# i18n-codelens-mcp

Inspect, audit and safely edit i18n locale JSON files from AI agents.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 2.0.0
- **Author:** io.github.hepter
- **License:** MIT
- **npm:** i18n-codelens-mcp
- **Source:** https://github.com/hepter/i18n-codelens-mcp
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 29 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-06T05:54:19.182Z
- **Version scanned:** 2.0.0
- **CVEs:** none found by OSV at scan time

## Tools

10 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `i18n_project_info` — Locales, key format (plain or namespace:key), key counts, resolved config and warnings. Call once per session before other tools.
- `i18n_get_translations` — Values of specific keys in every (or selected) locale; null marks a missing translation. A key ending with '.' returns the whole namespace. Use includeValues:fa
- `i18n_search_keys` — Find keys by substring of the key or the translated text, optionally under a key prefix. Keys missing from some locales are marked with "in". Add includeValues 
- `i18n_file_keys` — Translation keys referenced in one source file and the locales that lack each of them. Run after editing a component to verify its copy is complete.
- `i18n_key_references` — Where keys are used in code, as path:line:column, with exact totals. Useful before renaming or deleting a key.
- `i18n_audit` — Project-wide health check: keys missing in some locale (vs the base locale), placeholder mismatches, keys used in code but untranslated, and keys never referenc
- `i18n_upsert_translations` — Create or update keys in one call, with a value per locale. Writes immediately and never deletes keys. An existing value that differs is reported as a conflict 
- `i18n_delete_keys` — Remove keys from all or selected locales. Previews by default; pass dryRun:false to delete (or confirm the dialog).
- `i18n_rename_key` — Rename a key across locales, or move a whole namespace when from ends with '.' (e.g. 'nav.' -> 'menu.'). Refuses when a target exists. Previews by default; pass
- `i18n_format_resources` — Normalize JSON formatting and sort keys (top level only for mixed files). Previews by default; pass dryRun:false to rewrite.

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"i18n-codelens\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"i18n-codelens-mcp\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs on your machine.
- Floor 36, ceiling 60 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/i18n-codelens-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/i18n-codelens-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/i18n-codelens-mcp
- HTML page: https://forgeregistry.com/registry/i18n-codelens-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
