6 min read

Repomix: Pack a Whole Repo Into One File for AI (GitHub, Scanned)

Packs a codebase into one AI-friendly file with token counts, ready for Claude, ChatGPT or Gemini.

Repomix logo
✅
Scan: safe. Nothing to warn about. The secret hits are the test suite for Repomix's own secret filter, and the advisories in the CLI's lockfile are denial-of-service bugs in glob and URI parsing. Scanned Oct 3, 2026; the full report is below.

Repomix fixes a small, constant annoyance: getting a codebase into a chat window. Run it in a project folder and it writes repomix-output.xml, a single file with the directory tree and the contents of every file, ready to upload to Claude, ChatGPT, Gemini or any other model. It respects .gitignore, prints token counts per file and in total so you know whether the result fits a context window, and can write Markdown or plain text instead of XML.

The options go well beyond concatenation. --compress uses Tree-sitter to keep signatures and structure while dropping function bodies, cutting tokens; --remote packs a GitHub repository without cloning it yourself; --include and --ignore take glob patterns, and a list of files can be piped in. It runs Secretlint over everything and leaves out files that match known credential formats, and it can run as an MCP server so an agent can pack code on its own.

Repomix is MIT licensed, written in TypeScript by the developer yamadashy, and has about 28,700 stars. There is also a web version at repomix.com, and Chrome and Firefox extensions that add a Repomix button to GitHub repository pages.

  • Repository: github.com/yamadashy/repomix
  • Licence: MIT (MIT License)
  • Language: TypeScript. Stars: 28.7K. Forks: 1,561. Last push: Oct 3, 2026.
  • Scan: safe, Oct 3, 2026, commit 8d64291

Who it is for

Anyone who asks AI models about code too big to paste in one go: developers after a review or refactoring plan for a whole project, people exploring an unfamiliar repository, and anyone working in a chat interface rather than an IDE agent.

Getting started

1. Run it in any project folder, no install needed

npx repomix@latest

2. Or install it for repeated use (Homebrew, yarn and bun also work)

npm install -g repomix

3. Pack a GitHub repository without cloning it

repomix --remote yamadashy/repomix

4. Shrink the output to signatures and structure

repomix --compress

Look at the output before uploading it anywhere. Secretlint catches files that match known credential formats, not every secret, and the packed file is your whole codebase in one place. In MCP mode the server can read any path your user can, unless you start it with --sandbox.

Safety scan

We cloned yamadashy/repomix at commit 8d64291 on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No bare-IP URLs or committed binaries across 1,182 files and about 148,000 lines, half of it documentation in many languages. The four secret hits are in tests/core/security/workers/securityCheckWorker.test.ts: a fake GitHub token, Slack tokens and a private key that exist to prove Secretlint catches them.
  • The one pattern hit is the devcontainer Dockerfile installing Claude Code with its official curl | bash installer, for contributors who develop inside the container. Install hooks are a build step on prepare and the browser extension's wxt prepare.
  • The CLI's package-lock.json pins 404 packages with five advisories (3 high, 2 moderate), all denial-of-service bugs in brace-expansion, braces and fast-uri, triggered by malicious glob patterns or URLs rather than by code you pack. The other 20 sit in the repomix.com website's client and server and the browser extension, mostly undici, Vite and markdown-it.
  • Remote packing clones the repository you name into a temporary folder and only reads it. The MCP server can read any path your user can unless you start it with --sandbox, which the README explains.
  • 21 workflows. The single pull_request_target one, jev-pr-labeler.yml, has no permissions by default, never checks out the PR and only asks the API for the changed-file list. 24 of 28 third-party actions are pinned to commits. Security policy, CodeQL, Renovate, licence, contributing guide and code of conduct present.

What the scanner counted

CheckResult
Secrets4 candidates found and read; see the notes above.
Suspicious code1 pattern hit found and read; every one is listed under the raw findings.
Install-time code2 npm lifecycle scripts
Committed binariesNone.
CI workflows21 workflows. 1 uses pull_request_target, none check out the pull request head. 4 of 28 third-party actions pinned to a tag rather than a commit.
Network hosts40 distinct hosts referenced from source; most often github.com, gitlab.com, discord.gg, chromewebstore.google.com. No URLs to bare IP addresses.
Known vulnerabilities25 advisories across 1,225 pinned packages: 0 critical, 9 high, 13 moderate, 3 low. browser/package-lock.json: 293 packages, 1 advisories; package-lock.json: 404 packages, 5 advisories; scripts/memory/package-lock.json: 25 packages, 0 advisories; website/client/package-lock.json: 716 packages, 23 advisories; website/server/package-lock.json: 372 packages, 5 advisories.
Project hygieneHas security policy, automated dependency updates, CodeQL, licence file, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Secret candidates (4, redacted)
WhereRuleMatch
tests/core/security/workers/securityCheckWorker.test.ts:16github-tokenghp_wW…NUx (40 chars)
tests/core/security/workers/securityCheckWorker.test.ts:23slack-tokenxoxa-2…103 (30 chars)
tests/core/security/workers/securityCheckWorker.test.ts:24slack-tokenxoxb-2…103 (30 chars)
tests/core/security/workers/securityCheckWorker.test.ts:29private-key-----B…--- (31 chars)
Pattern hits (1)
WhereRuleMatch
.devcontainer/Dockerfile:99download-piped-to-shellRUN curl -fsSL https://claude.ai/install.sh | bash
npm lifecycle scripts (2)
  • browser/package.json prepare: wxt prepare
  • package.json prepare: npm run build
Worst known vulnerabilities (24 of 25)
AdvisorySeverityPackageSummary
GHSA-2v37-7h3g-55p8highnanoid@3.3.16nanoid: custom generators can loop indefinitely when size is zero
GHSA-6j4f-fj2g-mc7phighbrace-expansion@5.0.9brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-qhr7-859c-m2p7highbrace-expansion@5.0.9brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-vfj7-8cjw-p6xmhighbraces@3.0.3braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
GHSA-6j4f-fj2g-mc7phighbrace-expansion@2.1.4brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-qhr7-859c-m2p7highbrace-expansion@2.1.4brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-rfgv-xxqx-mfg5highundici@7.29.0undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
GHSA-w293-vg96-wgc3highundici@7.29.0undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
GHSA-fx2h-pf6j-xcffhighvite@5.4.21vite: `server.fs.deny` bypass on Windows alternate paths
GHSA-q2hr-2g5m-vwhrmoderatebrace-expansion@5.0.9brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
GHSA-hrr3-gc8f-f4qjmoderatefast-uri@3.1.7fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
GHSA-2g4f-4pwh-qvx6moderateajv@8.17.1ajv has ReDoS when using `$data` option
GHSA-q2hr-2g5m-vwhrmoderatebrace-expansion@2.1.4brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
GHSA-67mh-4wv8-2f99moderateesbuild@0.21.5esbuild enables any website to send any requests to the development server and read the response
GHSA-253c-mchw-3w2rmoderatemarkdown-it@14.2.0markdown-it linkify: true has two quadratic paths, so a few hundred KB of markdown blocks the event loop for tens of sec…
GHSA-2jfj-6hjv-fm6jmoderateundici@7.29.0undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
GHSA-3wwx-pv8p-q78vmoderateundici@7.29.0undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
GHSA-3xpg-4rpp-hhhmmoderateundici@7.29.0undici vulnerable to Denial of Service via unbounded decompression of compressed responses
GHSA-pmjh-fq2x-6v4xmoderateundici@7.29.0undici vulnerable to Denial of Service via orphaned RetryHandler response body
GHSA-rx4f-c7p8-82vqmoderateundici@7.29.0undici vulnerable to Denial of Service via WebSocketStream unclean close
GHSA-4w7w-66w2-5vf9moderatevite@5.4.21Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
GHSA-v6wh-96g9-6wx3moderatevite@5.4.21launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
GHSA-2gqq-gqf2-x968lowundici@7.29.0undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
GHSA-8436-99hf-9mmvlowundici@7.29.0undici vulnerable to caching and replay of unsafe HTTP method responses
Workflows worth a look

By the numbers

Stars28.7K
Forks1,561
Contributors84
Commits4,619
Open issues111
Open pull requests39
Releases102
Latest releasev1.18.1
LicenceMIT
Main languageTypeScript
Project age2 years
Last pushOct 3, 2026
Tracked files1,182
Lines of code148K
Checkout size9 MB

Lines by language: Markdown 72K, TypeScript 62K, JSON 6,608, Vue 3,665, YAML 2,592, JavaScript 622.

Questions

Is Repomix free?

Yes. It is MIT licensed and free, as are the repomix.com web version and the browser extensions. It makes no model calls of its own; you paste or upload the output to whichever AI service you already use.

Will Repomix put my API keys in the output?

It tries not to. Secretlint scans every file and leaves out those that match known credential formats, and anything listed in .gitignore is skipped. Neither is a guarantee, so for private code skim the file list Repomix prints and use --ignore for anything sensitive.

Does Repomix work on large repositories?

It packs them, but the result can exceed a model's context window. The token counts show which files are heaviest, --compress, --include and --ignore trim the output, and --split-output breaks it into several files.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.