Lockstep MCP runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 9 Aug 2026.
Local lockfile and package-manager reproducibility analysis without dependency details. Tools...
Today is the operative word: we check Lockstep MCP every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add lockstep-mcp -- npx -y @mrfentmen/lockstep-mcp
{
"mcpServers": {
"lockstep-mcp": {
"args": [
"-y",
"@mrfentmen/lockstep-mcp"
],
"command": "npx"
}
}
}
[mcp_servers.lockstep-mcp]
command = "npx"
args = ["-y", "@mrfentmen/lockstep-mcp"]
{
"mcpServers": {
"lockstep-mcp": {
"args": [
"-y",
"@mrfentmen/lockstep-mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"lockstep-mcp": {
"args": [
"-y",
"@mrfentmen/lockstep-mcp"
],
"command": "npx"
}
}
}
Summarize local dependency manifest and lockfile drift without returning package names,...
Local explanation of reproducibility signals and toolchain contradictions without exact versions...
Local build artifact size and dependency weight inspection without file content output. Tools...
npm registry MCP server — package intelligence, security audits, dependency analysis
Local aggregate test-history stability analysis without test names or raw result contents. Tools...
Dependency graph and blast-radius analysis for local TypeScript/JavaScript repos.
Repo analysis for coding agents with ranked files, dependency maps, and task-scoped context.
Summarize local license evidence and uncertainty without returning package names, license text,...
Answers built from our own checks of this server.