Fix your first finding #
Find and repair an empty tool description. Requires Python 3.10+ and uv. No clone or persistent package installation is required. Run these shell commands in a scratch directory.
Create and scan #
cat > agent.yaml <<'YAML'
system_prompt: |
You are a support agent. Use the tools to help the user.
tools:
- name: process_ticket
description: ""
parameters:
type: object
properties:
ticket_id:
type: string
YAML
uvx --from lintlang==0.8.0 lintlang scan agent.yaml --fail-on fail
Expected with the pinned release: FAIL — 1 CRITICAL, 1 HIGH, 1 MEDIUM, exit 1. H1.1 identifies the empty description; H2 flags missing limits; H3 flags an undescribed parameter. A finding is a successful detection, not a broken installation.
Repair and rerun #
cat > agent-fixed.yaml <<'YAML'
system_prompt: |
You are a support agent. Use the tools to help the user.
Stop and report the failure once the retry limit is reached.
tools:
- name: process_ticket
description: "Apply a resolution action to one existing support ticket. Use this only after the ticket has been read; do NOT use it to look tickets up."
parameters:
type: object
properties:
ticket_id:
type: string
description: "Identifier of the existing ticket to act on"
required: [ticket_id]
constraints:
max_iterations: 3
timeout_seconds: 30
YAML
uvx --from lintlang==0.8.0 lintlang scan agent-fixed.yaml --fail-on fail
Expected: PASS — 0 findings, exit 0. This means the selected static checks found no covered defect; it is not a runtime-safety certificate.
Gate your real instructions #
uvx --from lintlang==0.8.0 lintlang scan AGENTS.md --fail-on fail
Replace AGENTS.md with an existing input you own. Without a threshold, scans are advisory. --fail-on fail gates HIGH/CRITICAL; --fail-on review also gates MEDIUM. Input errors remain nonzero. Installation alternatives include pip and pipx; PowerShell examples are in the reference.
Next: Supported inputs · GitHub CI · GitLab CI · Rules · Integrations.