Skip to content

FAQ

Does mcp-lint call my tools?

No. It only sends initialize and the four list requests. It never calls tools/call, reads a resource, or gets a prompt, so it is safe to run against a server with destructive tools.

Why did my server get an F when it only has warnings?

Warnings cost 8 points each per tool. A tool with five warnings scores 60, and if most tools look like that, the average falls below 60. Run with --format markdown to see which tools pull the score down, or turn off rules that do not apply to you in .mcp-lint.json.

Why is the score capped at 50?

Any error from an injection/* rule caps the score at 50. A single tool that tells the model to hide something from the user compromises every conversation that loads the server, no matter how clean the other tools are. See ADR 0002.

How do I silence a false positive?

Set the rule to off or lower its severity in .mcp-lint.json, or add the tool to ignoreTools. Inline suppressions for a single finding are on the roadmap.

Which transports are supported?

stdio, Streamable HTTP, and the older HTTP+SSE transport. With --url, mcp-lint tries Streamable HTTP first and falls back to SSE. Pass headers with -H for servers that need a token.

Can I lint a server without running it?

Yes. Save its tools/list result, or run mcp-lint --save snapshot.json -- <command> once, then lint the file with --file. This is the fastest way to gate pull requests in CI.

What do the exit codes mean?

0 means the score met the minimum, 1 means it fell below the minimum, and 2 means a usage error or a failure to connect to the server.

Does the Docker image lint stdio servers?

Yes, as long as the server runs on Node.js: the image includes node and npx. Mount the server into the container, for example docker run --rm -v "$PWD:/work" ghcr.io/superintelligenceco/mcp-lint:0.2 -- node server.js. For a server in another language, use --url, the npm package, or a standalone executable.

How do I verify a release download?

Every release has a SHA256SUMS file, and install.sh checks the download against it. The release assets carry GitHub build provenance attestations, so you can also run gh attestation verify mcp-lint-linux-x64 --repo superintelligenceco/mcp-lint. The container image is signed with cosign keyless signing.