# locklens

> Use this tool when you need to identify vulnerabilities in package lockfiles for npm, yarn, and pnpm projects. It audits lockfiles via CLI or as an MCP server over stdio, providing outputs that highlight potential security risks. Ideal for developers and security teams seeking to ensure the integrity of their project dependencies.

Canonical page: https://skillsregistry.net/skills/barmplus-locklens  
JSON: https://api.skillsregistry.net/v1/skills/barmplus-locklens

## Description

Audits package lockfiles for vulnerabilities, supporting npm, yarn, and pnpm. Runs via CLI or as an MCP server over stdio.

## Trust

- **Trust score (0–1):** 0.69
- **Verification tier:** scanned
- **Last scanned:** 2026-09-03

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-03

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/co7qc8ypsr)
- **Repository:** <https://github.com/BARMPlus/locklens>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "barmplus-locklens"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/barmplus-locklens` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/barmplus-locklens/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
