org.lexlint/lexlint
name:org.lexlint/lexlint
Compliance lint for AI, scraping, and privacy law. Cited findings in 200 or more jurisdictions.
- transport:
- remote
- credential class:
- self-provisionable
Owner verification
Not yet verified. Verifying proves you control this server and is free, permanently — it never changes a published score.
Start verification →Tools
- check_accessshallow
Preflight. Reports whether an UnGovr Open Data key reached LexLint, whether it is valid, how much of today's free allowance is left and when it resets, how current the corpus is, and whether the LexLint plugin you are running is the latest published one. Call this first: a missing key otherwise surfaces several steps later as a rejected tool call. Costs one upstream request, always: the optional jurisdictions preview below rides this same request rather than spending a second one. It also returns which model families this procedure is exercised against: lowercase your own model id, split it into words on every character that is not a letter, and if none of those words is exactly a token from tested_model_families, show the developer model_notice and let them decide whether to continue. Whole words, never substrings: solar-pro is not sol. Run the lint either way, and print the notice without asking when no developer is present. Nothing about your model is sent here and no argument carries one; the comparison is yours to make.
- get_lawshallow
One jurisdiction's law from the UnGovr corpus, across all five topics LexLint covers: AI law, scraping/crawling and access legality, personal-data and biometric privacy, age-gating and age verification, and news-aggregation law. Returns the instruments (citations, status, behavior categories, as_of_date) together with the jurisdiction-level crawl posture: verdict-level crawl policy, per-scenario access matrix, robots.txt legal weight, and TDM opt-out status. Resolution walks to the most specific jurisdiction with data and reports the walk in resolved_from. ONE call answers an AI question, a scraping question, a privacy question, an age-gating question and a news-aggregation question: they are the same payload, so do not call this five times for one jurisdiction. Research summary, NOT legal advice and NOT authorization to access any system. Requires X-API-Key (passed through to data.ungovr.org).
- resolve_domain_jurisdictionshallow
Best-effort mapping from a domain to the jurisdiction whose law governs its OPERATOR, for feeding into the other tools. Never uses server or edge-node location; IP addresses are refused. Costs one to four upstream requests, varying with how many domain-label candidates it tries before a match; a fall-back to top-level-domain inference costs nothing further. Not part of a lint's own five-request total (check_access, set_profile, run_lint): call this only to derive a jurisdiction from a domain rather than declaring one. Requires X-API-Key (passed through to data.ungovr.org).
- run_lintshallow
Step 2 of the lint, and the one that returns findings. Pass the activities and jurisdictions set_profile validated, and get lint-style findings: which obligations apply, with severity (warn/info), citation, as_of_date, staleness, and confidence. warn: a live obligation binds the profile (obligation), a posture finding needs attention (posture), or LexLint lacks current data for a declared jurisdiction (coverage). info: context rather than a live duty, and kind says which of three kinds it is: an instrument LexLint cannot say is currently binding (pending), a jurisdiction-wide statement of how the local law treats crawling as a whole, binding nobody on its own (posture), or a note about what was not reported (coverage). LexLint never reports error: a lint cannot be sure something is prohibited, so it will not say so. Obligations are matched from AI, scraping and privacy law; age-gating and news-aggregation law are in the corpus and are served by get_law, but carry no activity tags yet, so they raise no obligation finding here. A finding whose instrument has a LexLint page carries note_url; show the citation as a link to it, and never construct that URL yourself. A jurisdiction LexLint has no current data for is a WARNING, never a silent pass, and the passing state is "no basic issues found", never "compliant". This is a lint for catching basic issues early, NOT legal advice and NOT a compliance certification. Costs three upstream requests for any number of declared jurisdictions: it reads the whole published corpus and filters to your declaration in memory, rather than one request per jurisdiction. A repeat lint against a corpus that has not moved since an earlier one can cost fewer, served from this key's own cache. Requires X-API-Key (an UnGovr Open Data key, passed through and metered upstream; get one at https://ungovr.org/settings/api-keys?cli=lexlint).
- set_profileshallow
Step 1 of the lint. Declare what the app does (activities) and where it will operate (jurisdiction slugs); get back the validated, canonical profile plus what the corpus holds for each jurisdiction, so the depth of a run is known before it is spent. Write the returned profile into the project's lexlint.yml and pass it to run_lint. Stores nothing server-side. An unknown activity or a malformed slug is refused here rather than silently weakening a lint later. Costs one upstream request for any number of jurisdictions. It answers the same coverage question check_access's own jurisdictions preview does, off a request check_access spends either way, so asking both is redundant, never costlier: they just repeat the same answer. Requires X-API-Key (an UnGovr Open Data key, passed through and metered upstream; get one at https://ungovr.org/settings/api-keys?cli=lexlint).
- submit_feedbackshallow
Send the developer's feedback on LexLint to the people who build it, recorded against their UnGovr account so we can write back. Run this ONLY when the developer asks for it: never volunteer it, never offer it as a next step after a lint, and never run it in a headless or CI session where nobody can approve anything. Draft the usage summary from what you actually did this session, print the exact payload, and send only what they have explicitly approved, unchanged. Never read the session transcript to build it: a key pasted into a session is recorded there, and a summary built from one would carry the developer's own key to us. One submission per session. Requires X-API-Key.
Embed this server’s score
Tool count and median score across every tool in this server’s corpus — honest in a way a single cherry-picked tool’s badge wouldn’t be.
[](https://vouch.tools/servers/1ea0165d-a3a6-4d9d-9198-b1ea3c440a0b)