Lokalise Incident RunbookSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-09Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: lokalise-incident-runbook description: 'Execute Lokalise incident response procedures with triage, mitigation, and postmortem. Use when responding to Lokalise-related outages, investigating errors, or running post-incident reviews for Lokalise integration failures. Trigger with phrases like "lokalise incident", "lokalise outage", "lokalise down", "lokalise on-call", "lokalise emergency", "translations broken". ' allowed-tools: Read, Grep, Bash(curl:*), Bash(lokalise2:*) version: 1.14.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - lokalise - incident-response compatibility: Designed for Claude Code --- # Lokalise Incident Runbook ## Overview Rapid-response procedures for Lokalise-related incidents in production. Covers quick diagnostics (API health, token validity, rate limit status), triage for five common failure modes (missing translations, stale translations, API outage, file upload failures, OTA failures), fallback to cached translations, and communication templates for stakeholder notification. Designed to be executed under pressure — each section is self-contained. ## Prerequisites - `curl` and `jq` available on the responder's machine - Production Lokalise API token accessible (from secret manager or break-glass procedure) - `LOKALISE_PROJECT_ID` known (check your deployment config or Lokalise dashboard) - Access to application logs (Datadog, CloudWatch, GCP Logging, or equivalent) - Incident communication channel (Slack, PagerDuty, or equivalent) ## Instructions ### Step 1: Quick Diagnostics (Run First) Execute these three checks immediately to narrow the problem scope. Copy-paste into your terminal: ```bash #!/bin/bash # incident-diagnostics.sh — Run all three checks in sequence set -uo pipefail : "${LOKALISE_API_TOKEN:?Set LOKALISE_API_TOKEN before running diagnostics}" : "${LOKALISE_PROJECT_ID:?Set LOKALISE_PROJECT_ID before running diagnostics}" echo "=== 1. Lokalise API Health ===" API_STATUS=$(curl -sf -o /dev/null -w "%{http_code}" \ "https://api.lokalise.com/api2/projects/${LOKALISE_PROJECT_ID}" \ -H "X-Api-Token: ${LOKALISE_API_TOKEN}") case "$API_STATUS" in 200) echo "API: HEALTHY (200 OK)" ;; 401) echo "API: AUTH FAILURE (401) — Token invalid or expired. Rotate immediately." ;; 403) echo "API: FORBIDDEN (403) — Token lacks permissions for this project." ;; 404) echo "API: NOT FOUND (404) — Check LOKALISE_PROJECT_ID value." ;; 429) echo "API: RATE LIMITED (429) — Throttled. Wait 10 seconds and retry." ;; 5*) echo "API: LOKALISE OUTAGE (${API_STATUS}) — Check https://status.lokalise.com" ;; 000) echo "API: UNREACHABLE — DNS/network issue. Check connectivity." ;; *) echo "API: UNEXPECTED (${API_STATUS}) — Investigate further." ;; esac echo "" echo "=== 2. Token Validity ===" TOKEN_CHECK=$(curl -sf "https://api.lokalise.com/api2/projects/${LOKALISE_PROJECT_ID}" \ -H "X-Api-Token: ${LOKALISE_API_TOKEN}" 2>/dev/null) if [[ $? -eq 0 ]]; then PROJECT_NAME=$(echo "$TOKEN_CHECK" | jq -r '.project.name') TEAM_ID=$(echo "$TOKEN_CHECK" | jq -r '.project.team_id') echo "Token: VALID" echo " Project: ${PROJECT_NAME}" echo " Team ID: ${TEAM_ID}" else echo "Token: INVALID or project inaccessible" echo " Action: Get a valid token from your secret manager or Lokalise dashboard" fi echo "" echo "=== 3. Rate Limit Status ===" RATE_RESPONSE=$(curl -sI "https://api.lokalise.com/api2/projects/${LOKALISE_PROJECT_ID}/keys?limit=1" \ -H "X-Api-Token: ${LOKALISE_API_TOKEN}" 2>/dev/null) RATE_LIMIT=$(echo "$RATE_RESPONSE" | grep -i "x-ratelimit-limit" | tr -d '\r' | awk '{print $2}') RATE_REMAINING=$(echo "$RATE_RESPONSE" | grep -i "x-ratelimit-remaining" | tr -d '\r' | awk '{print $2}') if [[ -n "$RATE_REMAINING" ]]; then echo "Rate limit: ${RATE_LIMIT:-6} req/sec" echo "Remaining: ${RATE_REMAINING} req/sec" if [[ "${RATE_REMAINING}" -eq 0 ]]; then echo "STATUS: EXHAUSTED — Wait 1 second for reset" else echo "STATUS: OK" fi else echo "Could not determine rate limit status" fi ``` ### Step 2: Triage Decision Tree Based on the diagnostics above, follow the appropriate path: | Symptom | Diagnostics Result | Go To | |---------|-------------------|-------| | Users see English instead of their language | API healthy, token valid | **Triage A: Missing Translations** | | Users see outdated translations | API healthy, token valid | **Triage B: Stale Translations** | | All translations fail to load | API returns 5xx | **Triage C: API Outage** | | CI upload fails | API returns 4xx on upload | **Triage D: File Upload Failures** | | App works but new keys show raw key names | API healthy, keys exist in Lokalise | **Triage A: Missing Translations** | ### Triage A: Missing Translations in Production **Likely causes:** New keys deployed before translations were uploaded, download step skipped in CI, locale file not included in build. ```bash # 1. Check if the key exists in Lokalise KEY_NAME="homepage.welcome_message" # Replace with the missing key curl -sf "https://api.lokalise.com/api2/projects/${LOKALISE_PROJECT_ID}/keys?filter_keys=${KEY_NAME}" \ -H "X-Api-Token: ${LOKALISE_API_TOKEN}" \ | jq '.keys[] | {key_name: .key_name.web, translations: [.translations[] | {locale: .language_iso, value: .translation}]}' # 2. Check if the locale file was included in the deployed build # (run on the production server or check the build artifact) ls -la /app/locales/ # Adjust path to your deployed locale directory cat /app/locales/de.json | jq ".$KEY_NAME" 2>/dev/null || echo "Key not found in deployed file" # 3. Quick fix: Re-download and redeploy lokalise2 file download \ --token "$LOKALISE_API_TOKEN" \ --project-id "$LOKALISE_PROJECT_ID" \ --format json \ --original-filenames=true \ --directory-prefix="" \ --export-empty-as=base \ --unzip-to "src/locales/" # Then trigger a redeploy ``` ### Triage B: Stale Translations **Likely causes:** Cache
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__lokalise-incident-runbook.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Lokalise Incident Runbook skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Lokalise Incident Runbook safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Lokalise Incident Runbook access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Lokalise Incident Runbook work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.