Lokalise Core Workflow ASAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-09Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: lokalise-core-workflow-a description: 'Execute Lokalise primary workflow: Upload source files and manage translation keys. Use when uploading translation files, creating/updating keys, or managing source strings in Lokalise projects. Trigger with phrases like "lokalise upload", "lokalise push keys", "lokalise source strings", "add translations to lokalise". ' allowed-tools: Read, Write, Edit, Bash(lokalise2:*), Bash(npm:*), Grep version: 1.14.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - lokalise - workflow compatibility: Designed for Claude Code --- # Lokalise Core Workflow A ## Overview Primary workflow covering the "source to Lokalise" direction: upload translation files, create and update keys programmatically, tag keys for organization, and perform bulk operations. Both SDK and CLI approaches shown for every operation. ## Prerequisites - Lokalise API token exported as `LOKALISE_API_TOKEN` - Lokalise project ID exported as `LOKALISE_PROJECT_ID` - `@lokalise/node-api` installed for SDK examples - `lokalise2` CLI installed for CLI examples - Source translation file(s) in a supported format (JSON, XLIFF, PO, YAML, etc.) ## Instructions 1. Upload source translation files. File upload is async: the API returns a process object that must be polled until completion. **SDK — Base64 encode and upload:** ```typescript import { LokaliseApi } from "@lokalise/node-api"; import { readFileSync } from "node:fs"; const client = new LokaliseApi({ apiKey: process.env.LOKALISE_API_TOKEN! }); const PROJECT_ID = process.env.LOKALISE_PROJECT_ID!; // Read and base64-encode the source file const fileContent = readFileSync("./locales/en.json"); const base64Data = fileContent.toString("base64"); const uploadProcess = await client.files().upload(PROJECT_ID, { data: base64Data, filename: "en.json", lang_iso: "en", replace_modified: true, // Overwrite changed translations distinguish_by_file: true, // Same key names in different files stay separate tags: ["source", "v2.1"], // Auto-tag uploaded keys }); console.log(`Upload queued: process ${uploadProcess.process_id}, status: ${uploadProcess.status}`); ``` **SDK — Poll upload process until complete:** ```typescript async function waitForUpload( client: LokaliseApi, projectId: string, processId: string, maxWaitMs = 60_000 ): Promise<void> { const start = Date.now(); while (Date.now() - start < maxWaitMs) { const proc = await client.queuedProcesses().get(processId, { project_id: projectId }); console.log(` Process ${processId}: ${proc.status}`); if (proc.status === "finished") return; if (proc.status === "cancelled" || proc.status === "failed") { throw new Error(`Upload ${proc.status}: ${JSON.stringify(proc.details)}`); } await new Promise((r) => setTimeout(r, 1000)); } throw new Error(`Upload timed out after ${maxWaitMs}ms`); } await waitForUpload(client, PROJECT_ID, uploadProcess.process_id); console.log("Upload complete"); ``` **CLI — Upload with polling:** ```bash set -euo pipefail lokalise2 --token "$LOKALISE_API_TOKEN" file upload \ --project-id "$LOKALISE_PROJECT_ID" \ --file ./locales/en.json \ --lang-iso en \ --replace-modified \ --distinguish-by-file \ --tag-inserted-keys \ --tag-updated-keys \ --tags "source,v2.1" \ --poll # Waits for process to finish ``` 1. Create keys programmatically when keys come from code scanning, CMS exports, or CI pipelines rather than file uploads. **SDK — Create keys with initial translations:** ```typescript const newKeys = await client.keys().create({ project_id: PROJECT_ID, keys: [ { key_name: { web: "onboarding.step1.title" }, platforms: ["web"], description: "First step of onboarding wizard", tags: ["onboarding", "v2.1"], translations: [ { language_iso: "en", translation: "Welcome aboard!" }, ], }, { key_name: { web: "onboarding.step1.body" }, platforms: ["web"], description: "Body text for onboarding step 1", tags: ["onboarding", "v2.1"], translations: [ { language_iso: "en", translation: "Let's get you set up in just a few steps." }, ], }, { key_name: { web: "errors.network_timeout" }, platforms: ["web"], description: "Shown when API call times out", is_hidden: false, tags: ["errors"], translations: [ { language_iso: "en", translation: "Connection timed out. Please try again." }, ], }, ], }); console.log(`Created ${newKeys.items.length} keys`); for (const k of newKeys.items) { console.log(` ${k.key_id}: ${k.key_name.web}`); } ``` **SDK — Update existing keys:** ```typescript const updatedKey = await client.keys().update(KEY_ID, { project_id: PROJECT_ID, description: "Updated description", tags: ["onboarding", "v2.2", "reviewed"], is_hidden: false, }); ``` 1. Tag keys for organization. Tags let you filter keys in the Lokalise UI and API — useful for release tracking, feature flags, and workflow status. **SDK — Add tags to existing keys (bulk):** ```typescript // List keys by an existing tag const v21Keys = await client.keys().list({ project_id: PROJECT_ID, filter_tags: "v2.1", limit: 500, }); // Bulk-update: add a new tag to all of them const keyIds = v21Keys.items.map((k) => k.key_id); const updated = await client.keys().bulk_update({ project_id: PROJECT_ID, keys: keyIds.map((id) => ({ key_id: id, tags: ["v2.1", "ready-for-review"], // Full tag list (replaces existing) })), }); console.log(`Tagged ${updated.items.length} keys with 'ready-for-review'`); ``` **SDK — Filter keys by tag:** ```typescript const errorKeys = await client.keys().list({ project_id: PROJECT_ID, filter_tags: "errors", include_translations: 1, limit: 100, }); for (const k of errorKeys.items) { const en = k.translations.find( (t: { language_iso:
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__lokalise-core-workflow-a.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Lokalise Core Workflow A skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Lokalise Core Workflow A safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Lokalise Core Workflow A access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Lokalise Core Workflow A work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.