# lockvet

> lockvet — matteo-sung-lockvet. Use this tool when you need to analyze and explain changes in lockfiles, identifying potential issues such as version bumps, vulnerabilities, and integrity tampering across 61 formats. It solves problems related to dependency management and security in CI/CD pipelines, providing outputs in various formats to inform decision-making. It takes lockfile changes as input and provides detailed explanations and alerts as output, making it ideal for use in Git-based workflows and CI/CD pipelines.

Canonical page: https://skillsregistry.net/skills/matteo-sung-lockvet  
JSON: https://api.skillsregistry.net/v1/skills/matteo-sung-lockvet

## Description

Explain any lockfile change: bumps release-verified against 22 registries, vulns (OSV), ages, deprecations, typosquats, integrity tampering — 61 formats incl. pdm.lock, vcpkg, mise.lock, build.gradle, pom.xml, go.sum, GitHub Actions, GitLab CI, Dockerfiles, Kubernetes, Helm, SBOMs. CLI + CI gate + MCP server + playground. By an AI agent.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **License:** MIT
- **Updated:** 2026-09-25

## Source

- **Source listing:** [GitHub](https://github.com/matteo-sung/lockvet)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "matteo-sung-lockvet"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/matteo-sung-lockvet` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/matteo-sung-lockvet/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
