{"slug": "lockvet-io-github-matteo-sung-lockvet-0-6-14", "title": "lockvet (io.github.matteo-sung/lockvet@0.6.14)", "summary": "Lockvet v0.6.14, an MCP server that explains lockfile and workflow-pin changes across 61 formats, was published to the official MCP registry on 2026-09-02, according to mcpindex.ai. The server, distributed as Docker image ghcr.io/matteo-sung/lockvet:0.6.14, passed a semantic screen with no manipulation pattern found, but the deterministic conformance probe has not yet been run.", "body_md": "[← Index](/leaderboard)\n\n# lockvet\n\nExplain any lockfile or workflow-pin change: bumps, vulns, ages, deprecations — 61 formats\n\nThe current version, v0.6.14, was published to the official MCP registry on 2026-09-02. It is distributed as the Docker image ghcr.io/matteo-sung/lockvet:0.6.14, filed under Other by this index, and declares 5 environment variables. Removals and unreachable sources are measured across every server this index tracks, contract drift across the servers that answer in consecutive snapshots; [the index's current counts](/stats) put this record in context.\n\n## Using lockvet in Claude, Cursor, Gemini CLI, Cline, or Zed?\n\nMCP tool contracts can change remotely with no version bump. The mcpindex gate pins each contract and **HOLDs the call** when it drifts-before your agent acts. Zero credentials. This is not the package install for this server itself (use **Install this server** for that).\n\nRewrites your MCP host config so each server launches behind the gate. Inspect first: curl -fsSL https://mcpindex.ai/install.sh | less\n\n```\nuv tool install mcpindex-gate && mcpindex-config-wire\n```\n\n[method](/methodology)\n\nSemantic screen found no manipulation pattern in the description. Conformance probe not yet run.\n\n`mcpindex.integrity.description`\n\npassINFOevidence“No malicious instructions found”via static_description\n\n- - Semantic screen only - the deterministic conformance probe has not run on this server\n- - Confidence is reported but not yet calibrated (v1)\n- - Screen reads the tool description, not the live behavior\n- - advisory\n- - registry description only no input schema\n- - screen model 8b\n- - The registry listing (version, packages, links) changed after this screen ran - the description we assessed did not\n\nSemantic screen: an LLM judge reads the tool description for hidden instructions (status PARTIAL). A pass means the description is not lying, not that the tool is safe: a high-capability tool with an honest description still warrants caution. The deterministic conformance probe has not been run on this server yet, so the screen here is semantic-only. Posture: advisory. Confidences are reported but not yet calibrated (calibrated=false at v1). Full verdict history is not shown on this page.\n\nOwn this server? [Screen its description →](/screen)\n\n## That verdict was true at screening time (snapshot 2026-09-02).\n\nContracts can change after screening, with no version bump. The gate pins lockvet’s tool contracts on first sight and holds any silent change before your agent acts - the check that keeps being true on Tuesday.\n\n[See your first HOLD in 2 minutes →](/guides/install-the-gate-first-hold)\n\nRelated: [how to trust an MCP server](/guides/how-to-trust-an-mcp-server) · [screen before install](/guides/screen-mcp-server-before-install) · [silent contract drift](/guides/mcp-silent-contract-drift)\n\nPeople vet a server before wiring it in. One line on your project site or docs answers that with an independent record: screening verdict, registry provenance, contract drift history. It stays current as new screens and drift events land.\n\n```\n[Independent trust record for lockvet](https://mcpindex.ai/server/io-github-matteo-sung-lockvet) - screening verdict, registry provenance, and contract drift monitoring.\n<a href=\"https://mcpindex.ai/server/io-github-matteo-sung-lockvet\">Independent trust record for lockvet</a> - screening verdict, registry provenance, and contract drift monitoring.\n```\n\nA live verdict badge for your README or listing. It reflects the current screen, links back here, and updates when the verdict does.\n\n```\n[![mcpindex](https://mcpindex.ai/api/v1/badge/io-github-matteo-sung-lockvet)](https://mcpindex.ai/server/io-github-matteo-sung-lockvet)\n<a href=\"https://mcpindex.ai/server/io-github-matteo-sung-lockvet\"><img src=\"https://mcpindex.ai/api/v1/badge/io-github-matteo-sung-lockvet\" alt=\"mcpindex verdict\" height=\"20\" /></a>\n```\n\n`GITHUB_TOKEN`\n\nGitHub token — private repos and higher API rate limits for vet_url/queue\n\n`GITLAB_TOKEN`\n\nGitLab token (read_api) — private projects and self-hosted instances\n\n`BITBUCKET_TOKEN`\n\nBitbucket Cloud access token or app password — private repos, workspace queue scans\n\n`GITEA_TOKEN`\n\nGitea/Forgejo/Codeberg token — private repos\n\n`AZURE_DEVOPS_TOKEN`\n\nAzure DevOps PAT (Code: Read) — private projects\n\n[methodology](/methodology)\n\n[AgentRoamai.agentroam/agentroam](/server/ai-agentroam-agentroam)\n\nBuy travel eSIMs, gift cards and mobile top-ups with crypto — user confirms before any order.\n\n[Authoryzeai.authoryze/authoryze](/server/ai-authoryze-authoryze)\n\nGive your AI agent a spending limit: approval controls and single-use virtual cards.\n\n[Espresso MCPio.github.mattgierhart/espresso-mcp](/server/io-github-mattgierhart-espresso-mcp)\n\nFind great espresso cafes worldwide with curated data and transparent quality scoring.", "url": "https://wpnews.pro/news/lockvet-io-github-matteo-sung-lockvet-0-6-14", "canonical_source": "https://mcpindex.ai/server/io-github-matteo-sung-lockvet", "published_at": "2026-09-02 00:02:08+00:00", "updated_at": "2026-09-02 00:22:51.768261+00:00", "lang": "en", "topics": ["developer-tools"], "entities": ["lockvet", "mcpindex.ai", "ghcr.io/matteo-sung/lockvet:0.6.14"], "alternates": {"html": "https://wpnews.pro/news/lockvet-io-github-matteo-sung-lockvet-0-6-14", "markdown": "https://wpnews.pro/news/lockvet-io-github-matteo-sung-lockvet-0-6-14.md", "text": "https://wpnews.pro/news/lockvet-io-github-matteo-sung-lockvet-0-6-14.txt", "jsonld": "https://wpnews.pro/news/lockvet-io-github-matteo-sung-lockvet-0-6-14.jsonld"}}