ccc Semantic Code Search
cocoindex-io/cocoindex-code
Semantic code search and index management with the ccc CLI: the agent initializes, indexes and queries the project by concept, filtering by language or path.
Safely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing.
$ npx skills add daymade/claude-code-skills --skill repomix-safe-mixer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install daymade/claude-code-skills repomix-safe-mixer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/repomix-safe-mixer .claude/skills/repomix-safe-mixer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "repomix-safe-mixer" agent skill from https://github.com/daymade/claude-code-skills/tree/main/repomix-safe-mixer into .claude/skills/repomix-safe-mixer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repomix-safe-mixer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/daymade/claude-code-skills/tree/main/repomix-safe-mixerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add daymade/claude-code-skills --skill repomix-safe-mixer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install daymade/claude-code-skills repomix-safe-mixer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/repomix-safe-mixer .agents/skills/repomix-safe-mixer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "repomix-safe-mixer" agent skill from https://github.com/daymade/claude-code-skills/tree/main/repomix-safe-mixer into .agents/skills/repomix-safe-mixer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repomix-safe-mixer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add daymade/claude-code-skills --skill repomix-safe-mixer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install daymade/claude-code-skills repomix-safe-mixer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/repomix-safe-mixer .cursor/skills/repomix-safe-mixer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "repomix-safe-mixer" agent skill from https://github.com/daymade/claude-code-skills/tree/main/repomix-safe-mixer into .cursor/skills/repomix-safe-mixer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repomix-safe-mixer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/daymade/claude-code-skills.git --path repomix-safe-mixer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add daymade/claude-code-skills --skill repomix-safe-mixer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install daymade/claude-code-skills repomix-safe-mixer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/repomix-safe-mixer .gemini/skills/repomix-safe-mixer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "repomix-safe-mixer" agent skill from https://github.com/daymade/claude-code-skills/tree/main/repomix-safe-mixer into .gemini/skills/repomix-safe-mixer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repomix-safe-mixer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install daymade/claude-code-skills repomix-safe-mixerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add daymade/claude-code-skills --skill repomix-safe-mixer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/repomix-safe-mixer .github/skills/repomix-safe-mixer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "repomix-safe-mixer" agent skill from https://github.com/daymade/claude-code-skills/tree/main/repomix-safe-mixer into .github/skills/repomix-safe-mixer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repomix-safe-mixer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add daymade/claude-code-skills --skill repomix-safe-mixer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install daymade/claude-code-skills repomix-safe-mixer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/repomix-safe-mixer .opencode/skills/repomix-safe-mixer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "repomix-safe-mixer" agent skill from https://github.com/daymade/claude-code-skills/tree/main/repomix-safe-mixer into .opencode/skills/repomix-safe-mixer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "repomix-safe-mixer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
repomix-safe-mixerSafely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing.
Repomix Safe Mixer is an agent skill from daymade/claude-code-skills. Safely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing. Use when packaging code for distribution, creating reference packages, or when the user mentions security concerns about sharing code with repomix.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/common_secrets.md`, `scripts/safe_pack.py` and `scripts/scan_secrets.py`).
It sits in Agent Workflows, covering Codebase knowledge for agents. The repository describes itself as: Professional Claude Code skills marketplace featuring production-ready skills for enhanced development workflows. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 872127b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
API_KEYVITE_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Repomix Safe Mixer loads about 2k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 539 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
# 1. Copy this file to .env# 3. Never commit .env to version controlAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from daymade/claude-code-skills at commit 872127b, republished under its MIT licence (© daymade). 539 words, ~1,957 tokens.
.claude/skills/repomix-safe-mixer/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Safely package codebases with repomix by automatically detecting and removing hardcoded credentials.
This skill prevents accidental credential exposure when packaging code with repomix. It scans for hardcoded secrets (API keys, database credentials, tokens), reports findings, and ensures safe packaging.
When to use: When packaging code with repomix for distribution, creating shareable reference packages, or whenever security concerns exist about hardcoded credentials in code.
Use safe_pack.py from this skill's scripts/ directory for the complete workflow: scan → report → pack.
python3 scripts/safe_pack.py <directory>What it does:
Example:
python3 scripts/safe_pack.py ./my-projectOutput if clean:
🔍 Scanning ./my-project for hardcoded secrets...
✅ No secrets detected!
📦 Packing ./my-project with repomix...
✅ Packaging complete!
Package is safe to distribute.Output if secrets found:
🔍 Scanning ./my-project for hardcoded secrets...
⚠️ Security Scan Found 3 Potential Secrets:
🔴 supabase_url: 1 instance(s)
- src/client.ts:5
Match: https://your-project-ref.supabase.co
❌ Cannot pack: Secrets detected!Custom output file:
python3 scripts/safe_pack.py \
./my-project \
--output package.xmlWith repomix config:
python3 scripts/safe_pack.py \
./my-project \
--config repomix.config.jsonExclude patterns from scanning:
python3 scripts/safe_pack.py \
./my-project \
--exclude '.*test.*' '.*\.example'Force pack (dangerous, skip scan):
python3 scripts/safe_pack.py \
./my-project \
--force # ⚠️ NOT RECOMMENDEDUse scan_secrets.py from this skill's scripts/ directory for scanning only (without packing).
python3 scripts/scan_secrets.py <directory>Use cases:
Example:
python3 scripts/scan_secrets.py ./my-projectJSON output for programmatic use:
python3 scripts/scan_secrets.py \
./my-project \
--jsonExclude patterns:
python3 scripts/scan_secrets.py \
./my-project \
--exclude '.*test.*' '.*example.*' '.*SECURITY_AUDIT\.md'The scanner detects common credential patterns including:
Cloud Providers:
AKIA...)API Keys:
sk_live_..., pk_live_...)sk-...)AIza...)Authentication:
eyJ...)-----BEGIN PRIVATE KEY-----)0x...)See references/common_secrets.md for complete list and patterns.
When secrets are found:
Examine each finding to verify it's a real credential (not a placeholder or example).
Before:
const SUPABASE_URL = "https://your-project-ref.supabase.co";
const API_KEY = "<hardcoded-anon-key-DO-NOT-COMMIT>";After:
const SUPABASE_URL = import.meta.env.VITE_SUPABASE_URL || "https://your-project-ref.supabase.co";
const API_KEY = import.meta.env.VITE_API_KEY || "your-api-key-here";
// Validation
if (!import.meta.env.VITE_SUPABASE_URL) {
console.error("⚠️ Missing VITE_SUPABASE_URL environment variable");
}# Example environment variables
VITE_SUPABASE_URL=https://your-project-ref.supabase.co
VITE_API_KEY=your-api-key-here
# Instructions:
# 1. Copy this file to .env
# 2. Replace placeholders with real values
# 3. Never commit .env to version controlRun scanner again to confirm secrets removed:
python3 scripts/scan_secrets.py ./my-projectOnce clean, package safely:
python3 scripts/safe_pack.py ./my-projectIf credentials were already exposed (e.g., committed to git, shared publicly):
The scanner skips common false positives:
Placeholders:
your-api-key, example-key, placeholder-value<YOUR_API_KEY>, ${API_KEY}, TODO: add keyTest/Example files:
.*test.*, .*example.*, .*sample.*Comments:
//, #, /*, *Environment variable references (correct usage):
process.env.API_KEYimport.meta.env.VITE_API_KEYDeno.env.get('API_KEY')Use --exclude to skip additional patterns if needed.
This skill works with standard repomix:
Default usage (no config):
python3 scripts/safe_pack.py ./projectWith repomix config:
python3 scripts/safe_pack.py \
./project \
--config repomix.config.jsonCustom output location:
python3 scripts/safe_pack.py \
./project \
--output ~/Downloads/package-clean.xmlThe skill runs repomix internally after security validation, passing through config and output options.
# Scan and pack in one command
python3 scripts/safe_pack.py \
~/workspace/my-project \
--output ~/Downloads/my-project-package.xml# Step 1: Scan to discover secrets
python3 scripts/scan_secrets.py ~/workspace/my-project
# Step 2: Review findings and replace credentials with env vars
# (Edit files manually or with automation)
# Step 3: Verify cleanup
python3 scripts/scan_secrets.py ~/workspace/my-project
# Step 4: Package safely
python3 scripts/safe_pack.py \
~/workspace/my-project \
--output ~/Downloads/my-project-clean.xml# Pre-commit hook: scan for secrets
python3 scripts/scan_secrets.py . --json
# Exit code 1 if secrets found (blocks commit)
# Exit code 0 if clean (allows commit)References:
references/common_secrets.md - Complete credential pattern catalogScripts:
scripts/scan_secrets.py - Standalone security scannerscripts/safe_pack.py - Complete scan → pack workflowRelated Skills:
repomix-unmixer - Extracts files from repomix packagesskill-creator - Creates new Claude Code skillsThis skill detects common patterns but may not catch all credential types. Always:
Not a replacement for: Secret scanning in CI/CD, git history scanning, or comprehensive security audits.
© daymade, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in repomix-safe-mixer of daymade/claude-code-skills.
Open the folder on GitHubat commit 872127b
Repomix Safe Mixer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Repomix Safe Mixer this skilldaymade/claude-code-skills | 1.4k | — | ~2k | Automated safety check: Notes | MIT | |
| ccc Semantic Code Searchcocoindex-io/cocoindex-code | 2.8k | — | ~938 | Automated safety check: Pass | Apache-2.0 | |
| Context Engineeringabashev/vfs-s3 | 106 | 9 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Repomix Codebase Packeryamadashy/repomix | 29k | — | ~1.3k | Automated safety check: Notes | MIT | |
| Codebase Handbook BuilderRuhan-Wang/Harness_Handbook | 333 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| CodemapJordanCoin/codemap | 704 | — | ~1.8k | Automated safety check: Pass | MIT |
cocoindex-io/cocoindex-code
Semantic code search and index management with the ccc CLI: the agent initializes, indexes and queries the project by concept, filtering by language or path.
abashev/vfs-s3
Optimizes agent context setup. An agent skill from abashev/vfs-s3.
yamadashy/repomix
Packs a local directory or remote GitHub repository into one AI-friendly file with Repomix, then searches it to explore structure, find patterns and count tokens.
Ruhan-Wang/Harness_Handbook
Generates, refreshes, validates and uses a compact handbook that maps where a change touches in a repository, using the active Codex session and no external LLM API.
JordanCoin/codemap
Gives an agent a quick map of a codebase's structure, dependencies, changes and handoffs, and tunes per-project config so the output stays code-first.
sopaco/deepwiki-rs
A skill your agent uses when an agent needs source code from the local repomix index under .terrain/agent/repomix.md (not committed; regenerate via Terrain scan).
daymade/claude-code-skills
This skill should be used when comparing two videos to analyze compression results or quality differences.
daymade/claude-code-skills
Generates professional animated CLI demos as GIFs using VHS terminal recordings.
daymade/claude-code-skills
Converts DOCX/PDF/PPTX and saved HTML/HTM to high-quality Markdown with automatic post-processing.
daymade/claude-code-skills
Generates several distinct, clickable HTML interaction prototypes for one product surface into a Design Board and collects selection/remix feedback before implementation.
daymade/claude-code-skills
Diagnoses and repairs repository setup and guarded Git workflows for Claude Code or Codex — environment repair, startup sync, hook auditing, collaborator handoff.
daymade/claude-code-skills
Pulls Bigdata.com (RavenPack) financial and news data via the official bigdata-client SDK and /v1/ REST endpoints — structured financials, prices, analyst estimates, entity-sentiment series…
Categories
Safely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing. Repomix Safe Mixer is an agent skill from daymade/claude-code-skills. Safely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing.
Repomix Safe Mixer fits situations like: packaging code for distribution; creating reference packages; the user mentions security concerns about sharing code with repomix.
Run `npx skills add daymade/claude-code-skills --skill repomix-safe-mixer -a claude-code`. Or copy the skill folder (repomix-safe-mixer in daymade/claude-code-skills) into .claude/skills/repomix-safe-mixer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add daymade/claude-code-skills --skill repomix-safe-mixer -a codex`. Or copy the skill folder (repomix-safe-mixer in daymade/claude-code-skills) into .agents/skills/repomix-safe-mixer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add daymade/claude-code-skills --skill repomix-safe-mixer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/repomix-safe-mixer, .gemini/skills/repomix-safe-mixer, .github/skills/repomix-safe-mixer and .opencode/skills/repomix-safe-mixer in your project.
Going by SKILL.md and its folder, Repomix Safe Mixer needs Python for the scripts in its folder, the command-line tools its instructions call (python3) and credentials named API_KEY and VITE_API_KEY. Our summary lists: Python 3; A credential in API_KEY; A credential in VITE_API_KEY.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Repomix Safe Mixer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Repomix Safe Mixer: ccc Semantic Code Search (cocoindex-io/cocoindex-code, 2.8k stars), Context Engineering (abashev/vfs-s3, 106 stars), Repomix Codebase Packer (yamadashy/repomix, 29k stars) and Codebase Handbook Builder (Ruhan-Wang/Harness_Handbook, 333 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
daymade (a GitHub user) maintains it in daymade/claude-code-skills, which has 1,447 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 9, 2026.
Source: daymade/claude-code-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.