MCP server for coding agents¶
The MCP server gives a coding agent controlled access to mule-lint’s project scan, rule catalog, XML formatter, and API contract validator. It runs locally over standard input/output and requires no credentials.
Before configuring a host¶
Run this once in a terminal:
npx -y @sfdxy/mule-lint@2.0.0 mcp
The process waits silently for an MCP client. That means startup succeeded; stop it with Ctrl+C. The first run can take longer while npm downloads the pinned package.
Pin the version in shared configuration. Otherwise different developers may receive different rule sets after a release.
Codex¶
Add the server with the Codex CLI:
codex mcp add mule-lint -- npx -y @sfdxy/mule-lint@2.0.0 mcp
codex mcp list
Restart Codex after changing MCP configuration. Codex configuration is documented in the official Codex documentation.
Claude Code or Claude Desktop¶
Use this server entry under the host’s mcpServers key:
{
"mcpServers": {
"mule-lint": {
"command": "npx",
"args": ["-y", "@sfdxy/mule-lint@2.0.0", "mcp"]
}
}
}
For Claude Code, a CLI alternative is:
claude mcp add mule-lint -- npx -y @sfdxy/mule-lint@2.0.0 mcp
Reload the host, then use its MCP status view to confirm that mule-lint connected.
VS Code¶
In .vscode/mcp.json, VS Code uses a servers key and an explicit stdio type:
{
"servers": {
"mule-lint": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@sfdxy/mule-lint@2.0.0", "mcp"]
}
}
}
Reload the VS Code window after saving the file.
Available tools¶
| Tool | Use it for | Important behavior |
|---|---|---|
run_lint_analysis |
Scan a selected project or file scope | Requires an absolute target path; defaults to recommended |
validate_snippet |
Check generated Mule XML before suggesting it | XML only; no project-wide context |
get_rule_details |
Explain a rule ID and related standard | Read-only catalog lookup |
format_mule_xml |
Format a project, file, or XML string | File/project mode writes unless check: true |
validate_api_contract |
Validate a local RAML/OpenAPI project | Remote references are never fetched |
The server also exposes standards, rules, and practice guides as MCP resources, plus prompts for project analysis, rule explanation, and fixing an issue.
Structured analysis results¶
run_lint_analysis advertises an output schema and returns the versioned report directly in structuredContent. Read schemaVersion, execution.status, and scan before interpreting findings. A successful tool transport is not evidence of a complete analysis. Incomplete and no-file scans return isError: true; failures before scanning starts return an explicit tool error without a report.
Legacy text issue groups remain available for existing clients. Quality ratings are omitted from that text when execution is incomplete or no files were scanned. Snippet rule failures also return errors instead of clean results. Static-analysis findings and secure-property reference checks are not a complete security assessment.
See versioned report JSON for the shared CLI/library contract.
A good agent request¶
Scan this Mule project with the recommended profile. Group the result by rule,
explain the errors first, and propose changes without editing files yet.
For an implementation request:
Scan this Mule project, fix only MULE-003 findings, validate the changed XML,
then run the project scan again. Do not change unrelated formatting.
Safety and scope¶
- Give the agent the project directory you intend it to inspect.
- Lint and catalog tools are read-only.
- Formatting can write XML; ask for
check: truewhen you only want a preview. - Review agent changes as a normal source-control diff.
- Do not place customer reports, credentials, or raw production payloads in prompts or committed fixtures.
Troubleshooting¶
If the server does not appear:
- run the pinned
npx ... mcpcommand directly; - confirm the host uses
mcpServersorserversas shown above; - make sure the project path supplied to scan tools is absolute;
- restart or reload the host;
- check the host’s MCP logs for npm/PATH errors.
See general troubleshooting for installation issues.
Analysis result contract¶
The shared analysis service owns configuration and result
policy. MCP preserves its recommended default and existing tool names, grouped text and
resource URIs. See structured analysis results and the
generated schema reference. A missing structuredContent
on a fatal tool error must never be interpreted as zero issues.
MCP standards and documentation resources resolve from the installed package, not similarly named files in the caller's working directory. File-target scope uses selected-file context and may run project rules; a complete execution is not proof of full-project coverage.