Repository navigation
Agent Lint: open-source linter for Codex, AGENTS.md, MCP, Claude Code, and Cursor config #46874
Replies: 2 comments
|
One candidate for your requested Codex checks: shell-looking placeholders inside static I read #387: CX013 intentionally classifies placeholders as non-secrets without promising expansion. Its clean fixture reflects that. A separate compatibility warning could catch the resulting connection mistake while preserving CX013: the Codex reference and implementation distinguish static headers from environment lookup. Possible fixtures for a separate advisory rule: # Suspicious: this is the literal text $AUTH_HEADER.
[mcp_servers.placeholder]
url = "https://example.com/mcp"
http_headers = { Authorization = "$AUTH_HEADER" }
# Environment lookup; AUTH_HEADER holds the complete header value.
[mcp_servers.env_reference]
url = "https://example.com/mcp"
env_http_headers = { Authorization = "AUTH_HEADER" }
# Clean anonymous control: no credential fields required.
[mcp_servers.remnant_read]
url = "https://remnant.dedale-bi.com/mcp/chatgpt"Suggested bounds: warn on placeholder-looking authorization values, preserve intentional static headers, allow a documented suppression, and never expand environment variables or print their values during linting. The anonymous control comes from our public read-first connection example; it needs no account. This is source-level feedback, not a reproduced Agent Lint CLI result: I haven't run your Linux/macOS release here. Would a compatibility warning distinct from CX013 fit your intended scope? |
|
I'm the founder of Gated. One additional AGENTS.md/skills check I'd find useful is an opt-in advisory for an undocumented approval boundary. A project can tell an agent to request approval while the actual controlled route covers only an explicitly invoked CLI. Other GitHub tools or credentials may still work. The documentation should make that difference visible. A possible review record would name:
For example, a qualified statement says that requests explicitly sent through one CLI cover new-branch creation at an existing SHA, with independent routes outside that boundary. An unqualified claim that every GitHub write is intercepted deserves human review. This is a proposed documentation check, not a reproduced Agent Lint bug or an existing schema. I'd keep it opt-in and advisory, allow suppression for intentionally documented exceptions, and never inspect or print secret values. A static check cannot establish that all usable credentials have been removed or that the stated control actually ran. That distinction matters in our own evidence: actual Codex and Claude Code runtimes completed safe-mode request, approval, simulated execution, and receipt checks. A live GitHub branch write was verified separately through the downloaded CLI, with provider readback. The rehearsals don't establish live writes from either runtime. Our free credential-boundary guide includes a manual inventory; it requires no signup. Product applications are closed as of October 6. Would an opt-in coverage-documentation check fit Agent Lint, or would you keep this as a manual review item? |
Uh oh!
There was an error while loading. Please reload this page.
I’ve open-sourced Agent Lint, a linter for configuration used by Codex and other coding agents:
https://github.com/zhupanov/agent-lint
It validates things including:
.codex/ and .codex-plugin/
AGENTS.md
.agents/skills/
MCP configuration
Claude Code configuration
Cursor configuration
The project currently has ~300 lint rules, with a documented rule registry.
It supports configurable rule severity and suppression, running selected rules with --only, GitHub Actions integration, and prebuilt binaries for Linux and macOS. It’s implemented in Rust.
The motivation was pretty simple: agent configuration is becoming large and structured enough that it increasingly benefits from the same kind of automated validation we already expect for other parts of a software project.
I’d especially appreciate feedback from Codex users on:
configuration patterns I’m not covering yet
rules that would be useful for real-world Codex projects
false positives or cases where a rule is too opinionated
additional AGENTS.md or MCP checks worth adding
Issues and contributions are very welcome.
All reactions