{
  "id": "mcp-tool-lint",
  "name": "MCP Tool Descriptor Lint",
  "description": "Lint a supplied MCP tool descriptor for a bounded naming profile, description quality, object-root input/output schemas and typed annotation hints. Unsupported schemas produce explicit findings. Annotations are untrusted hints; this is neither full MCP protocol validation nor a security decision.",
  "category": "api-assurance",
  "priceUsd": "0.01",
  "pricingStatus": "proposed-unverified",
  "pricing": {
    "unit": "one successful operation call",
    "proposedNominalUsd": "0.01",
    "sixDecimalTokenBaseUnits": "10000",
    "subscription": false,
    "includesPayerWalletOrNetworkFees": false,
    "liveQuoteVerified": false,
    "condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
  },
  "intents": [
    "Review tool descriptors before adding them to an agent catalogue",
    "Identify schema limitations and untrusted annotation hints"
  ],
  "whenToUse": [
    "Review tool descriptors before adding them to an agent catalogue",
    "Identify schema limitations and untrusted annotation hints"
  ],
  "whenNotToUse": [
    "MCP transport/protocol conformance certification",
    "Trusting readOnlyHint as an authorization guarantee"
  ],
  "capabilities": [
    "Machine-actionable pointer findings",
    "128-character portable tool naming profile"
  ],
  "limits": {
    "inputBytes": 110000,
    "jsonNodes": 10000,
    "depth": 24,
    "schemaNodes": 128,
    "schemaDepth": 12,
    "schemaProperties": 64,
    "findings": 200,
    "outputBytes": 450000,
    "jsonPointerCharacters": 4096
  },
  "errorCodes": [
    "INPUT_LIMIT",
    "COMPLEXITY_LIMIT",
    "SCHEMA_LIMIT",
    "EVALUATION_LIMIT",
    "UNSAFE_KEY",
    "OUTPUT_LIMIT",
    "POINTER_LIMIT",
    "UNSUPPORTED_OPENAPI",
    "INVALID_OPENAPI",
    "OPENAPI_LIMIT",
    "UNSUPPORTED_SCHEMA",
    "OBJECT_SCHEMA_REQUIRED",
    "OPERATION_NOT_FOUND"
  ],
  "requirementsProfile": {
    "format": "declared-requirements-v1",
    "facts": {
      "execution.suppliedCode": false,
      "execution.remoteMutation": false,
      "execution.llmInference": false,
      "execution.paidMcp": false,
      "verification.semanticTruth": false,
      "verification.sourceAuthenticity": false,
      "verification.liveVulnerabilities": false,
      "numbers.arbitraryPrecisionJson": false,
      "numbers.model": "ieee754-binary64",
      "privacy.requestBodyPersisted": false,
      "execution.deterministic": true,
      "execution.networkAccess": false,
      "privacy.resultBodyPersisted": false,
      "payment.x402": true,
      "payment.mpp": true,
      "operation.id": "mcp-tool-lint",
      "operation.category": "api-assurance",
      "limit.httpRequestBytes": 131072,
      "limit.requestBytes": 110000,
      "limit.responseBytes": 524288,
      "limit.resultBytes": 450000,
      "limit.jsonDepth": 24,
      "limit.jsonNodes": 10000
    },
    "unknownPolicy": "Undeclared requirements are unknown, never compatible. Matching declared facts does not establish semantic fit or input validity.",
    "preflight": "/preflight"
  },
  "documentation": "/reference/tools/mcp-tool-lint.md",
  "serviceContract": "/reference/services/mcp-tool-lint.json",
  "errors": [
    {
      "status": 400,
      "meaning": "Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch",
      "retry": "Correct the request before payment"
    },
    {
      "status": 402,
      "meaning": "Payment challenge or rejected payment",
      "retry": "Use official protocol SDK; inspect payment outcome before another payment"
    },
    {
      "status": 409,
      "meaning": "Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN",
      "retry": "Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay"
    },
    {
      "status": 413,
      "meaning": "Input or generated output too large",
      "retry": "Reduce input; no payment attempted for validation failure"
    },
    {
      "status": 415,
      "meaning": "Unsupported media type or compression",
      "retry": "Send uncompressed application/json"
    },
    {
      "status": 422,
      "meaning": "Schema or service-specific semantic validation failure",
      "retry": "Correct input using returned error code; no payment attempted"
    },
    {
      "status": 429,
      "meaning": "Request/payment-attempt rate exceeded",
      "retry": "Wait for rate limit window; preserve existing payment identity"
    },
    {
      "status": 503,
      "meaning": "Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement",
      "retry": "Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation"
    }
  ],
  "numericPrecision": "JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.",
  "paymentWorkflow": {
    "discoveryOnly": false,
    "supportedProtocols": [
      "x402",
      "mpp"
    ],
    "x402": {
      "credentialHeader": "PAYMENT-SIGNATURE",
      "challengeHeader": "PAYMENT-REQUIRED",
      "receiptHeader": "PAYMENT-RESPONSE",
      "version": 2,
      "scheme": "exact",
      "paymentIdentifier": "payment-identifier extension MUST equal the HTTP Idempotency-Key",
      "sdk": "@x402/core with @x402/evm"
    },
    "mpp": {
      "supported": true,
      "credentialHeader": "Authorization",
      "challengeHeader": "WWW-Authenticate",
      "receiptHeader": "Payment-Receipt",
      "method": "tempo",
      "intent": "charge",
      "sdk": "mppx",
      "tokenDecimals": 6
    },
    "steps": [
      "Check configured readiness and the exact service schema",
      "Generate a fresh random Idempotency-Key for this operation; never use a discovery probe fixture for purchases",
      "Send valid input without a credential to obtain the official protocol challenge",
      "Use the official SDK and authorized wallet to fulfill the challenge",
      "Retry only with identical key, body, protocol and credential",
      "On PAYMENT_UNCERTAIN stop and request operator reconciliation; never blindly pay again"
    ],
    "versionedRetries": "Request fingerprint includes service release version. Retries across a version upgrade can conflict; coordinate upgrades outside the 24-hour replay window and reconcile pending attempts.",
    "docs": "/llms.txt"
  },
  "method": "POST",
  "paths": {
    "x402": "/v1/x402/mcp-tool-lint",
    "mpp": "/v1/mpp/mcp-tool-lint"
  },
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "properties": {
      "tool": {
        "$ref": "#/$defs/__schema0"
      }
    },
    "required": [
      "tool"
    ],
    "additionalProperties": false,
    "$defs": {
      "__schema0": {
        "anyOf": [
          {
            "type": "string"
          },
          {
            "type": "number"
          },
          {
            "type": "boolean"
          },
          {
            "type": "null"
          },
          {
            "type": "array",
            "items": {
              "$ref": "#/$defs/__schema0"
            }
          },
          {
            "type": "object",
            "propertyNames": {
              "type": "string"
            },
            "additionalProperties": {
              "$ref": "#/$defs/__schema0"
            }
          }
        ]
      }
    }
  },
  "outputSchema": {
    "type": "object",
    "required": [
      "operation",
      "version",
      "result",
      "provenance"
    ],
    "properties": {
      "operation": {
        "const": "mcp-tool-lint",
        "type": "string"
      },
      "version": {
        "const": "0.29.0",
        "type": "string"
      },
      "result": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "profile": {
            "type": "string",
            "const": "mcp-tool-descriptor-lint-v1"
          },
          "passesChecks": {
            "type": "boolean"
          },
          "complete": {
            "type": "boolean",
            "const": false
          },
          "schemaSupported": {
            "type": "boolean"
          },
          "findings": {
            "maxItems": 200,
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "code": {
                  "type": "string"
                },
                "severity": {
                  "type": "string",
                  "enum": [
                    "error",
                    "warning",
                    "unsupported"
                  ]
                },
                "path": {
                  "type": "string"
                },
                "message": {
                  "type": "string"
                },
                "suggestion": {
                  "type": "string"
                }
              },
              "required": [
                "code",
                "severity",
                "path",
                "message",
                "suggestion"
              ],
              "additionalProperties": false
            }
          },
          "findingCount": {
            "type": "integer",
            "minimum": 0,
            "maximum": 9007199254740991
          },
          "truncated": {
            "type": "boolean"
          }
        },
        "required": [
          "profile",
          "passesChecks",
          "complete",
          "schemaSupported",
          "findings",
          "findingCount",
          "truncated"
        ],
        "additionalProperties": false
      },
      "provenance": {
        "type": "object",
        "required": [
          "inputSha256",
          "outputSha256",
          "deterministic",
          "externalRequests"
        ],
        "properties": {
          "inputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "outputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "deterministic": {
            "const": true
          },
          "externalRequests": {
            "const": 0
          }
        }
      }
    },
    "additionalProperties": false
  },
  "exampleInput": {
    "tool": {
      "name": "get_order",
      "description": "Read a single order by ID",
      "inputSchema": {
        "type": "object",
        "required": [
          "id"
        ],
        "properties": {
          "id": {
            "type": "integer"
          }
        },
        "additionalProperties": false
      },
      "annotations": {
        "readOnlyHint": true,
        "openWorldHint": false
      }
    }
  },
  "exampleResponse": {
    "operation": "mcp-tool-lint",
    "version": "0.29.0",
    "result": {
      "profile": "mcp-tool-descriptor-lint-v1",
      "passesChecks": true,
      "complete": false,
      "schemaSupported": true,
      "findings": [
        {
          "code": "ANNOTATIONS_UNTRUSTED",
          "severity": "warning",
          "path": "/tool/annotations",
          "message": "Annotations are hints and cannot establish authorization or safety",
          "suggestion": "Verify tool behavior and enforce permissions independently"
        }
      ],
      "findingCount": 1,
      "truncated": false
    },
    "provenance": {
      "inputSha256": "f66182b11adf2e7a4e3a849f0df9edd8d3045eae4ccea501d2b2e9a7d491f31c",
      "outputSha256": "6c4e2538aeec9993abca6cba4ccddc9e47a5a1a7f2e4836c55d4ff5380d13ce2",
      "deterministic": true,
      "externalRequests": 0
    }
  },
  "requiredHeaders": {
    "Content-Type": "application/json",
    "Idempotency-Key": "random 16–128 character operation identifier"
  },
  "fixedExample": "/reference/examples/mcp-tool-lint.json",
  "execution": {
    "deterministic": true,
    "externalRequests": 0,
    "maxExternalRequests": 0,
    "resultSnapshotPersisted": false,
    "fixedExampleIsIllustrativeSnapshot": false,
    "requiresPayment": true,
    "supportsMcpExecution": false
  },
  "releaseSnapshot": {
    "format": "static-release-reference-v1",
    "sourceVersion": "0.29.0",
    "sourceRegistrySha256": "a2b5ec09bf6c38b9d2879d746a4fded374f5928b445377b0270ef6aa8e6cac65",
    "generatedAt": "2026-10-06T15:38:00Z",
    "releaseAcceptance": "not-verified-by-generator",
    "runtimeReadiness": "not-evaluated",
    "livePaymentsVerified": false,
    "indexingVerified": false,
    "apiOrigin": null,
    "notice": "Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment."
  }
}
