Back to Browse

Lintbase MCP Server

Developer ToolsLow Risk9.7MCP RegistryLocal
Free

Server data from the Official MCP Registry

Real-time Firestore schema context for AI coding agents. Stop hallucinating field names.

About

Real-time Firestore schema context for AI coding agents. Stop hallucinating field names.

Security Report

9.7
Low Risk9.7Low Risk

Valid MCP server (3 strong, 1 medium validity signals). No known CVEs in dependencies. โš ๏ธ Package registry links to a different repository than scanned source. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.

9 files analyzed ยท 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-madia333-lintbase-mcp": {
      "args": [
        "-y",
        "lintbase-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

LintBase

Ground Truth for AI Coding Agents. LintBase gives AI agents real-time knowledge of your database schema, security rules, and architecture so they stop hallucinating your codebase.

npx lintbase export-context firestore --key ./service-account.json

npm version npm downloads License: MIT


Why LintBase?

Developers are constantly feeding context files to AI tools like Cursor, Windsurf, Copilot Workspace, and Claude Code. If your agent doesn't understand your real database schema, it writes code that fails in production.

LintBase acts as the bridge. It connects directly to your database, reads the ground truth of your live documents, and generates structured context optimized for AI.

  • ๐Ÿค– Stops AI Hallucinations โ€” Generates exact schema, field presence rates, and types.
  • ๐Ÿ“ Catches Schema Drift โ€” CI protection with lintbase check against schema snapshots.
  • ๐Ÿ”’ Security Context โ€” Highlights missing rules or exposed PII before your AI writes queries.
  • ๐Ÿ’ธ Cost Awareness โ€” Prevents AI from writing unbounded queries on 2M+ document collections.
  • ๐Ÿƒ Universal NoSQL โ€” Works effortlessly with Firestore and MongoDB.

Why not just let the agent read the code?

Because in document databases, the code lies. The real schema is whatever your live documents actually contain, and that drifts away from the code with every half-finished migration, every renamed field, and every previous AI session that wrote in a hurry. An agent inferring the schema from TypeScript interfaces writes plausible queries against a database that no longer exists. The failure is silent: empty results, undefined values, a new field variant living alongside the old one. LintBase reads the documents, not the code.

Limitations (honest ones)

  • Firestore and MongoDB only. Postgres is the obvious gap and it is next.
  • Large collections are sampled, not fully scanned. Presence rates are estimates on multi-million-document collections.
  • The MCP server is newer than the CLI. Expect rough edges there first.

๐Ÿค– AI Context Export (For Cursor, Claude, Windsurf)

The fastest way to give your AI agent perfect database knowledge.

npx lintbase export-context firestore --key ./service-account.json

Output:

/lintbase-context/
โ”œโ”€โ”€ database-schema.md
โ”œโ”€โ”€ collections.md
โ”œโ”€โ”€ security-rules.md
โ”œโ”€โ”€ architecture.md
โ””โ”€โ”€ risk-report.md

Drop the lintbase-context folder into your AI's context window, or mention it in .cursorrules. Your agent will now write perfect, drift-free database queries.


Quick Start

1. Get a service account key

Firebase Console โ†’ Project Settings โ†’ Service Accounts โ†’ Generate new private key

Save the JSON file. Never commit it to git.

2. CI Pipeline Protection (Schema Drift)

LintBase acts as "Version Control for your Schema". Run the snapshot command to create a baseline:

npx lintbase snapshot firestore --key ./service-account.json

Commit .lintbase/schema.json to your repository. Then, add the check command to your CI/CD pipeline (GitHub Actions, GitLab CI):

npx lintbase check firestore --key ./service-account.json --fail-on error

If a query or deployment accidentally deletes a critical field or changes a type (e.g., string to number), your CI build will fail instantly.

3. Run a general scan

npx lintbase scan firestore --key ./service-account.json

You'll see a full report in your terminal:

 LintBase โ€” Firestore Scan
 โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
 Collections scanned:  12
 Documents sampled:    847
 Issues found:         23  (4 errors ยท 11 warnings ยท 8 infos)
 Risk score:           67 / 100  [HIGH]

 ERRORS
 โœ–  users         no-auth-check        Documents readable without authentication
 โœ–  orders        missing-index        Query on `status` + `createdAt` has no composite index
 โœ–  debug_logs    large-collection     Collection has 2.4M docs โ€” estimated $340/mo in reads

 WARNINGS
 โš   products      schema-drift         Field `price` found as both Number and String
 โš   sessions      ttl-missing          No expiry field โ€” stale docs accumulate indefinitely
 ...

3. Save to your dashboard (optional)

Track your database health over time at lintbase.com:

npx lintbase scan firestore \
  --key ./service-account.json \
  --save https://www.lintbase.com \
  --token <your-api-token>

Get your token at lintbase.com/dashboard/settings.


Supported Databases

  • Firestore: npx lintbase scan firestore --key ./sa.json
  • MongoDB: npx lintbase scan mongodb --uri mongodb+srv://user:pass@cluster.mongodb.net/test

๐Ÿค– AI Agent Integration (MCP)

Using Cursor, Claude Desktop, or Windsurf? Install lintbase-mcp to give your AI agent real-time Firestore schema context โ€” so it stops hallucinating field names.

Add to .cursor/mcp.json:

{
  "mcpServers": {
    "lintbase": {
      "command": "npx",
      "args": ["-y", "lintbase-mcp"]
    }
  }
}

Now when you ask your AI "add a field to users", it will check your real schema first before writing a line of code.

โ†’ Full setup guide & tools reference


What it catches

๐Ÿ”’ Security

RuleWhat it detects
no-auth-checkCollections readable/writable without auth
exposed-piiEmail, phone, SSN fields without encryption markers
world-readableDocuments with overly permissive security rules

๐Ÿ’ธ Cost

RuleWhat it detects
large-collectionCollections with 100k+ docs and high read cost
unbounded-queryQueries without limit() that scan entire collections
missing-indexFilter combinations that fall back to full collection scans
debug-collectionCollections that look like temporary data that was never cleaned up

๐Ÿ“ Schema Drift

RuleWhat it detects
type-inconsistencyField stored as different types across documents
missing-required-fieldField present in 90%+ of docs but absent in some
nullable-idReference fields that are sometimes null

โšก Performance

RuleWhat it detects
deep-nestingDocument fields nested > 3 levels deep
large-documentDocuments approaching the 1MB Firestore limit
hot-documentSingle document updated by many users simultaneously
no-paginationCollections without a standard pagination field

Options

lintbase <command> <database> [options]

Commands:
  scan <database>             Scan a database and print diagnostic report
  export-context <database>   Export schema to markdown/JSON for AI agents
  snapshot <database>         Generate local schema snapshot for CI comparison
  check <database>            Run in headless CI mode (fails on schema drift)

Options:
  --key <path>      Path to Firebase service account JSON 
  --uri <uri>       MongoDB connection URI
  --limit <n>       Max documents to sample per collection     [default: 100]
  --max-depth <n>   Firestore: tiers to recurse into subcollections
                    (1 = top-level only)                       [default: 2]
  --fail-on <lvl>   Fail pipeline if issues exceed severity (error, warning, info)
  --save <url>      Dashboard URL to save results
  --token <token>   API token for dashboard (from lintbase.com)
  --collections     Comma-separated list of collections to scan
  -h, --help        Show help

Dashboard

The CLI is free forever. The dashboard visualizes your scan results as an interactive schema map โ€” your credentials never leave your machine.

What Pro gets you via --save:

  • โฌก Schema Map โ€” every collection as a draggable card, with real field names, types, presence rates, and issue badges
  • โ—Ž Health Radar โ€” per-collection spider chart across Schema, Security, Performance, and Cost axes
  • โŠ• Priority Quadrant โ€” 2ร—2 bubble chart of Impact vs. Ease of Fix โ€” tells you what to fix first
  • โ‰‹ Drift Timeline โ€” stored history across scans so you can replay your schema architecture over time.

CLI Local Tooling: 100% Free ยท Pro: $39/month โ€” unlimited history, dashboards, and shared team workflow.


Security

  • Your service account key never leaves your machine โ€” it is only read locally
  • Document sampling is hard-capped at --limit (default 100) to prevent accidental read costs
  • The --save flag only sends the scan summary and issue list โ€” never raw document data

License

MIT ยฉ Mamadou Dia

Reviews

No reviews yet

Be the first to review this server!