: getting a codebase into a chat window. Run it in a project folder and it writes repomix-output.xml, a single file with the directory tree and the contents of every file, ready to upload to Claude, ChatGPT, Gemini or any other model. It respects .gitignore, prints token counts per file and in total so you know whether the result fits a context window, and can write Markdown or plain text instead of XML.
The options go well beyond concatenation. --compress uses Tree-sitter to keep signatures and structure while dropping function bodies, cutting tokens; --remote packs a GitHub repository without cloning it yourself; --include and --ignore take glob patterns, and a list of files can be piped in. It runs Secretlint over everything and leaves out files that match known credential formats, and it can run as an MCP server so an agent can pack code on its own.
Repomix is MIT licensed, written in TypeScript by the developer yamadashy, and has about 28,700 stars. There is also a web version at repomix.com, and Chrome and Firefox extensions that add a Repomix button to GitHub repository pages.
- Repository: github.com/yamadashy/repomix
- Licence: MIT (MIT License)
- Language: TypeScript. Stars: 28.7K. Forks: 1,561. Last push: Oct 3, 2026.
- Scan: safe, Oct 3, 2026, commit 8d64291
Who it is for
Anyone who asks AI models about code too big to paste in one go: developers after a review or refactoring plan for a whole project, people exploring an unfamiliar repository, and anyone working in a chat interface rather than an IDE agent.
Getting started
1. Run it in any project folder, no install needed
npx repomix@latest2. Or install it for repeated use (Homebrew, yarn and bun also work)
npm install -g repomix3. Pack a GitHub repository without cloning it
repomix --remote yamadashy/repomix4. Shrink the output to signatures and structure
repomix --compressLook at the output before uploading it anywhere. Secretlint catches files that match known credential formats, not every secret, and the packed file is your whole codebase in one place. In MCP mode the server can read any path your user can, unless you start it with --sandbox.
Safety scan
We cloned yamadashy/repomix at commit 8d64291 on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No bare-IP URLs or committed binaries across 1,182 files and about 148,000 lines, half of it documentation in many languages. The four secret hits are in tests/core/security/workers/securityCheckWorker.test.ts: a fake GitHub token, Slack tokens and a private key that exist to prove Secretlint catches them.
- The one pattern hit is the devcontainer Dockerfile installing Claude Code with its official curl | bash installer, for contributors who develop inside the container. Install hooks are a build step on prepare and the browser extension's wxt prepare.
- The CLI's package-lock.json pins 404 packages with five advisories (3 high, 2 moderate), all denial-of-service bugs in brace-expansion, braces and fast-uri, triggered by malicious glob patterns or URLs rather than by code you pack. The other 20 sit in the repomix.com website's client and server and the browser extension, mostly undici, Vite and markdown-it.
- Remote packing clones the repository you name into a temporary folder and only reads it. The MCP server can read any path your user can unless you start it with --sandbox, which the README explains.
- 21 workflows. The single pull_request_target one, jev-pr-labeler.yml, has no permissions by default, never checks out the PR and only asks the API for the changed-file list. 24 of 28 third-party actions are pinned to commits. Security policy, CodeQL, Renovate, licence, contributing guide and code of conduct present.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | 4 candidates found and read; see the notes above. |
| Suspicious code | 1 pattern hit found and read; every one is listed under the raw findings. |
| Install-time code | 2 npm lifecycle scripts |
| Committed binaries | None. |
| CI workflows | 21 workflows. 1 uses pull_request_target, none check out the pull request head. 4 of 28 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often github.com, gitlab.com, discord.gg, chromewebstore.google.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 25 advisories across 1,225 pinned packages: 0 critical, 9 high, 13 moderate, 3 low. browser/package-lock.json: 293 packages, 1 advisories; package-lock.json: 404 packages, 5 advisories; scripts/memory/package-lock.json: 25 packages, 0 advisories; website/client/package-lock.json: 716 packages, 23 advisories; website/server/package-lock.json: 372 packages, 5 advisories. |
| Project hygiene | Has security policy, automated dependency updates, CodeQL, licence file, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Secret candidates (4, redacted)
| Where | Rule | Match |
|---|---|---|
| tests/core/security/workers/securityCheckWorker.test.ts:16 | github-token | ghp_wW…NUx (40 chars) |
| tests/core/security/workers/securityCheckWorker.test.ts:23 | slack-token | xoxa-2…103 (30 chars) |
| tests/core/security/workers/securityCheckWorker.test.ts:24 | slack-token | xoxb-2…103 (30 chars) |
| tests/core/security/workers/securityCheckWorker.test.ts:29 | private-key | -----B…--- (31 chars) |
Pattern hits (1)
| Where | Rule | Match |
|---|---|---|
| .devcontainer/Dockerfile:99 | download-piped-to-shell | RUN curl -fsSL https://claude.ai/install.sh | bash |
npm lifecycle scripts (2)
browser/package.jsonprepare:wxt preparepackage.jsonprepare:npm run build
Worst known vulnerabilities (24 of 25)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-2v37-7h3g-55p8 | high | nanoid@3.3.16 | nanoid: custom generators can loop indefinitely when size is zero |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@5.0.9 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@5.0.9 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-vfj7-8cjw-p6xm | high | braces@3.0.3 | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@2.1.4 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@2.1.4 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-rfgv-xxqx-mfg5 | high | undici@7.29.0 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol |
| GHSA-w293-vg96-wgc3 | high | undici@7.29.0 | undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool |
| GHSA-fx2h-pf6j-xcff | high | vite@5.4.21 | vite: `server.fs.deny` bypass on Windows alternate paths |
| GHSA-q2hr-2g5m-vwhr | moderate | brace-expansion@5.0.9 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service |
| GHSA-hrr3-gc8f-f4qj | moderate | fast-uri@3.1.7 | fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets |
| GHSA-2g4f-4pwh-qvx6 | moderate | ajv@8.17.1 | ajv has ReDoS when using `$data` option |
| GHSA-q2hr-2g5m-vwhr | moderate | brace-expansion@2.1.4 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service |
| GHSA-67mh-4wv8-2f99 | moderate | esbuild@0.21.5 | esbuild enables any website to send any requests to the development server and read the response |
| GHSA-253c-mchw-3w2r | moderate | markdown-it@14.2.0 | markdown-it linkify: true has two quadratic paths, so a few hundred KB of markdown blocks the event loop for tens of sec… |
| GHSA-2jfj-6hjv-fm6j | moderate | undici@7.29.0 | undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches |
| GHSA-3wwx-pv8p-q78v | moderate | undici@7.29.0 | undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression |
| GHSA-3xpg-4rpp-hhhm | moderate | undici@7.29.0 | undici vulnerable to Denial of Service via unbounded decompression of compressed responses |
| GHSA-pmjh-fq2x-6v4x | moderate | undici@7.29.0 | undici vulnerable to Denial of Service via orphaned RetryHandler response body |
| GHSA-rx4f-c7p8-82vq | moderate | undici@7.29.0 | undici vulnerable to Denial of Service via WebSocketStream unclean close |
| GHSA-4w7w-66w2-5vf9 | moderate | vite@5.4.21 | Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling |
| GHSA-v6wh-96g9-6wx3 | moderate | vite@5.4.21 | launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows |
| GHSA-2gqq-gqf2-x968 | low | undici@7.29.0 | undici vulnerable to response truncation via oversized chunked responses in the dump interceptor |
| GHSA-8436-99hf-9mmv | low | undici@7.29.0 | undici vulnerable to caching and replay of unsafe HTTP method responses |
Workflows worth a look
- .github/workflows/jev-pr-labeler.yml: pull_request_target
By the numbers
| Stars | 28.7K |
|---|---|
| Forks | 1,561 |
| Contributors | 84 |
| Commits | 4,619 |
| Open issues | 111 |
| Open pull requests | 39 |
| Releases | 102 |
| Latest release | v1.18.1 |
| Licence | MIT |
| Main language | TypeScript |
| Project age | 2 years |
| Last push | Oct 3, 2026 |
| Tracked files | 1,182 |
| Lines of code | 148K |
| Checkout size | 9 MB |
Lines by language: Markdown 72K, TypeScript 62K, JSON 6,608, Vue 3,665, YAML 2,592, JavaScript 622.
Questions
Is Repomix free?
Yes. It is MIT licensed and free, as are the repomix.com web version and the browser extensions. It makes no model calls of its own; you paste or upload the output to whichever AI service you already use.
Will Repomix put my API keys in the output?
It tries not to. Secretlint scans every file and leaves out those that match known credential formats, and anything listed in .gitignore is skipped. Neither is a guarantee, so for private code skim the file list Repomix prints and use --ignore for anything sensitive.
Does Repomix work on large repositories?
It packs them, but the result can exceed a model's context window. The token counts show which files are heaviest, --compress, --include and --ignore trim the output, and --split-output breaks it into several files.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
