Skip to content

mcp-lint

mcp-lint lints and grades Model Context Protocol (MCP) servers before an agent ever calls them.

It connects to a server over stdio, Streamable HTTP, or HTTP+SSE, or reads a saved tools/list result. It lists the tools, prompts, and resources, then checks them for broken JSON schemas, vague descriptions, prompt-injection surfaces, and dangerous capabilities. You get a score from 0 to 100, a letter grade, and reports in text, JSON, Markdown, or SARIF.

mcp-lint grading a messy MCP server

Install

npx @superintelligenceco/mcp-lint --help
npm install --global @superintelligenceco/mcp-lint
curl -fsSL https://raw.githubusercontent.com/superintelligenceco/mcp-lint/main/install.sh | sh
docker run --rm ghcr.io/superintelligenceco/mcp-lint:0.2 --help

What it checks

Category Examples
Schema Missing or invalid inputSchema, untyped parameters, required names that do not exist
Description Missing, too short, too long, or vague descriptions
Injection "Ignore previous instructions", invisible Unicode, hidden HTML comments, ~/.ssh references
Capability Shell execution, unconstrained file writes and network access, missing annotations
Naming Invalid tool names, duplicates, mixed casing styles

The README lists all 21 rules with their default severities.

Next steps

  • Getting started walks through a first run, CI gating, and configuration.
  • Architecture shows how a run flows from a server to a report.
  • FAQ answers common questions about scores, false positives, and transports.
  • Decisions records why the tool works the way it does.