Agent♥︎Age
Catalog

io.github.calllint/calllint

Official

by calllint · TypeScript

Static preflight safety gate for MCP servers — scan configs before you run them. Never executes.

CallLint MCP Pre-Flight Safety Gate

CallLint is a static preflight safety gate for MCP servers and agent-tool configurations. It scans configs before execution to determine the blast radius—what tools can read, write, execute, connect to, send, or mutate—then returns an evidence-backed verdict (SAFE / REVIEW / BLOCK / UNKNOWN). It never executes, installs, or connects to the servers it judges.

🛠️ Key Features

  • Static preflight risk linting for MCP and agent-tool configs
  • Blast radius checks: read, write, execute, connect to, send, mutate
  • Evidence-backed verdicts: SAFE / REVIEW / BLOCK / UNKNOWN
  • “Never executes, installs, or connects” during judging

🚀 Use Cases

  • Scan an MCP server config before loading it in an agent
  • Pre-check tool permissions and potential side effects from configuration
  • Reduce uncertainty when tool behavior is not yet reviewed

⚡ Developer Benefits

  • Early, config-level safety signal (verdict) before tool use
  • Avoids runtime inspection requirements since it is static

⚠️ Limitations

  • Operates only as a linter; it does not execute or validate behavior by running tools

Topics

ai-agentsai-securityclillmmcpmcp-serverprompt-injectionsecuritystatic-analysissupply-chain-security

Related servers

More in Security