Lockdown — DevOps skill for Claude Code
Per-repo supply-chain hardening — detects the package managers, Dockerfiles, and CI in use, then guides you through and applies install-time, deploy, and pipeline hardening for npm/pnpm, pip/uv, Docke.
How to install Lockdown
Installs to ~/.claude/skills/spardutti-claude-skills-lockdown/SKILL.md
mkdir -p ~/.claude/skills/spardutti-claude-skills-lockdown && curl -fsSL https://raw.githubusercontent.com/Spardutti/claude-skills/HEAD/commands/lockdown.md -o ~/.claude/skills/spardutti-claude-skills-lockdown/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Lockdown does
name: lockdown description: "Per-repo supply-chain hardening — detects the package managers, Dockerfiles, and CI in use, then guides you through and applies install-time, deploy, and pipeline hardening for npm/pnpm, pip/uv, Docker, and GitHub Actions" category: Workflow allowed-tools: Bash, Read, Edit, Write, Glob, Grep argument-hint: "[layer] optional — js | python | docker | ci; default runs every layer detected"
Lockdown — Supply-Chain Hardening
You are a supply-chain hardening gu
Alternatives in DevOps
- CI/CD Helper — CI/CD pipeline configuration and troubleshooting 2.6k ★
- Cccc — Coordinate your coding agents like a group chat — read receipts, delivery tracking, and remote ops from your p 1.1k ★
- Proxy — route Claude Code requests through multiple upstream providers (OpenCode Go, OpenCode Zen, and AWS Bedrock) wi 957 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Sandbox Shell
macOS Seatbelt sandbox CLI for developers. Protect credentials (SSH, AWS, GPG) from malicious npm packages, su
Harden Config
Deployment hardening step 5 — validate runtime/deploy config per target. Railway: railway.json/toml, healthche
Infra Context Arken
Create comprehensive Arken infrastructure documentation through a 5-phase process. Reads docker-compose.yml, n
Apply Framework
Apply OR update the framework on any one project. Detects framework-presence, shows a detailed value/risk asse
Skill Shipyard Pipeline
Skill Package 2026: Ultimate AI Skills Deployment Tool – Plugin, ZIP & CI/CD
CI Orchestrate
Orchestrate CI/CD pipeline fixes through parallel specialist agent deployment
Related Agents
Dependency Vetter
Supply-chain security audit of a third-party package (npm today) at ONE exact resolved version, run BEFORE it
Devsecops Reviewer
Infrastructure and CI/CD security reviewer — scans Terraform, Dockerfiles, Kubernetes manifests, GitHub Action
Dependency Auditor
Audit dependencies for vulnerabilities, outdated versions, and deprecations. C#/.NET first (dotnet list packag