Pixellint

io.github.aleksUIXv0.31.12更新于 Oct 4, 2026

Validate pixels, postbacks, conversion API payloads, and tracking URLs with spec-backed findings.

已验证STDIO仅桌面Developer ToolsData & Analytics

概览

AI 生成的概览

依据厂商规范校验广告像素、回传和转化 API 载荷,并返回助手可直接处理的结构化结果。

功能
Pixellint 是一个面向测量工件(如跟踪 URL、回传和转化 API 载荷)的规范优先校验器。该 MCP 服务器提供三个工具:list_rulepacks、list_vendors(可按 category 或 host 过滤)以及 validate_artifact,后者接收工件类型、工件本身,以及可选的 claimed_vendor、expansion_state 和规则包选择。响应包含带稳定 ID、严重级别、证据等级和识别出的厂商的结构化结果,便于代理直接处理而无需解析文本。
适用场景
当助手需要检查像素、回传或转化 API 载荷是否符合厂商公开的参数约定时使用,例如跟踪配置的 QA 或投放变更上线前检查。也可用于把无法识别的跟踪主机归属到某个厂商。
运行要求
以本地 stdio 进程运行,通过 cargo install pixellint-mcp 安装。未声明任何账号、API 密钥或环境变量。仅支持桌面端,不提供托管 MCP 端点。
安装前请注意
它只做校验,不发送请求、不触发像素,也不自动修复;修复提示需由用户自行应用。提交到独立网页演练场的工件可能被存储,避免粘贴敏感值。MCP 服务器本身不发送工件。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Pixellint,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

Pixellint

[Rust] [crates.io] [npm] [docs.rs] [license]

Pixellint is a spec-first validator for pixels, postbacks, conversion API payloads, and other measurement artifacts. It runs in a terminal, in CI, and in agents, and every finding carries a stable id, a severity, an evidence level, and the document it came from.

Broken pixels cost attribution, QA time, and campaign money. The tooling that exists is fragmented: vendor-specific helpers, enterprise tag auditors, and schema linters that know nothing about ad tech. Pixellint is the open validation layer underneath all of that.

bash
$ pixellint validate url 'https://www.facebook.com/tr?ev=Purchse&[email protected]'rulepack: core  okrulepack: vendor/meta (vendor: meta)  error   vendor.meta.param.id.missing   `id` is required on Meta Pixel requests but is not present. It is the numeric Pixel ID from Events Manager.    fix: Set `id` to the numeric Pixel ID shown in Events Manager.    docs: https://developers.facebook.com/docs/meta-pixel/get-started  warning vendor.meta.param.ev.invalid   `ev` is `Purchse`, which is not one of the documented values: PageView, AddPaymentInfo, ...    fix: Use a standard event name, or confirm the custom event is registered in Events Manager.    docs: https://developers.facebook.com/docs/meta-pixel/reference  error   vendor.meta.pii.unhashed_email A parameter carries what looks like a raw email address. Meta requires customer information to be normalized and SHA-256 hashed before it is sent.    fix: Normalize the value, hash it with SHA-256, and send the hex digest instead of the plain address.    docs: https://developers.facebook.com/docs/meta-pixel/advanced/advanced-matching
2 error(s), 1 warning(s), 0 info message(s) across 2 rulepack(s).

Server-side events are checked in the body, one event at a time:

bash
$ pixellint validate json '{"data":[{"event_name":"Purchase","event_time":1770000000000,    "action_source":"website","user_data":{"em":"[email protected]"}}]}'rulepack: vendor/meta-conversions-api (vendor: meta)  error   vendor.meta-conversions-api.body.event_time.invalid `event_time` must be at most 10 digits, but `1770000000000` has 13. Meta documents it as a Unix timestamp in seconds...    fix: Send seconds, not milliseconds: divide a JavaScript `Date.now()` by 1000 and floor it.  error   vendor.meta-conversions-api.body.purchase_requires_value_and_currency A `Purchase` event is missing `custom_data.value` or `custom_data.currency`.  error   vendor.meta-conversions-api.body.website_requires_source_url The event is marked `action_source: website` but carries no `event_source_url`.

Install

bash
cargo install pixellint          # CLIcargo install pixellint-mcp      # MCP servernpm install pixellint            # library, WASM-backed

Or paste a URL into the playground at pixellint.org, which runs the same engine in your browser. Artifacts you test may be stored; see privacy. Vendor contracts are at pixellint.org/packs/. Guides for pixels, conversion APIs, and consent are at pixellint.org/docs/.

Start with the contracts people actually hit:

Use it

QA

Validate an inline artifact, a file with @path, or stdin with -:

bash
pixellint validate url 'https://px.ads.linkedin.com/collect?pid=123456&fmt=gif'pixellint validate postback @conversion-endpoint.txt --jsoncurl -s "$TAG_URL" | pixellint validate vast -

Callers that already extracted many URLs (Vastlint, an HTML adapter) pass them as a document. Identical values validate once:

bash
pixellint validate-many @extracted.json --json

extracted.json is the wrapper in docs/MULTI_ARTIFACT_SCHEMA.md, or a JSON array of URL strings. Pixellint does not parse VAST, HTML, or GTM.

If the artifact is still a template with unexpanded macros, say so, and macro rules adjust:

bash
pixellint validate url 'https://example.com/pixel?cb=[CACHEBUSTING]' --state template

CI

pixellint validate exits 0 when the artifact is clean or only produced warnings, 1 when any error-severity finding is present, and 2 on a usage or input problem.

yaml
- uses: aleksUIX/[email protected]  with:    path: fixtures/conversion-pixel.txt    kind: url

version selects the CLI release (auto follows the action's own v* tag). Linux and macOS runners, x86_64 and aarch64. The Action downloads a prebuilt tarball from GitHub Releases.

Or install the CLI:

yaml
- name: Validate tracking artifacts  run: |    cargo install pixellint    pixellint validate url @fixtures/conversion-pixel.txt

Agents

bash
cargo install pixellint-mcp

pixellint-mcp speaks MCP over stdio and exposes three tools. It does not send artifacts; there is no hosted MCP on pixellint.org. Playground artifacts on pixellint.org may be stored; see pixellint.org/privacy.

  • MCP Registry name: mcp-name: io.github.aleksUIX/pixellint

  • list_rulepacks

  • list_vendors, optionally filtered by category or attributing a single host

  • validate_artifact, taking artifact_kind, artifact, and optional claimed_vendor, expansion_state, rulepacks, except_rulepacks

Responses include the structured findings, the detected vendors, and a severity summary, so an agent can act on the result without parsing prose.

Node and the browser

js
import { validate, isOk } from "pixellint";
const summary = validate("https://www.facebook.com/tr?ev=Purchase");isOk(summary); // false, the pixel id is missing

Library

rust
use pixellint_core::{ArtifactKind, Engine, ExpansionState, ValidationOptions, ValidationRequest};
let engine = Engine::default();let request = ValidationRequest {    artifact_kind: ArtifactKind::Url,    artifact: "https://www.facebook.com/tr?id=1234567890123456&ev=PageView".to_string(),    claimed_vendor: None,    expansion_state: ExpansionState::Unknown,};
let summary = engine.validate(&request, &ValidationOptions::default())?;assert!(summary.is_ok());

Rulepacks

core runs on every URL-like artifact. Vendor packs run only when the artifact targets their endpoints, so you get vendor checks without asking for them, and nothing fires on an endpoint it does not understand. A conversion API body has no endpoint to go by, so those packs claim it by the shape of the payload.

RulepackCoversEvidence
coreURL validity, transport, credentials, fragments, ad-tech macro handling, IAB consent signalsnormative
vendor/metafacebook.com/tr pixel requestsofficial vendor
vendor/meta-conversions-apiGraph API events edge, URL and JSON event payloadofficial vendor
vendor/google-analyticsGA4 Measurement Protocol, URL and JSON event payloadofficial vendor
vendor/google-analytics-collectThe /g/collect transport the Google tag uses in the browserecosystem reference
vendor/google-tag-managergtm.js, gtag/js, and ns.html loader requestsofficial vendor
vendor/google-ads-conversionGoogle Ads conversion and view-through pixelsofficial vendor
vendor/google-ads-click-conversionsGoogle Ads UploadClickConversions JSONofficial vendor
vendor/floodlightCampaign Manager Floodlight activity tagsofficial vendor
vendor/cm360-tracking-adCM360 tracking ads, dc_trk_aid and dc_trk_cidofficial vendor
vendor/cm360-vast-eventCM360 VAST event pixels, dc_oe on googlesyndicationecosystem reference
vendor/google-ad-managerAd Manager /gampad/ads, iu sz output env gdfp_req correlatorofficial vendor
vendor/adobe-analyticsAdobe Analytics data collection beaconsofficial vendor
vendor/pinterestPinterest tag requests and the noscript fallbackofficial vendor
vendor/pinterest-conversions-apiConversions API events, URL and JSON event payloadofficial vendor
vendor/snapchatSnap Conversions API v3, URL and JSON event payloadofficial vendor
vendor/tiktokTikTok Pixel loader events.js?sdkid=ecosystem reference
vendor/tiktok-events-apiEvents API pixel track and batch, URL and JSON event payloadofficial vendor
vendor/linkedinLinkedIn conversion image pixelsecosystem reference
vendor/linkedin-conversions-apiLinkedIn conversion events, single and batchedofficial vendor
vendor/microsoft-uetMicrosoft Advertising Universal Event Trackingecosystem reference
vendor/microsoft-conversions-apiMicrosoft Advertising CAPI, URL and JSON event payloadofficial vendor
vendor/microsoft-clarityMicrosoft Clarity tag loader, project ID in the pathofficial template
vendor/redditReddit Pixel conversion requestsecosystem reference
vendor/reddit-conversions-apiConversions API v3 events, URL and JSON event payloadofficial vendor
vendor/quora-conversions-apiQuora Conversion API JSON on /ads/v0/conversionofficial vendor
vendor/nextdoor-conversions-apiNextdoor Conversions API JSON on /v2/api/conversions/trackofficial vendor
vendor/x-conversions-apiX conversion API measurement events, URL and JSON payloadofficial vendor
vendor/xX website tag image pixels on analytics.twitter.com, analytics.x.com, and t.co /adsctecosystem reference
vendor/the-trade-deskThe Trade Desk universal pixel iframe on insight.adsrvr.org/track/upofficial vendor
vendor/criteoCriteo OneTag loader ld.js?a=official vendor
vendor/criteo-retail-mediaCriteo Retail Media Delivery API on /delivery/retailmediaofficial vendor
vendor/taboolaTaboola Pixel loader, account ID in the pathofficial vendor
vendor/hotjarHotjar tracking code, site ID in the pathofficial template
vendor/hubspotHubSpot tracking code, Hub ID in the pathofficial template
vendor/awinAwin fall-back conversion pixel and S2S read, including product-level bd[n]official vendor
vendor/awin-basketAwin product-level basket.php product_line rowsofficial vendor
vendor/partnerizePartnerize conversion URL, campaign, clickref, and currency in the pathofficial vendor
vendor/amazon-adsAmazon Ad Tag conversion loader, Tag ID in the pathecosystem reference
vendor/amazon-vfwAmazon DSP Firefly DV measurement, vstevt and dvparams on /dv/ecosystem reference
vendor/doubleverifyDoubleVerify visit.jpg beacons, ctx cmp plc sidecosystem reference
vendor/doubleverify-eventDoubleVerify event.png quartiles, vstevtecosystem reference
vendor/freewheelFreeWheel GET /ad/g/ ad requests, nw and csid or ssidofficial vendor
vendor/outbrainOutbrain conversion pixel on /pixel and /unifiedPixelecosystem reference
vendor/baiduBaidu Tongji collect hm.gif?si=ecosystem reference
vendor/kwaiKwai Pixel loader, sdkid on s1.kwai.netecosystem reference
vendor/hubspot-pixelHubSpot __ptq.gif collect pixelecosystem reference
vendor/cjCJ Affiliate conversion pixel on emjcd.com/uofficial vendor
vendor/impactimpact.com Universal Tracking Tag, UUID in the pathofficial template
vendor/rakutenRakuten Advertising conversion pixel on /epecosystem reference
vendor/brevo-jsBrevo JavaScript tracker sa.js?key=official template
vendor/yahoo-dotYahoo DSP Dot image pixelsofficial vendor
vendor/yandex-metricaYandex Metrica Measurement Protocolofficial vendor
vendor/openaiOpenAI Ads image tagofficial vendor
vendor/openai-conversions-apiOpenAI Ads Conversions API, URL and JSON payloadofficial vendor
vendor/kochavaKochava S2S events, JSON payloadofficial vendor
vendor/singularSingular S2S EVENT, query parametersofficial vendor
vendor/amplitudeAmplitude HTTP V2 event uploadsofficial vendor
vendor/mixpanelMixpanel track ingestionofficial vendor
vendor/posthogPostHog capture, single and batchedofficial vendor
vendor/klaviyoKlaviyo event creationofficial vendor
vendor/brazeBraze user track: events, purchases, attributesofficial vendor
vendor/brevoBrevo Tracker REST trackEventofficial vendor
vendor/segmentSegment HTTP Tracking API, single and batchedofficial vendor
vendor/rudderstackRudderStack HTTP Tracking API and Pixel APIofficial vendor
vendor/adjustAdjust S2S events on s2s.adjust.comofficial vendor
vendor/appsflyerAppsFlyer S2S in-app events, URL and JSON payloadofficial vendor
vendor/appsflyer-onelink-impressionAppsFlyer OneLink impression URLs, template ID and pidofficial vendor
vendor/branchBranch Events API standard and custom eventsofficial vendor
vendor/adformAdform video and click tags on regional domains, banner number bnofficial vendor
vendor/ispotiSpot OTT impression pixel, TC-####-# in the pathofficial vendor
vendor/comscoreComscore Direct collect c1, c2, c7official vendor
vendor/quantcastQuantcast Measure pixel, p-code aofficial vendor
vendor/plausiblePlausible Events API JSONofficial vendor
vendor/matomoMatomo Cloud matomo.php, idsite and recofficial vendor
vendor/parselyParse.ly tracker loader, Site ID in the pathofficial vendor
vendor/crazyeggCrazy Egg tracking script, account and script IDs in the pathofficial template
vendor/chartbeatChartbeat ping, site id h and account UID gofficial vendor
vendor/heapHeap.js 5 configuration loader, environment ID in the pathofficial vendor
vendor/mouseflowMouseflow project script, website ID in the pathofficial vendor
vendor/intercomIntercom Messenger loader, workspace ID in the pathofficial vendor

Vendor directory

Rulepacks cover 133 endpoint families across 77 vendors. The vendor directory covers the rest by attribution: 120 vendor rows and 299 hosts, so an unrecognized pixel still gets a name. Full inventory: docs/STANDARDS.md.

bash
$ pixellint validate url 'https://trc.taboola.com/actions?a=1'rulepack: directory (vendor: taboola)  info  directory.no_rulepack_coverage  This endpoint belongs to Taboola (native). No Pixellint rulepack covers it, so only the core checks ran. The `vendor/taboola` rulepack covers other Taboola endpoints, not this one.

Directory entries make one claim, that a host belongs to a vendor. They carry no parameter contracts, the finding is always info, and attribution never changes an exit code. See docs/VENDOR_DIRECTORY.md.

bash
pixellint list-vendorspixellint list-vendors --json

Select packs per run:

bash
pixellint validate url "$ARTIFACT" --rulepack corepixellint validate url "$ARTIFACT" --except vendor/metapixellint list-rulepacks --json

Full rule inventory with citations: docs/STANDARDS.md.

Evidence levels

Findings say where their authority comes from, and you can hold packs to different standards accordingly:

  • normative: a formal standard such as the WHATWG URL Standard or an RFC
  • official_vendor: a parameter contract the vendor publishes, with the URL
  • official_template: vendor-published templates or SDK behavior
  • ecosystem_reference: consistent real-world behavior the vendor generates in its own UI but does not document
  • heuristic: Pixellint's judgment, labeled as such

The manifest loader refuses to compile a pack that claims official_vendor without citing documentation.

Custom rulepacks

Rulepacks are data, not code. First-party vendor packs are written in the same JSON format you can write for an internal endpoint:

json
{  "id": "custom/acme",  "display_name": "Acme internal pixel",  "description": "Contract for the internal conversion endpoint.",  "vendor": "acme",  "source_level": "heuristic",  "match": { "hosts": ["px.acme.example"], "path_prefixes": ["/collect"] },  "params": [    { "name": "aid", "requirement": "required", "format": { "kind": "integer" } },    { "name": "ev", "requirement": "required", "format": { "kind": "enum", "values": ["view", "purchase"] } }  ]}
bash
pixellint validate url 'https://px.acme.example/collect?ev=purchase' --rulepack-file acme.json

The format is documented in docs/RULEPACK_SCHEMA.md.

Private pixels that only need a name, not a parameter contract, belong in a directory overlay:

bash
pixellint validate url 'https://px.acme.example/collect' --directory-file extra.json

The overlay uses the same entry shape as the built-in directory. New hosts only; it cannot steal a first-party host. Contribute an upstream host through a PR: CONTRIBUTING.md.

What Pixellint does not do

  • It does not extract artifacts from documents. html, js, and gtm are not validation kinds; the CLI exits 2 if you pass them. Callers such as Vastlint parse VAST, HTML, or GTM containers and hand Pixellint the URLs they found. pixellint validate-many wraps those extracted URLs. The document result model is in docs/MULTI_ARTIFACT_SCHEMA.md.
  • It does not fire requests or check whether an endpoint responds.
  • It does not auto-fix. Findings carry fix hints; applying them is on you.

Evidence

Every rule is backed by tests: unit tests in crates/pixellint-core/src/, a golden corpus in fixtures/ with one directory per rulepack, and integration tests that drive the real CLI binary and the real MCP stdio transport.

bash
cargo test --workspace

Benchmark

In-process engine speed over the golden corpus, D1-shaped synthetic pixels, and large validate-many batches:

bash
cargo run -p pixellint-bench --release -- --quickcargo run -p pixellint-bench --releasecargo run -p pixellint-bench --release -- --mode load --heavy

See bench/README.md.

Docs

License

Apache-2.0. Pixellint is not affiliated with or endorsed by any vendor named in its rulepacks; see NOTICE.

来源:README.md,提交 8e445d5

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.31.12最新Oct 4, 2026