Skip to main content
LintLang — deterministic analysis for the runtime of agents

LintLang

Static analysis for the instructions your AI agents execute.

LintLang is developed by Hermes Labs.

Hermes Labs studies failure modes in agent and LLM systems, develops open-source tools that treat language as part of the runtime, and works with teams to remediate reliability failures in production.

CI PyPI Downloads Python License OpenSSF Scorecard DOI

Product page · Browser playground · PyPI · Documentation

lintlang scan reporting a CRITICAL tool-description finding

LintLang catches ambiguous tool descriptions, missing operational limits, schema/description mismatches, conflicting output contracts, and other bounded instruction defects before a model runs.

Local · deterministic · zero LLM calls · no telemetry or network access during a scan

Quick start

Requires Python 3.10+.

Run once without installing:

uvx lintlang scan AGENTS.md

Or install it:

pip install lintlang
lintlang scan AGENTS.md

Use the instruction file your agent actually reads: AGENTS.md, CLAUDE.md, GEMINI.md, GitHub Copilot instructions, or another supported prompt/configuration path.

No instruction file yet? Try the checkout-free first run.

A normal scan reports findings without blocking:

REVIEW — findings detected

To make HIGH or CRITICAL findings fail CI:

lintlang scan AGENTS.md --fail-on fail

What LintLang catches

  • Ambiguous tools — empty, vague, or overlapping descriptions without a clear selection rule.
  • Missing bounds — retries, loops, or tool use without explicit stopping or progress conditions.
  • Contract mismatches — descriptions that disagree with schemas, malformed message roles, or conflicting output-format requirements.
  • Context and prompt defects — vague or unscoped context, instruction files that point at project files that no longer exist, embedded prompt issues, and selected problems in supported Python prompt pipelines.
  • Skill metadata — a SKILL.md whose front-matter description is missing, over the 1024-character limit, or never says when to use the skill; a name that is invalid or differs from its directory.

Every finding has a stable identifier, severity, evidence, and a suggested review action where the parser can justify one. Findings in text files carry the line number.

Every result also says what it inspected:

FAIL — 2 HIGH
Inspected: 18 tools (18 described, 18 with a schema)

A file LintLang could read nothing from is reported SKIPPED, never PASS.

Reports also explain the separate HERM confidence label using its current coverage proxies: whether prompt-like framing and input-boundary language were detected. The guidance is conditional on the document's purpose; reference material can naturally receive lower confidence. This label is not a statistical probability, a finding-certainty estimate, or the structural PASS/REVIEW/FAIL verdict. The current coverage bands are high at 90% or more, medium at 75% or more, and low below 75%.

Conservative automatic rewrite

scan --fix currently handles one exact case: a direct, standalone Don't be verbose instruction (with or without a final period; curly apostrophe is also accepted). It prints the unified diff before writing. Use --dry-run to preview without writing, or --backup to preserve the exact original bytes as FILE.lintlang.bak before the write; an existing backup is never overwritten.

lintlang scan AGENTS.md --fix --dry-run
lintlang scan AGENTS.md --fix --backup

The file must start with a top-level # Instructions heading, followed only by blank lines and the supported instruction as its first body line. Other headings, preambles, quoted, commented, code, and ambiguous contexts are left untouched; malformed lexical scope fails closed. Only one explicit .md, .txt, or .prompt file is accepted. H1/H2 suggestions that would invent tool behavior, output formats, or scope; security negatives; other priority rules; and cross-file conflicts remain manual. This is a narrow syntactic rewrite, not an automatic-fix score or a claim that other suggestions are safe to apply.

LintLang does not decide whether arbitrary prose is true, predict runtime model behavior, or certify an agent as safe.

What it can scan

Surface Examples
Coding-agent instructions AGENTS.md, CLAUDE.md, GEMINI.md, Copilot instructions, SKILL.md with front matter
Tool definitions MCP tools/list dumps and manifests, OpenAI/Anthropic/Gemini function lists, mcpServers.*.tools, VS Code languageModelTools — found by shape in any JSON or YAML, object or array root
Agent configuration YAML and JSON with a system prompt, messages, tools, or output schema
Prompts and instructions Markdown, text, and prompt files
Python Supported extractable pipeline patterns
Invocation Individual files, directories, repository discovery, standard input

See the technical reference for detector coverage, extraction behavior, and the CLI flags for repository discovery (--discover) and standard-input scanning (--stdin-filename).

Use it where instructions change

Local review

lintlang scan AGENTS.md

Existing repositories

Create a baseline for findings already reviewed, then gate only new findings:

lintlang scan AGENTS.md --write-baseline .lintlang-baseline.json
lintlang scan AGENTS.md \
  --baseline .lintlang-baseline.json \
  --fail-on review

See baseline adoption for matching semantics and maintenance.

GitHub CI and Code Scanning

Generate a pinned workflow for a known instruction path:

lintlang init --github --path AGENTS.md

The generated workflow runs the same scanner and can upload SARIF for GitHub Code Scanning.

Integrations

LintLang fits existing developer workflows rather than requiring a runtime service.

Integration Use
GitHub Action Scan instruction paths in pull requests and CI
GitHub Code Scanning Upload SARIF findings beside code findings
pre-commit Review instructions before commit
Claude Code Optional non-blocking guidance after supported edits
GitHub Copilot CLI On-demand audit of a named instruction or tool-definition file
Gemini CLI Optional non-blocking guidance after supported edits
OpenCode Optional non-blocking post-edit guidance
Hermes Agent Bounded pre-verification of supported edits
MegaLinter Opt-in external plugin for existing MegaLinter users

See the integrations and ecosystem guide for setup instructions and public ecosystem references. The GitHub Copilot CLI plugin guide gives the direct install command.

Results and exit behavior

Verdict Meaning
PASS No remaining MEDIUM or higher findings
REVIEW At least one MEDIUM finding remains
FAIL At least one HIGH or CRITICAL finding remains
ERROR A requested input could not be inspected, including a scan that inspected zero files or nothing in any file
SKIPPED The file holds nothing LintLang inspects (a package.json, a JSON Schema, Python with no prompt). Shown with its reason; never counted as PASS

Findings are non-blocking by default. Use --fail-on to choose a CI threshold. Input errors remain nonzero regardless of that threshold; a scan that inspects zero files is one of them, and --allow-empty is the opt-out for an input that may legitimately be empty. See the GitHub CI guide for the exact per-channel behavior.

Machine-readable JSON and SARIF output are available for automation.

Where LintLang fits

syntax and schema validation
        ↓
LintLang static instruction checks
        ↓
runtime agent evaluation
        ↓
domain and security review

LintLang is an authoring and review control. It does not run models, observe tool selection at runtime, prove semantic correctness, replace evaluation, or establish that an agent is production-safe.

A clean scan means only that the selected static checks found no covered defects in the recognized content.

Evidence

Character.AI’s public Larch repository pins a LintLang release in recurring CI. MegaLinter catalogs LintLang as the AI_LINTLANG external plugin.

See the integrations and ecosystem guide for additional public references.

LintLang is an engineering evolution of Hermes Labs’ research into structural epistemic failure modes in language models. See Research and design lineage.

Documentation

Need Document
Detector behavior and rule IDs Technical reference
Existing-repository adoption Baselines
Integrations and ecosystem Integration guide
CI and Code Scanning GitHub initializer
Research and design lineage Research
Claude Code Plugin guide
Gemini CLI Extension guide
MegaLinter Plugin guide
Product scope and intent INTENT.md
Releases CHANGELOG.md
Contribution CONTRIBUTING.md
Security SECURITY.md

Contributing

Bug reports, disputed findings, reproducible false positives, documentation corrections, and focused contributions are welcome. Read CONTRIBUTING.md before opening a pull request.

License

Apache License 2.0

Release files for lintlang 0.7.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for lintlang 0.7.1
File Size Uploaded
lintlang-0.7.1.tar.gz 441.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for lintlang 0.7.1
File Interpreter ABI Platform
lintlang-0.7.1-py3-none-any.whl Python 3 none any Details

Total release size: 574.6 kB

Release files / lintlang-0.7.1.tar.gz

Download URL lintlang-0.7.1.tar.gz
Size 441.2 kB
Tags Source
SHA-256 checksum
How to use checksums
afd00466277de447bcfa41a9fe29a34dac5e40d7dfb0b8f21763f29398fb8b47
BLAKE2b-256 checksum
How to use checksums
d630841117bb0110074d5c2483be4585884a2444c634a9e1d161429f1be885df
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release files / lintlang-0.7.1-py3-none-any.whl

Download URL lintlang-0.7.1-py3-none-any.whl
Size 133.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6f6f92002abcba4e3222fb445bfdd02c233e04411e14c1cecd1bc194b0037bbe
BLAKE2b-256 checksum
How to use checksums
a0ee50497f9fa22ad2a307ed361849d872a25780b78639ba83bc34641fd41a08
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release history Release notifications | RSS feed

0.8.0

2 release files

This release

0.7.1 This release

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.8

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page