{"_id":"@alexmelges/agentlint","_rev":"2-01cf3eb093bc5b4e9cb3820c0dc2e91a","name":"@alexmelges/agentlint","dist-tags":{"latest":"0.3.2"},"versions":{"0.3.1":{"name":"@alexmelges/agentlint","version":"0.3.1","keywords":["agent","lint","ai","coding-agent","static-analysis","code-quality"],"author":{"name":"Alex Melges","email":"alexmelges@gmail.com"},"license":"MIT","_id":"@alexmelges/agentlint@0.3.1","maintainers":[{"name":"alexmelges","email":"alexmelges@gmail.com"}],"homepage":"https://github.com/alexmelges/agentlint#readme","bugs":{"url":"https://github.com/alexmelges/agentlint/issues"},"bin":{"agentlint":"dist/cli.js"},"dist":{"shasum":"36f6ef4c3d08bf55083de293ce386d32a6fd8ccf","tarball":"https://registry.npmjs.org/@alexmelges/agentlint/-/agentlint-0.3.1.tgz","fileCount":63,"integrity":"sha512-YGBrf9z1QeUyq/URVj3UcOOEUyysPwxXC2UrzRr3VVDk6ISy7cY5xt97U+UoOL1prntNoyC0X8ek9j+wCIGJ2w==","signatures":[{"sig":"MEYCIQCeBT3Qt/0v4oEwhX4CH1lLR/C4pQZUAr5hVCuURwQUswIhAKxpmKs8g8sNeO0HbqmjePYW0GIDi446UWIWS3ZlEOPn","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":70515},"type":"module","engines":{"node":">=20"},"gitHead":"b8029a3782e1c2077474b50d4dc427d928e3146d","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"alexmelges","email":"alexmelges@gmail.com"},"repository":{"url":"git+https://github.com/alexmelges/agentlint.git","type":"git"},"_npmVersion":"11.8.0","description":"Static analysis for agent-generated code. Catches code smells that coding agents consistently produce.","directories":{},"_nodeVersion":"25.5.0","_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/agentlint_0.3.1_1771365194730_0.5205227049845631","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"name":"@alexmelges/agentlint","version":"0.3.2","description":"Static analysis for agent-generated code. Catches code smells that coding agents consistently produce.","type":"module","bin":{"agentlint":"dist/cli.js"},"scripts":{"build":"tsc","test":"vitest run","test:watch":"vitest","lint":"tsc --noEmit"},"keywords":["agent","lint","ai","coding-agent","static-analysis","code-quality"],"author":{"name":"Alex Melges","email":"alexmelges@gmail.com"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/alexmelges/agentlint.git"},"devDependencies":{"typescript":"^5.7.0","vitest":"^3.0.0","@types/node":"^22.0.0"},"engines":{"node":">=20"},"gitHead":"36663a6a3978c3a92c039645270839c1e2bdc287","_id":"@alexmelges/agentlint@0.3.2","bugs":{"url":"https://github.com/alexmelges/agentlint/issues"},"homepage":"https://github.com/alexmelges/agentlint#readme","_nodeVersion":"25.5.0","_npmVersion":"11.8.0","dist":{"integrity":"sha512-v6FV0sz72k1tl0AH56YcCpjL2FavI0iCrI374E57N+ssMC+qO9jPBLBy0rtJ8xGS5EKH3UBoqK1PDvkXG6uKnw==","shasum":"9196a62a51d2840ea618814b9778314b27ef16b5","tarball":"https://registry.npmjs.org/@alexmelges/agentlint/-/agentlint-0.3.2.tgz","fileCount":63,"unpackedSize":70561,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDDnfVw122p1OSXLAFQhXrT5WWabTywLQQa4SQXVLU2bwIhALIqhQDfJBK6A2rr1yMIyxTLJZyZzKDTsjAAH2KKbwtj"}]},"_npmUser":{"name":"alexmelges","email":"alexmelges@gmail.com"},"directories":{},"maintainers":[{"name":"alexmelges","email":"alexmelges@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agentlint_0.3.2_1771365472837_0.509048241656787"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-17T21:53:14.662Z","modified":"2026-02-17T21:57:53.100Z","0.3.1":"2026-02-17T21:53:14.881Z","0.3.2":"2026-02-17T21:57:52.983Z"},"bugs":{"url":"https://github.com/alexmelges/agentlint/issues"},"author":{"name":"Alex Melges","email":"alexmelges@gmail.com"},"license":"MIT","homepage":"https://github.com/alexmelges/agentlint#readme","keywords":["agent","lint","ai","coding-agent","static-analysis","code-quality"],"repository":{"type":"git","url":"git+https://github.com/alexmelges/agentlint.git"},"description":"Static analysis for agent-generated code. Catches code smells that coding agents consistently produce.","maintainers":[{"name":"alexmelges","email":"alexmelges@gmail.com"}],"readme":"# AgentLint\n\nProduction-readiness checker for agent-generated code. Catches the patterns that coding agents (Claude Code, Codex, Cursor, Copilot) consistently produce but shouldn't ship.\n\n**Not a style linter.** ESLint handles formatting. AgentLint catches agent-specific code smells — hardcoded paths, missing error handling, leaked credentials, naive patterns.\n\n## Quick Start\n\n```bash\nnpx agentlint .\n```\n\n### Scan a git diff (CI-friendly)\n\n```bash\ngit diff main | npx agentlint --stdin\n```\n\n### JSON output for CI/CD\n\n```bash\nnpx agentlint . --json --errors-only\n```\n\nExit code `1` if any errors found, `0` otherwise.\n\n## Rules (14)\n\n| Rule | Severity | What it catches |\n|------|----------|----------------|\n| `no-hardcoded-paths` | error | `/Users/john/...`, `/home/deploy/...` |\n| `no-hardcoded-urls` | warning | `http://localhost:3000`, hardcoded ports |\n| `no-unhandled-async` | warning | `async` without `try/catch`, `.then()` without `.catch()` |\n| `no-credential-leak` | error | Hardcoded passwords, API keys, tokens |\n| `no-console-log` | warning | `console.log` instead of structured logging |\n| `no-unbounded-query` | warning | `.find({})`, `SELECT *` without LIMIT |\n| `no-input-validation` | warning | HTTP handlers without input validation |\n| `no-retry-logic` | info | `fetch()` without retry/backoff |\n| `no-todo-fixme` | info | TODO/FIXME/HACK comments |\n| `no-sync-fs` | warning | `readFileSync` and friends |\n| `no-magic-numbers` | info | Unexplained numeric literals |\n| `no-empty-catch` | error | `catch (e) {}` that swallows errors |\n| `no-any-type` | warning | TypeScript `any` type usage |\n| `no-timeout` | warning | `fetch()` without timeout/AbortSignal |\n\n## Why not ESLint?\n\nESLint catches **style** issues. AgentLint catches **production-readiness** issues specific to AI-generated code:\n\n- ESLint won't flag `/Users/john/data.json` as a hardcoded path\n- ESLint won't detect that your Express handler has no input validation\n- ESLint won't notice your `fetch()` has no timeout or retry logic\n- ESLint won't catch `password = \"hunter2\"` as a credential leak\n- Secret scanners (gitleaks, trufflehog) only cover secrets, not architectural issues\n\nAgentLint fills the gap between linting and code review.\n\n## Programmatic API\n\n```typescript\nimport { lintFiles, formatJSON } from 'agentlint';\n\nconst result = await lintFiles('./src');\nconsole.log(formatJSON(result));\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md"}