agent-lint
Server Details
Checks CLAUDE.md, AGENTS.md or a system prompt for 12 safeguards unattended agents need.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
TDQS
Scored across 1 tool
There is only one tool, so there is no possibility of misselection or overlap with a sibling. Its purpose—linting an agent rules file against safeguards—is stated explicitly and unambiguously.
A single tool named lint_rules_file follows a clean verb_noun snake_case convention that clearly signals action (lint) and target (rules_file). Nothing inconsistent to compare against.
One tool is thin for a linting server; the domain naturally suggests at least a companion for scanning a directory/repo or listing the 12 safeguards checked. Still, the single tool does earn its place and is not a trivial no-op, so this is borderline rather than a mismatch.
The core operation—checking one rules file's text for safeguards and leaked secrets—is fully covered, and the description is honest about its keyword-only limits. Minor gaps remain: no multi-file/glob scanning, no way to enumerate the safeguard rules, and no severity/exit-status reporting for CI use.
Available Tools
1 toollint_rules_fileLint an agent rules fileARead-onlyInspect
Check an agent rules file (CLAUDE.md, AGENTS.md, system prompt) for 12 safeguards an unattended agent needs (kill switch, spending limit, untrusted-input rule, secrets, memory, audit...). Keyword checks: they report what is written down, not what is enforced. Also flags live-looking API keys and hardcoded URLs/IDs that can go stale. Pass the file's text; nothing is stored.
| Name | Required | Description | Default |
|---|---|---|---|
| text | Yes | The full text of the rules file |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well past the readOnlyHint/openWorldHint annotations by disclosing two real behavioral traits: the checks are keyword-based and report what is written, not what is enforced (a genuine limitation), and nothing is stored (privacy/data-handling). It also specifies extra detections beyond the headline safeguards (live-looking API keys, stale URLs/IDs).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three dense sentences, front-loaded with the purpose, then the caveat about keyword checking, then the input/retention note. No filler or restated name.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a single-string, read-only lint tool without an output schema, the description supplies enough: what gets checked, the keyword-based nature of the verdict, and that input is not persisted. A brief sense of the report shape (per-safeguard pass/fail) would make it fully self-contained.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and the single 'text' parameter is fully documented there, so the description's 'Pass the file's text; nothing is stored' adds only marginal meaning. Baseline 3 applies when the schema carries the parameter semantics.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Names a specific verb (lint/check) and resource (agent rules file), then enumerates concrete targets: CLAUDE.md, AGENTS.md, system prompts, 12 safeguards like kill switch, spending limit, and secrets. An agent immediately knows what the tool inspects and what it produces.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The intended context is clear — bring a rules file's text to have it audited for unattended-agent safeguards — and the tool asserts itself as the only relevant one (no siblings). It does not state explicit preconditions or when-not to use it, keeping it short of a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- First observed
lint_rules_file
Related MCP Connectors
Static linter for CLAUDE.md-style agent constitution files: 10 operational-guardrail checks.
Static linter for CLAUDE.md-style agent constitution files: 10 operational-guardrail checks.
Research-backed linting + generation for agent context files (CLAUDE.md, AGENTS.md, Cursor rules).
Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.
Related MCP Servers
AlicenseNot gradedqualityCmaintenanceValidates AGENTS.md files against the cross-vendor coding-agent spec, detecting security smells and consistency issues.MITagent-guardprivate
AlicenseAqualityAmaintenanceSafety checks an agent runs before it acts — flags malicious packages, destructive shell commands, secret leaks, and web-backend holes before execution.8MIT- AlicenseAqualityBmaintenanceSecurity co-pilot for AI agents. Scans for vulnerabilities like prompt injection, infinite loops, and token bombing in AI Agents, audits MCP servers, verifies AGENTS.md governance, and generates EU AI Act compliance reports.1087 npm3Apache 2.0
- AlicenseNot gradedqualityBmaintenanceAudits AI agent skills for safety using static, semantic, adversarial, and supply-chain analysis, providing scores and risk flags. Can be run via CLI, CI, or as an MCP tool from Claude Code, Cursor, and Codex.2Apache 2.0
Glama MCP Gateway
Add one secure layer between your agents and this server.