Skip to main content

lokalise-incident-runbook

Facilitates rapid incident response for Lokalise outages, including triage, mitigation, and postmortem procedures.

Install this skill

or
40/100

Security score

The lokalise-incident-runbook skill was audited on Mar 3, 2026 and we found 24 security issues across 4 threat categories. Review the findings below before installing.

Categories Tested

Security Issues

medium line 78

Template literal with variable interpolation in command context

SourceSKILL.md
78```bash
medium line 39

Curl to non-GitHub URL

SourceSKILL.md
39curl -s https://api.lokalise.com/api2/system/health | jq
medium line 42

Curl to non-GitHub URL

SourceSKILL.md
42curl -s https://status.lokalise.com/api/v2/status.json | jq '.status.description'
medium line 50

Curl to non-GitHub URL

SourceSKILL.md
50curl -s https://your-app.com/health/lokalise | jq
medium line 111

Curl to non-GitHub URL

SourceSKILL.md
111curl -s https://status.lokalise.com/api/v2/status.json | jq
medium line 120

Curl to non-GitHub URL

SourceSKILL.md
120watch -n 60 'curl -s https://status.lokalise.com/api/v2/status.json | jq ".status.description"'
medium line 173

Curl to non-GitHub URL

SourceSKILL.md
173curl "http://prometheus:9090/api/v1/query_range?query=lokalise_errors_total&start=-2h" > metrics.json
medium line 261

Curl to non-GitHub URL

SourceSKILL.md
261curl -sf https://your-app.com/health/lokalise | jq '.status' || echo "UNHEALTHY"
medium line 32

Webhook reference - potential data exfiltration

SourceSKILL.md
32| P3 | Minor impact | < 4 hours | Webhook delays, non-critical translations missing |
low line 267

Access to .env file

SourceSKILL.md
267process.env.LOKALISE_FALLBACK_ENABLED = "true";
low line 270

Access to .env file

SourceSKILL.md
270const useFallback = process.env.LOKALISE_FALLBACK_ENABLED === "true";
low line 39

External URL reference

SourceSKILL.md
39curl -s https://api.lokalise.com/api2/system/health | jq
low line 42

External URL reference

SourceSKILL.md
42curl -s https://status.lokalise.com/api/v2/status.json | jq '.status.description'
low line 47

External URL reference

SourceSKILL.md
47"https://api.lokalise.com/api2/projects?limit=1"
low line 50

External URL reference

SourceSKILL.md
50curl -s https://your-app.com/health/lokalise | jq
low line 60

External URL reference

SourceSKILL.md
60├─ YES: Is https://status.lokalise.com showing incident?
low line 84

External URL reference

SourceSKILL.md
84"https://api.lokalise.com/api2/projects?limit=1" | jq '.projects[0].name // .error'
low line 96

External URL reference

SourceSKILL.md
96"https://api.lokalise.com/api2/projects" | grep -i "x-ratelimit"
low line 111

External URL reference

SourceSKILL.md
111curl -s https://status.lokalise.com/api/v2/status.json | jq
low line 120

External URL reference

SourceSKILL.md
120watch -n 60 'curl -s https://status.lokalise.com/api/v2/status.json | jq ".status.description"'
low line 173

External URL reference

SourceSKILL.md
173curl "http://prometheus:9090/api/v1/query_range?query=lokalise_errors_total&start=-2h" > metrics.json
low line 261

External URL reference

SourceSKILL.md
261curl -sf https://your-app.com/health/lokalise | jq '.status' || echo "UNHEALTHY"
low line 277

External URL reference

SourceSKILL.md
277- [Lokalise Status Page](https://status.lokalise.com)
low line 279

External URL reference

SourceSKILL.md
279- [Community Forum](https://community.lokalise.com)
Scanned on Mar 3, 2026
View Security Dashboard
Installation guide →