Lockfile doctor
Offline deploy-safety skills for Claude Code. Zero credentials, zero network, zero dependencies.
npx -y skills add Starr-del/ShipSafe --skill lockfile-doctorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Diagnose package-manager and lockfile drift that causes 'works on my machine' deploy failures. Use whenever an install behaves differently in CI than locally, the user mentions lockfile conflicts, npm/pnpm/yarn confusion, 'npm ci failed', non-reproducible builds, or when auditing any Node project before deploy. Runs fully offline — no API keys, no network, no credentials.
SKILL.md
1.4 KB, as published. Nobody here has run it
lockfile-doctor
Part of shipsafe — offline deploy-safety skills. Every script is stdlib-only Python 3.8+; nothing leaves the machine.
python3 scripts/lockfile_doctor.py <project_root> [--json]
Checks: multiple coexisting lockfiles (platform picks one, devs use another), missing lockfile entirely, packageManager field disagreeing with the committed lockfile, missing engines.node, and fragile dependency specs — git branches, file: paths that won't exist on the build machine, and */latest wildcards.
The mental model to give the user: a deploy is reproducible only if the same package manager, same Node version, and same lockfile produce the same node_modules everywhere. Each finding is one of those three legs broken.
When MULTIPLE_LOCKFILES fires, help the user pick ONE manager (whichever the team actually uses), delete the other lockfiles, and gitignore them so they don't return.
Exit codes: 0 clean, 1 findings.
All paths below are relative to this skill's directory (lockfile-doctor/).