api-linter

api-linter is a skill for Claude Code from cyanheads/socrata-mcp-server. It costs 86 tokens per session (12,808 once invoked), scanned A, a copy of api-linter, Apache-2.0.

A reference for rules that check Model Context Protocol definitions, including tools, readable data sources, prompts, and server settings.

In plain words
What is it for?
Use it when `bun run lint:mcp` or `bun run devcheck` reports issues such as invalid schemas, naming problems, or mismatched server configuration.
Why use it?
It explains whether a reported lint message is an error or warning, what the rule means, and how to correct the definition.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin. Also seen: mentions CLAUDE.md; mentions Claude Code; mentions AGENTS.md.

Part of the socrata-mcp-server plugin — 32 skills, 1 MCP server shipped together

Good fit Use it when bun run lint:mcp or bun run devcheck reports issues such as invalid schemas, naming problems, or mismatched server configuration.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/cyanheads/socrata-mcp-server/api-linter
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add cyanheads/socrata-mcp-server --skill api-linter
Clone the repo
git clone --depth 1 https://github.com/cyanheads/socrata-mcp-server

Made for: Claude Code.

Or install socrata-mcp-server, the plugin that ships this one along with the rest of its 32 skills, 1 MCP server.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for api-linter

README.md
[![agentmods](https://agentmods.dev/badge/skills/cyanheads/socrata-mcp-server/api-linter.svg)](https://agentmods.dev/skills/cyanheads/socrata-mcp-server/api-linter)
Your own site
<a href="https://agentmods.dev/skills/cyanheads/socrata-mcp-server/api-linter"><img src="https://agentmods.dev/badge/skills/cyanheads/socrata-mcp-server/api-linter.svg" alt="Measured on agentmods" height="20"></a>
Per session 86 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 12,808 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00086 $0.12808
Opus 5 $0.00043 $0.06404
Sonnet 5 $0.00017 $0.02562
Haiku 4.5 $0.00009 $0.01281

Measured 7d ago against content hash 8f2c3de62558, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

api-linter scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to api-linter — 4 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

skills/api-linter/SKILL.md · 984 lines

How it starts

The opening of the file, as written. The whole thing — 984 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Overview

The linter validates tool, resource, and prompt definitions against the MCP spec and framework conventions. It is build-time only — not invoked at server startup. It runs in two places:

Entry point When On failure
bun run lint:mcp Manual or CI Prints errors + warnings, exits non-zero on errors.
bun run devcheck Pre-commit workflow Wraps lint:mcp alongside typecheck, format, bun audit, bun outdated.

Both surface the same LintReport from validateDefinitions() (exported from @cyanheads/mcp-ts-core/linter). Each diagnostic has a stable rule ID — that's the anchor you land on via the See: skills/api-linter/SKILL.md#<rule> breadcrumb appended to every message.

Severity:

  • error — MUST-level spec violation; blocks devcheck.
  • warning — SHOULD-level or quality issue; logged but devcheck continues.

Imports (if you need to run the linter programmatically):

import { validateDefinitions } from '@cyanheads/mcp-ts-core/linter';
import type { LintReport, LintDiagnostic } from '@cyanheads/mcp-ts-core/linter';

const report = validateDefinitions({ tools, resources, prompts, serverJson, packageJson });
if (!report.passed) process.exit(1);

Rule index

Grouped by family. Jump to any rule ID via its anchor.

Family Rules Section
Definition definition-invalid Definition rules
Format parity format-parity, format-parity-threw, format-parity-walk-failed, format-parity-depth-limit Format parity
Schema schema-is-object, describe-on-fields, schema-serializable, schema-unsatisfiable, header-param-designation Schema rules
Portability schema-format-portability, schema-anyof-needs-type, schema-no-discriminator-keyword, schema-no-defs, schema-root-oneof-portability, schema-dialect-tag Portability rules
Names name-required, name-format, name-unique Name rules
Tools description-required, handler-required, auth-type, auth-scope-format, annotation-type, annotation-coherence, meta-ui-type, meta-ui-resource-uri-required, meta-ui-resource-uri-scheme, app-tool-resource-pairing, canvas-consumer-missing Tool rules
Resources uri-template-required, uri-template-valid, resource-name-not-uri, template-params-align Resource rules
Landing landing-* (23 rules — shape, tagline, logo, links, repo, envExample, connectSnippets, theme) Landing config rules
Prompts generate-required Prompt rules
Handler body prefer-mcp-error-in-handler, prefer-error-factory, preserve-cause-on-rethrow, no-stringify-upstream-error Handler body rules
Error contract (structural) error-contract-type, error-contract-empty, error-contract-entry-type, error-contract-code-type, error-contract-code-unknown, error-contract-code-unknown-error, error-contract-reason-required, error-contract-reason-format, error-contract-reason-unique, error-contract-when-required, error-contract-retryable-type, error-contract-recovery-required, error-contract-recovery-empty, error-contract-recovery-min-words Error contract rules
Error contract (conformance) error-contract-conformance, error-contract-prefer-fail Error contract rules
Enrichment enrichment-type, enrichment-empty, enrichment-field-type, enrichment-output-collision, enrichment-prefer-block, enrichment-trailer-render, enrichment-trailer-orphan, enrichment-trailer-unknown-field, capped-list-no-truncation Enrichment rules
server.json ~40 rules prefixed server-json-* server.json rules

Read the full file on GitHub · 984 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 7d ago First seen · 984 lines · 86 tokens per session scan A 8f2c3de62558

Subscribe to this mod's changes

api-linter is a skill published in the GitHub repository cyanheads/socrata-mcp-server (3 stars, last pushed 16d ago), licensed Apache-2.0. It adds 86 tokens to every session and 12,808 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to api-linter, differing in 4 lines, and is treated as a copy.

Related

Other skills, from other repositories

api-linter

MCP definition linter rules reference. Use when bun run lint:mcp or bun run devcheck reports a lint error or warning (format-parity, schema-is-object, name-format, server-json-, etc.) and you need to understand the rule, its severity, and how to fix it. Every rule ID the linter emits has an entry in this doc.

cyanheads/treasury-fiscaldata-mcp-server · 86 tokens

report-issue-framework

File a bug or feature request against @cyanheads/mcp-ts-core when you hit a framework issue. Use when a builder, utility, context method, or config behaves contrary to the documented API — not for server-specific application bugs.

cyanheads/treasury-fiscaldata-mcp-server · 52 tokens

report-issue-local

File a bug or feature request against this MCP server's own repo. Use for server-specific issues — tool logic, service integrations, config problems, or domain bugs that aren't caused by the framework.

cyanheads/treasury-fiscaldata-mcp-server · 44 tokens

wtf-happened

Retrieve a distilled timeline of the current troubleshooting incident and generate a runbook skeleton. Returns a concise summary by default, or the full untruncated timeline on request.

Wave-Engineering/mcp-server-wtf · 0 tokens

wtf-now

Add a manual observation to the WTF flight recorder journal. The entry is stored as a crafted (intentional) record. Classification of the entry's action type is handled by the background classifier — do not attempt to infer it here.

Wave-Engineering/mcp-server-wtf · 0 tokens

wtf

Launch the WTF flight recorder for a new troubleshooting incident. Archives any prior incident, prompts for an optional title, then puts Claude into flight recorder mode where significant observations, theories, and corrective actions are journaled automatically.

Wave-Engineering/mcp-server-wtf · 0 tokens