Skip to main content

LintLang

LintLang — catch agent failures before your agent runs

Catch agent failures before your agent runs.

CI PyPI Downloads Python License OpenSSF Scorecard

Product page · Playground · PyPI · Docs

LintLang is a local, deterministic static linter for the instructions and tool interfaces an AI agent is given. It flags ambiguous tool choices, conflicting requirements, schema gaps, missing bounds, and other setup defects before the agent runs.

Point it at a project directory. LintLang finds supported agent-facing content inside the files you already use: MCP and function-tool definitions nested in JSON/YAML, parameter schemas, system prompts, messages, output contracts, AGENTS.md, CLAUDE.md, GEMINI.md, SKILL.md, and supported Python prompt code.

uvx lintlang scan .

See LintLang in action. A stylized view of the real DeerFlow finding behind merged PR #5656.

Stylized LintLang terminal showing an H1.9 finding in ByteDance DeerFlow's Vercel skill

LintLang is developed by Hermes Labs.

What LintLang catches

Agent configuration can be valid YAML, JSON, Markdown, or Python and still give a model bad instructions, bad choices, or an interface it cannot reliably use.

LintLang catches problems like:

  • Ambiguous tools — sibling tools that overlap without a clear reason for the model to choose one over another.
  • Missing bounds — retries, loops, or tool use without explicit stopping or progress conditions.
  • Schema mismatches — missing required fields, unclear parameters, and schemas that do not communicate enough intent.
  • Conflicting instructions — incompatible output requirements, vague priorities, and contradictory directions.
  • SKILL.md defects — missing or invalid metadata, unclear usage criteria, and skill names that do not match their directory.
  • Context and message errors — stale project references, unbounded persistence, malformed roles, and broken tool-message sequences.
  • Embedded agent logic — supported Python prompts, literal tool definitions, and selected pipeline thresholds.

Each result says what LintLang inspected. Content with no recognized agent-facing structures is reported as SKIPPED, never PASS. Tool comparisons are within one parsed input; a directory scan does not combine tools from separate files into one selection namespace.

For exact extraction rules and detector behavior, see the technical reference.

Quickstart

Requires Python 3.10+.

Run once without installing:

uvx lintlang scan .

Or name a specific configuration source:

uvx lintlang scan AGENTS.md
uvx lintlang scan SKILL.md
uvx lintlang scan agent.yaml

Install with pip:

pip install lintlang
lintlang scan .

Or with Homebrew on macOS:

brew install hermes-labs-ai/tap/lintlang
lintlang scan .

Findings are advisory by default.

Block on HIGH or CRITICAL findings:

lintlang scan . --fail-on fail

Include MEDIUM findings in the gate:

lintlang scan . --fail-on review

LintLang also emits JSON, SARIF, and GitLab Code Quality reports for automation. See the GitLab CI guide for a copyable Code Quality job.

Put it in CI

Generate a pinned GitHub Actions workflow that scans the repository directory:

lintlang init --github --path .

The generated Action gates HIGH or CRITICAL findings by default. Use a narrower path when CI should check only one configuration source.

For an existing repository with known findings, record a reviewed baseline:

lintlang scan . --write-baseline .lintlang-baseline.json

Then gate new or changed findings:

lintlang scan . \
  --baseline .lintlang-baseline.json \
  --fail-on review

See GitHub CI and Code Scanning and baseline adoption.

Integrations

LintLang works with GitHub Actions, GitHub Code Scanning, pre-commit, Claude Code, Cursor, GitHub Copilot CLI, Gemini CLI, Pi, OpenCode, Hermes Agent, and MegaLinter.

See the integration guide for setup and compatibility.

LintLang does not run models, observe runtime tool choices, or establish that an agent is production-safe. A clean scan means only that the selected static checks found no covered defects in the recognized content.

Documentation

Contributing

Bug reports, disputed findings, reproducible false positives, documentation corrections, and focused contributions are welcome.

See CONTRIBUTING.md and SECURITY.md.

License

Apache License 2.0

Release files for lintlang 0.8.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for lintlang 0.8.0
File Size Uploaded
lintlang-0.8.0.tar.gz 1.9 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for lintlang 0.8.0
File Interpreter ABI Platform
lintlang-0.8.0-py3-none-any.whl Python 3 none any Details

Total release size: 2.1 MB

Release files / lintlang-0.8.0.tar.gz

Download URL lintlang-0.8.0.tar.gz
Size 1.9 MB
Tags Source
SHA-256 checksum
How to use checksums
372c2c2b11ff02f649a3f9a98abddd5c0030e42907587db03b4d089806963747
BLAKE2b-256 checksum
How to use checksums
b04c53aa41e09d98cd0eea43560c4940705d19b55762e91e4ee2ac0d44f742c1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release files / lintlang-0.8.0-py3-none-any.whl

Download URL lintlang-0.8.0-py3-none-any.whl
Size 136.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b539688c02a59615a55b4c7ff27196eefbeb9cf0b15deeeccdc480ee8904e5c3
BLAKE2b-256 checksum
How to use checksums
82e19aece0eaf2622785431e036a7852e55645b2be3bd49c373fe3bcefcc5e3e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.8.0 This release

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.8

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page