Skip to main content
ClaudeWave
DLeibner avatar
DLeibner

mcp-surface-lint

View on GitHub

static linter for MCP servers

MCP ServersOfficial Registry0 stars0 forksTypeScriptUpdated today
Install in Claude Code / Claude Desktop
Method: Manual
Claude Code CLI
git clone https://github.com/DLeibner/mcp-surface-lint
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "mcp-surface-lint": {
      "command": "node",
      "args": ["/path/to/mcp-surface-lint/dist/index.js"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Clone https://github.com/DLeibner/mcp-surface-lint and follow its README for install instructions.
Use cases

MCP Servers overview

# mcp-surface-lint

Static, design-level linting for MCP tool surfaces. Deterministic, offline, and it never calls an LLM.

This is a monorepo:

| Package | What it is |
| --- | --- |
| [`packages/core`](packages/core) | The linter — 19 rules, the scoring engine, and the `mcplint` CLI (`mcp-surface-lint` on npm). Publishable to npm. |
| [`apps/web`](apps/web) | The hosted playground: paste a `tools/list` dump or point it at a remote MCP URL, get a score and an audit. |

## Quick start

```bash
npm install
npm run build          # builds core (the web app imports it)

npm test               # every package
npm run dev            # the web app on http://localhost:3000
```

The web app runs with no cloud accounts configured: reports are held in memory, rate limiting is off,
and no analytics are sent. Copy `apps/web/.env.example` to `.env.local` to wire up the real services.
See [`DEPLOYMENT.md`](DEPLOYMENT.md) for the production account, migration, publishing, and smoke-test
checklist.

## Releases

Production releases are semver Git tags (bare `X.Y.Z`, no `v` prefix — see `.npmrc`). From a clean
`main` branch:

```bash
npm version patch
# or: npm version minor
# or: npm version major
```

That bumps the root version, runs `preversion` (`npm run typecheck`), then the `version` lifecycle
syncs `mcp-surface-lint` and `@mcplint/web` to the same semver, stages workspace `package.json` files and
`package-lock.json`, commits, and tags. `postversion` pushes the branch and tags to `origin`.

### Advanced: bump one workspace only

When only the web app or CLI changed, you may want a partial bump. The default `version` hook syncs
**all** workspaces to the root version, so partial bumps need `--ignore-scripts` and manual staging:

```bash
npm version patch -w @mcplint/web --include-workspace-root --ignore-scripts
# or: npm version patch -w mcp-surface-lint --include-workspace-root --ignore-scripts
git add package.json apps/*/package.json packages/*/package.json package-lock.json
git commit -m "$(node -p \"require('./package.json').version\")"
git tag "$(node -p \"require('./package.json').version\")"
git push origin HEAD --follow-tags
```

The release tag still follows the root version; deploy always runs, and npm/Registry publication is
skipped when `packages/core` was not bumped.

`npm version` has no `--dry-run`; inspect `npm help version` or run on a throwaway clone before
cutting a real release.

Full runbook: [`DEPLOYMENT.md`](DEPLOYMENT.md).

## The CLI

```bash
npm run mcplint -- --stdio "node dist/server.js"
npm run mcplint -- https://example.com/mcp
npm run mcplint -- snapshot.json
```

See [`packages/core/README.md`](packages/core/README.md) for the full CLI, config, and scoring model,
and [`packages/core/docs/rules.md`](packages/core/docs/rules.md) for the rule catalogue.

## Hosted MCP server

The web app also serves a stateless Streamable HTTP MCP endpoint at `/api/mcp`. It exposes one
read-only tool, `check_mcp_server`, which accepts either a public HTTPS MCP URL (plus optional
headers) or an inline `tools/list` snapshot. The result includes structured composite/category
scores, footprint stats, and findings.

Each protocol request gets a fresh MCP server and transport. Tool inputs and captured schemas are
not written to the report store. See `/install` in the running web app for current Cursor, VS Code,
Claude, Windsurf, and generic client configurations.

## What the web app does and does not do

- **Ingest** is paste-a-dump or connect-to-an-https-URL. It never spawns a process, so stdio servers
  are a job for the CLI.
- **Remote capture is SSRF-guarded** ([`apps/web/lib/ssrf.ts`](apps/web/lib/ssrf.ts)): https only, every
  resolved address must be public unicast, the socket is pinned to the vetted IP so DNS rebinding
  cannot move it, and redirects are re-validated at every hop.
- **Reports are unlisted by default** — an unguessable URL, `noindex`, deleted after 30 days unless
  the owner opts them public. Anyone with an unlisted URL can view it.
- **The MCP endpoint is stateless** — unlike the interactive report workflow, it returns a report
  directly and does not persist the input, captured schemas, or result.
- **Everything is free.** The `GATE_FINDINGS` flag and `projectReport()` exist so a paid tier *could*
  withhold the audit while leaving the score free. It is off, and no billing exists.

What people ask about mcp-surface-lint

What is DLeibner/mcp-surface-lint?

+

DLeibner/mcp-surface-lint is mcp servers for the Claude AI ecosystem. static linter for MCP servers It has 0 GitHub stars and was last updated today.

How do I install mcp-surface-lint?

+

You can install mcp-surface-lint by cloning the repository (https://github.com/DLeibner/mcp-surface-lint) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is DLeibner/mcp-surface-lint safe to use?

+

DLeibner/mcp-surface-lint has not been audited yet by our security agent. Review the original repository on GitHub before using it in production.

Who maintains DLeibner/mcp-surface-lint?

+

DLeibner/mcp-surface-lint is maintained by DLeibner. The last recorded GitHub activity is from today, with 1 open issues.

Are there alternatives to mcp-surface-lint?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy mcp-surface-lint to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: DLeibner/mcp-surface-lint
[![Featured on ClaudeWave](https://claudewave.com/api/badge/dleibner-mcp-surface-lint)](https://claudewave.com/repo/dleibner-mcp-surface-lint)
<a href="https://claudewave.com/repo/dleibner-mcp-surface-lint"><img src="https://claudewave.com/api/badge/dleibner-mcp-surface-lint" alt="Featured on ClaudeWave: DLeibner/mcp-surface-lint" width="320" height="64" /></a>

More MCP Servers

mcp-surface-lint alternatives