Lokalise Local Dev LoopSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-09Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: lokalise-local-dev-loop description: 'Configure Lokalise local development with file sync and hot reload. Use when setting up a development environment, configuring translation sync, or establishing a fast iteration cycle with Lokalise. Trigger with phrases like "lokalise dev setup", "lokalise local development", "lokalise dev environment", "develop with lokalise", "lokalise sync". ' allowed-tools: Read, Write, Edit, Bash(npm:*), Bash(pnpm:*), Bash(lokalise2:*), Grep version: 1.14.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - lokalise - lokalise-local compatibility: Designed for Claude Code --- # Lokalise Local Dev Loop ## Overview Set up a complete local development workflow with Lokalise: project structure for i18n files, CLI push/pull commands, file watching for auto-upload, mock translations for offline development, framework integration (React i18next, Vue i18n), and a pre-commit hook to keep translations synced. ## Prerequisites - Lokalise API token exported as `LOKALISE_API_TOKEN` - Lokalise project ID exported as `LOKALISE_PROJECT_ID` - Node.js 18+ with npm or pnpm - `lokalise2` CLI installed - Git (for pre-commit hook) ## Instructions 1. Set up the project directory structure for i18n files, compatible with Lokalise's `bundle_structure` and most i18n frameworks. ``` project-root/ ├── src/ │ └── locales/ │ ├── en.json # Base language (source of truth) │ ├── fr.json # Downloaded from Lokalise │ ├── de.json │ ├── es.json │ └── index.ts # Barrel export + type definitions ├── scripts/ │ ├── i18n-push.sh # Upload source to Lokalise │ ├── i18n-pull.sh # Download translations from Lokalise │ └── i18n-mock.ts # Generate mock translations ├── .env.local # LOKALISE_API_TOKEN, LOKALISE_PROJECT_ID └── package.json # i18n:push, i18n:pull, i18n:sync scripts ``` **Barrel export with type safety (`src/locales/index.ts`):** ```typescript import en from "./en.json"; // Type derived from base language — all other locales must match this shape export type TranslationKeys = typeof en; export const defaultLocale = "en" as const; export const supportedLocales = ["en", "fr", "de", "es"] as const; export type Locale = (typeof supportedLocales)[number]; export async function loadLocale(locale: Locale): Promise<TranslationKeys> { const mod = await import(`./${locale}.json`); return mod.default; } ``` 1. Create CLI push/pull scripts for the upload-translate-download cycle. **Push script (`scripts/i18n-push.sh`):** ```bash #!/usr/bin/env bash set -euo pipefail # Upload source language file to Lokalise lokalise2 --token "$LOKALISE_API_TOKEN" file upload \ --project-id "$LOKALISE_PROJECT_ID" \ --file ./src/locales/en.json \ --lang-iso en \ --replace-modified \ --include-path \ --detect-icu-plurals \ --poll \ --tag-inserted-keys \ --tag-updated-keys echo "Source strings pushed to Lokalise" ``` **Pull script (`scripts/i18n-pull.sh`):** ```bash #!/usr/bin/env bash set -euo pipefail # Download all translations from Lokalise lokalise2 --token "$LOKALISE_API_TOKEN" file download \ --project-id "$LOKALISE_PROJECT_ID" \ --format json \ --original-filenames=false \ --bundle-structure "%LANG_ISO%.json" \ --export-empty-as base \ --export-sort a_z \ --replace-breaks=false \ --placeholder-format icu \ --unzip-to ./src/locales echo "Translations pulled to ./src/locales/" # Show what changed git diff --stat src/locales/ || true ``` **Package.json scripts:** ```json { "scripts": { "i18n:push": "bash scripts/i18n-push.sh", "i18n:pull": "bash scripts/i18n-pull.sh", "i18n:sync": "npm run i18n:push && npm run i18n:pull" } } ``` **Typical workflow:** ```bash # Edit source strings locally vim src/locales/en.json # Push changes to Lokalise npm run i18n:push # ... translators work in Lokalise UI ... # Pull completed translations npm run i18n:pull # Full round-trip npm run i18n:sync ``` 1. Set up watch mode to auto-upload source strings when `en.json` changes during development. ```typescript // scripts/i18n-watch.ts — run with: npx tsx scripts/i18n-watch.ts import { watch } from "node:fs"; import { execSync } from "node:child_process"; const SOURCE_FILE = "./src/locales/en.json"; let debounceTimer: ReturnType<typeof setTimeout> | null = null; function pushToLokalise() { console.log(`[${new Date().toISOString()}] Uploading ${SOURCE_FILE}...`); try { execSync("npm run i18n:push", { stdio: "inherit" }); console.log("Upload complete\n"); } catch (err) { console.error("Upload failed:", (err as Error).message); } } watch(SOURCE_FILE, (eventType) => { if (eventType !== "change") return; if (debounceTimer) clearTimeout(debounceTimer); debounceTimer = setTimeout(pushToLokalise, 2000); // 2s debounce }); console.log(`Watching ${SOURCE_FILE} for changes... (Ctrl+C to stop)`); ``` Add to package.json: ```json { "scripts": { "i18n:watch": "npx tsx scripts/i18n-watch.ts" } } ``` 1. Generate mock translations for offline development and layout testing. ```typescript // scripts/i18n-mock.ts import { readFileSync, writeFileSync, mkdirSync } from "node:fs"; const source: Record<string, string> = JSON.parse( readFileSync("./src/locales/en.json", "utf-8") ); // Pseudo-localization: wraps text in brackets and adds length function pseudoLocalize(text: string): string { // Preserve ICU placeholders like {name}, {count, plural, ...} return text.replace(/([^{}]+)/g, (match) => { const padded = match.replace(/[a-zA-Z]/g, (c) => { const base = c === c.toUpperCase() ? 65 : 97; return String.fromCharCode(((c.charCodeAt(0) - base + 13) % 26) + base); }); return `[${padded}]`; }); } // Generate longer text to test layout overflow function stretchLocalize(text: string): string { return `[${text}${"~".repeat(Math.ceil(text.lengt
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__lokalise-local-dev-loop.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Lokalise Local Dev Loop skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Lokalise Local Dev Loop safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Lokalise Local Dev Loop access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Lokalise Local Dev Loop work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.