Lokalise Core Workflow BSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-09Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| cursor | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: lokalise-core-workflow-b description: 'Manage Lokalise secondary workflow: Download translations and integrate with app. Use when downloading translation files, exporting translations, or integrating Lokalise output into your application. Trigger with phrases like "lokalise download", "lokalise pull translations", "export lokalise", "get translations from lokalise". ' allowed-tools: Read, Write, Edit, Bash(lokalise2:*), Bash(npm:*), Grep version: 1.14.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - lokalise - workflow compatibility: Designed for Claude Code --- # Lokalise Core Workflow B ## Overview Everything on the "Lokalise to app" side: download translated files, manage translations and review status, leverage translation memory, manage contributors and their language access, and handle format differences across JSON, XLIFF, and PO files. ## Prerequisites - Lokalise API token exported as `LOKALISE_API_TOKEN` - Lokalise project ID exported as `LOKALISE_PROJECT_ID` - `@lokalise/node-api` installed for SDK examples - `lokalise2` CLI installed for CLI examples - `unzip` available for extracting download bundles ## Instructions 1. Download translated files. The download endpoint returns an S3 URL to a zip bundle — request the bundle, download the zip, then extract. **SDK — Download and extract:** ```typescript import { LokaliseApi } from "@lokalise/node-api"; import { execSync } from "node:child_process"; import { mkdirSync } from "node:fs"; const client = new LokaliseApi({ apiKey: process.env.LOKALISE_API_TOKEN! }); const PROJECT_ID = process.env.LOKALISE_PROJECT_ID!; // Request the download bundle const download = await client.files().download(PROJECT_ID, { format: "json", original_filenames: false, bundle_structure: "%LANG_ISO%.json", // Output: en.json, fr.json, de.json filter_langs: ["en", "fr", "de", "es"], // Only these languages export_empty_as: "base", // Use base language for empty translations include_tags: ["release-3.0"], // Only keys with this tag replace_breaks: false, }); const bundleUrl = download.bundle_url; console.log(`Bundle URL: ${bundleUrl}`); // Download and extract mkdirSync("./locales", { recursive: true }); execSync(`curl -sL "${bundleUrl}" -o /tmp/lokalise-bundle.zip`); execSync(`unzip -o /tmp/lokalise-bundle.zip -d ./locales`); console.log("Translations extracted to ./locales/"); ``` **CLI — Download with structure:** ```bash set -euo pipefail lokalise2 --token "$LOKALISE_API_TOKEN" file download \ --project-id "$LOKALISE_PROJECT_ID" \ --format json \ --original-filenames=false \ --bundle-structure "locales/%LANG_ISO%.json" \ --filter-langs "en,fr,de,es" \ --export-empty-as base \ --replace-breaks=false \ --unzip-to . ``` **SDK — Download with original file structure preserved:** ```typescript const download = await client.files().download(PROJECT_ID, { format: "json", original_filenames: true, directory_prefix: "", // No extra prefix export_empty_as: "skip", // Omit untranslated keys include_comments: false, include_description: false, }); ``` 1. Manage translations — list, update, and mark as reviewed. **SDK — List translations for a language:** ```typescript const frTranslations = await client.translations().list({ project_id: PROJECT_ID, filter_lang_id: 673, // Language ID for French (find via languages endpoint) filter_is_reviewed: 0, // Only unreviewed limit: 100, }); for (const t of frTranslations.items) { console.log(`[${t.key_id}] ${t.translation} (reviewed: ${t.is_reviewed})`); } ``` **SDK — Update a translation:** ```typescript const updated = await client.translations().update(TRANSLATION_ID, { project_id: PROJECT_ID, translation: "Nouvelle traduction", is_reviewed: false, // Mark as needing review after edit }); ``` **SDK — Mark translations as reviewed (batch):** ```typescript const unreviewed = await client.translations().list({ project_id: PROJECT_ID, filter_lang_id: LANG_ID, filter_is_reviewed: 0, limit: 500, }); for (const t of unreviewed.items) { await client.translations().update(t.translation_id, { project_id: PROJECT_ID, is_reviewed: true, }); } console.log(`Marked ${unreviewed.items.length} translations as reviewed`); ``` **SDK — List translations with cursor pagination (for large datasets):** ```typescript async function* paginateTranslations( client: LokaliseApi, projectId: string, langId: number ) { let cursor: string | undefined; do { const params: Record<string, unknown> = { project_id: projectId, filter_lang_id: langId, limit: 500, }; if (cursor) params.cursor = cursor; const page = await client.translations().list(params); yield* page.items; cursor = page.hasNextCursor() ? page.nextCursor() : undefined; } while (cursor); } // Usage for await (const t of paginateTranslations(client, PROJECT_ID, 673)) { console.log(`${t.key_id}: ${t.translation}`); } ``` 1. Leverage translation memory (TM) for auto-suggestions based on previously translated segments. **SDK — Use TM during upload:** ```typescript const tmResults = await client.translationProviders().list({ team_id: TEAM_ID, }); // TM is automatically applied during file upload when `use_automations: true` const upload = await client.files().upload(PROJECT_ID, { data: base64Data, filename: "en.json", lang_iso: "en", use_automations: true, // Apply TM and MT suggestions automatically slashn_to_linebreak: true, }); ``` **SDK — Leverage TM during download (pre-translate empty keys):** ```typescript // Pre-translate uses TM + MT before download // First, trigger pre-translation // Then download with filled translations const download = await client.files().download(PROJECT_ID, { format: "json", original_filenames: false, bundle_structure: "
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__lokalise-core-workflow-b.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Lokalise Core Workflow B skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Lokalise Core Workflow B safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Lokalise Core Workflow B access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Lokalise Core Workflow B work with?
Its documentation mentions claude-code and cursor. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.