Pixellint

io.github.aleksUIXv0.31.12更新於 Oct 4, 2026

Validate pixels, postbacks, conversion API payloads, and tracking URLs with spec-backed findings.

已驗證STDIO僅桌面Developer ToolsData & Analytics

概覽

AI 產生的概覽

依廠商規範驗證廣告像素、回傳與轉換 API 酬載,並回傳助理可直接處理的結構化結果。

功能
Pixellint 是針對量測工件(例如追蹤 URL、回傳與轉換 API 酬載)的規範優先驗證器。此 MCP 伺服器提供三個工具:list_rulepacks、list_vendors(可依 category 或 host 篩選),以及 validate_artifact,後者接收工件類型、工件本身,以及選用的 claimed_vendor、expansion_state 與規則包選擇。回應包含帶穩定 ID、嚴重性、證據等級與辨識出的廠商的結構化結果,讓代理無須解析文字即可處理。
適用情境
當助理需要檢查像素、回傳或轉換 API 酬載是否符合廠商公開的參數約定時使用,例如追蹤設定的 QA 或投放變更上線前檢查。也可用於將無法辨識的追蹤主機歸屬到某個廠商。
執行需求
以本機 stdio 程序執行,透過 cargo install pixellint-mcp 安裝。未宣告任何帳號、API 金鑰或環境變數。僅支援桌面端,不提供託管 MCP 端點。
安裝前請注意
它只做驗證,不送出請求、不觸發像素,也不自動修正;修正提示需由使用者自行套用。提交到獨立網頁測試環境的工件可能被儲存,避免貼上敏感值。MCP 伺服器本身不送出工件。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Pixellint,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

Pixellint

[Rust] [crates.io] [npm] [docs.rs] [license]

Pixellint is a spec-first validator for pixels, postbacks, conversion API payloads, and other measurement artifacts. It runs in a terminal, in CI, and in agents, and every finding carries a stable id, a severity, an evidence level, and the document it came from.

Broken pixels cost attribution, QA time, and campaign money. The tooling that exists is fragmented: vendor-specific helpers, enterprise tag auditors, and schema linters that know nothing about ad tech. Pixellint is the open validation layer underneath all of that.

bash
$ pixellint validate url 'https://www.facebook.com/tr?ev=Purchse&[email protected]'rulepack: core  okrulepack: vendor/meta (vendor: meta)  error   vendor.meta.param.id.missing   `id` is required on Meta Pixel requests but is not present. It is the numeric Pixel ID from Events Manager.    fix: Set `id` to the numeric Pixel ID shown in Events Manager.    docs: https://developers.facebook.com/docs/meta-pixel/get-started  warning vendor.meta.param.ev.invalid   `ev` is `Purchse`, which is not one of the documented values: PageView, AddPaymentInfo, ...    fix: Use a standard event name, or confirm the custom event is registered in Events Manager.    docs: https://developers.facebook.com/docs/meta-pixel/reference  error   vendor.meta.pii.unhashed_email A parameter carries what looks like a raw email address. Meta requires customer information to be normalized and SHA-256 hashed before it is sent.    fix: Normalize the value, hash it with SHA-256, and send the hex digest instead of the plain address.    docs: https://developers.facebook.com/docs/meta-pixel/advanced/advanced-matching
2 error(s), 1 warning(s), 0 info message(s) across 2 rulepack(s).

Server-side events are checked in the body, one event at a time:

bash
$ pixellint validate json '{"data":[{"event_name":"Purchase","event_time":1770000000000,    "action_source":"website","user_data":{"em":"[email protected]"}}]}'rulepack: vendor/meta-conversions-api (vendor: meta)  error   vendor.meta-conversions-api.body.event_time.invalid `event_time` must be at most 10 digits, but `1770000000000` has 13. Meta documents it as a Unix timestamp in seconds...    fix: Send seconds, not milliseconds: divide a JavaScript `Date.now()` by 1000 and floor it.  error   vendor.meta-conversions-api.body.purchase_requires_value_and_currency A `Purchase` event is missing `custom_data.value` or `custom_data.currency`.  error   vendor.meta-conversions-api.body.website_requires_source_url The event is marked `action_source: website` but carries no `event_source_url`.

Install

bash
cargo install pixellint          # CLIcargo install pixellint-mcp      # MCP servernpm install pixellint            # library, WASM-backed

Or paste a URL into the playground at pixellint.org, which runs the same engine in your browser. Artifacts you test may be stored; see privacy. Vendor contracts are at pixellint.org/packs/. Guides for pixels, conversion APIs, and consent are at pixellint.org/docs/.

Start with the contracts people actually hit:

Use it

QA

Validate an inline artifact, a file with @path, or stdin with -:

bash
pixellint validate url 'https://px.ads.linkedin.com/collect?pid=123456&fmt=gif'pixellint validate postback @conversion-endpoint.txt --jsoncurl -s "$TAG_URL" | pixellint validate vast -

Callers that already extracted many URLs (Vastlint, an HTML adapter) pass them as a document. Identical values validate once:

bash
pixellint validate-many @extracted.json --json

extracted.json is the wrapper in docs/MULTI_ARTIFACT_SCHEMA.md, or a JSON array of URL strings. Pixellint does not parse VAST, HTML, or GTM.

If the artifact is still a template with unexpanded macros, say so, and macro rules adjust:

bash
pixellint validate url 'https://example.com/pixel?cb=[CACHEBUSTING]' --state template

CI

pixellint validate exits 0 when the artifact is clean or only produced warnings, 1 when any error-severity finding is present, and 2 on a usage or input problem.

yaml
- uses: aleksUIX/[email protected]  with:    path: fixtures/conversion-pixel.txt    kind: url

version selects the CLI release (auto follows the action's own v* tag). Linux and macOS runners, x86_64 and aarch64. The Action downloads a prebuilt tarball from GitHub Releases.

Or install the CLI:

yaml
- name: Validate tracking artifacts  run: |    cargo install pixellint    pixellint validate url @fixtures/conversion-pixel.txt

Agents

bash
cargo install pixellint-mcp

pixellint-mcp speaks MCP over stdio and exposes three tools. It does not send artifacts; there is no hosted MCP on pixellint.org. Playground artifacts on pixellint.org may be stored; see pixellint.org/privacy.

  • MCP Registry name: mcp-name: io.github.aleksUIX/pixellint

  • list_rulepacks

  • list_vendors, optionally filtered by category or attributing a single host

  • validate_artifact, taking artifact_kind, artifact, and optional claimed_vendor, expansion_state, rulepacks, except_rulepacks

Responses include the structured findings, the detected vendors, and a severity summary, so an agent can act on the result without parsing prose.

Node and the browser

js
import { validate, isOk } from "pixellint";
const summary = validate("https://www.facebook.com/tr?ev=Purchase");isOk(summary); // false, the pixel id is missing

Library

rust
use pixellint_core::{ArtifactKind, Engine, ExpansionState, ValidationOptions, ValidationRequest};
let engine = Engine::default();let request = ValidationRequest {    artifact_kind: ArtifactKind::Url,    artifact: "https://www.facebook.com/tr?id=1234567890123456&ev=PageView".to_string(),    claimed_vendor: None,    expansion_state: ExpansionState::Unknown,};
let summary = engine.validate(&request, &ValidationOptions::default())?;assert!(summary.is_ok());

Rulepacks

core runs on every URL-like artifact. Vendor packs run only when the artifact targets their endpoints, so you get vendor checks without asking for them, and nothing fires on an endpoint it does not understand. A conversion API body has no endpoint to go by, so those packs claim it by the shape of the payload.

RulepackCoversEvidence
coreURL validity, transport, credentials, fragments, ad-tech macro handling, IAB consent signalsnormative
vendor/metafacebook.com/tr pixel requestsofficial vendor
vendor/meta-conversions-apiGraph API events edge, URL and JSON event payloadofficial vendor
vendor/google-analyticsGA4 Measurement Protocol, URL and JSON event payloadofficial vendor
vendor/google-analytics-collectThe /g/collect transport the Google tag uses in the browserecosystem reference
vendor/google-tag-managergtm.js, gtag/js, and ns.html loader requestsofficial vendor
vendor/google-ads-conversionGoogle Ads conversion and view-through pixelsofficial vendor
vendor/google-ads-click-conversionsGoogle Ads UploadClickConversions JSONofficial vendor
vendor/floodlightCampaign Manager Floodlight activity tagsofficial vendor
vendor/cm360-tracking-adCM360 tracking ads, dc_trk_aid and dc_trk_cidofficial vendor
vendor/cm360-vast-eventCM360 VAST event pixels, dc_oe on googlesyndicationecosystem reference
vendor/google-ad-managerAd Manager /gampad/ads, iu sz output env gdfp_req correlatorofficial vendor
vendor/adobe-analyticsAdobe Analytics data collection beaconsofficial vendor
vendor/pinterestPinterest tag requests and the noscript fallbackofficial vendor
vendor/pinterest-conversions-apiConversions API events, URL and JSON event payloadofficial vendor
vendor/snapchatSnap Conversions API v3, URL and JSON event payloadofficial vendor
vendor/tiktokTikTok Pixel loader events.js?sdkid=ecosystem reference
vendor/tiktok-events-apiEvents API pixel track and batch, URL and JSON event payloadofficial vendor
vendor/linkedinLinkedIn conversion image pixelsecosystem reference
vendor/linkedin-conversions-apiLinkedIn conversion events, single and batchedofficial vendor
vendor/microsoft-uetMicrosoft Advertising Universal Event Trackingecosystem reference
vendor/microsoft-conversions-apiMicrosoft Advertising CAPI, URL and JSON event payloadofficial vendor
vendor/microsoft-clarityMicrosoft Clarity tag loader, project ID in the pathofficial template
vendor/redditReddit Pixel conversion requestsecosystem reference
vendor/reddit-conversions-apiConversions API v3 events, URL and JSON event payloadofficial vendor
vendor/quora-conversions-apiQuora Conversion API JSON on /ads/v0/conversionofficial vendor
vendor/nextdoor-conversions-apiNextdoor Conversions API JSON on /v2/api/conversions/trackofficial vendor
vendor/x-conversions-apiX conversion API measurement events, URL and JSON payloadofficial vendor
vendor/xX website tag image pixels on analytics.twitter.com, analytics.x.com, and t.co /adsctecosystem reference
vendor/the-trade-deskThe Trade Desk universal pixel iframe on insight.adsrvr.org/track/upofficial vendor
vendor/criteoCriteo OneTag loader ld.js?a=official vendor
vendor/criteo-retail-mediaCriteo Retail Media Delivery API on /delivery/retailmediaofficial vendor
vendor/taboolaTaboola Pixel loader, account ID in the pathofficial vendor
vendor/hotjarHotjar tracking code, site ID in the pathofficial template
vendor/hubspotHubSpot tracking code, Hub ID in the pathofficial template
vendor/awinAwin fall-back conversion pixel and S2S read, including product-level bd[n]official vendor
vendor/awin-basketAwin product-level basket.php product_line rowsofficial vendor
vendor/partnerizePartnerize conversion URL, campaign, clickref, and currency in the pathofficial vendor
vendor/amazon-adsAmazon Ad Tag conversion loader, Tag ID in the pathecosystem reference
vendor/amazon-vfwAmazon DSP Firefly DV measurement, vstevt and dvparams on /dv/ecosystem reference
vendor/doubleverifyDoubleVerify visit.jpg beacons, ctx cmp plc sidecosystem reference
vendor/doubleverify-eventDoubleVerify event.png quartiles, vstevtecosystem reference
vendor/freewheelFreeWheel GET /ad/g/ ad requests, nw and csid or ssidofficial vendor
vendor/outbrainOutbrain conversion pixel on /pixel and /unifiedPixelecosystem reference
vendor/baiduBaidu Tongji collect hm.gif?si=ecosystem reference
vendor/kwaiKwai Pixel loader, sdkid on s1.kwai.netecosystem reference
vendor/hubspot-pixelHubSpot __ptq.gif collect pixelecosystem reference
vendor/cjCJ Affiliate conversion pixel on emjcd.com/uofficial vendor
vendor/impactimpact.com Universal Tracking Tag, UUID in the pathofficial template
vendor/rakutenRakuten Advertising conversion pixel on /epecosystem reference
vendor/brevo-jsBrevo JavaScript tracker sa.js?key=official template
vendor/yahoo-dotYahoo DSP Dot image pixelsofficial vendor
vendor/yandex-metricaYandex Metrica Measurement Protocolofficial vendor
vendor/openaiOpenAI Ads image tagofficial vendor
vendor/openai-conversions-apiOpenAI Ads Conversions API, URL and JSON payloadofficial vendor
vendor/kochavaKochava S2S events, JSON payloadofficial vendor
vendor/singularSingular S2S EVENT, query parametersofficial vendor
vendor/amplitudeAmplitude HTTP V2 event uploadsofficial vendor
vendor/mixpanelMixpanel track ingestionofficial vendor
vendor/posthogPostHog capture, single and batchedofficial vendor
vendor/klaviyoKlaviyo event creationofficial vendor
vendor/brazeBraze user track: events, purchases, attributesofficial vendor
vendor/brevoBrevo Tracker REST trackEventofficial vendor
vendor/segmentSegment HTTP Tracking API, single and batchedofficial vendor
vendor/rudderstackRudderStack HTTP Tracking API and Pixel APIofficial vendor
vendor/adjustAdjust S2S events on s2s.adjust.comofficial vendor
vendor/appsflyerAppsFlyer S2S in-app events, URL and JSON payloadofficial vendor
vendor/appsflyer-onelink-impressionAppsFlyer OneLink impression URLs, template ID and pidofficial vendor
vendor/branchBranch Events API standard and custom eventsofficial vendor
vendor/adformAdform video and click tags on regional domains, banner number bnofficial vendor
vendor/ispotiSpot OTT impression pixel, TC-####-# in the pathofficial vendor
vendor/comscoreComscore Direct collect c1, c2, c7official vendor
vendor/quantcastQuantcast Measure pixel, p-code aofficial vendor
vendor/plausiblePlausible Events API JSONofficial vendor
vendor/matomoMatomo Cloud matomo.php, idsite and recofficial vendor
vendor/parselyParse.ly tracker loader, Site ID in the pathofficial vendor
vendor/crazyeggCrazy Egg tracking script, account and script IDs in the pathofficial template
vendor/chartbeatChartbeat ping, site id h and account UID gofficial vendor
vendor/heapHeap.js 5 configuration loader, environment ID in the pathofficial vendor
vendor/mouseflowMouseflow project script, website ID in the pathofficial vendor
vendor/intercomIntercom Messenger loader, workspace ID in the pathofficial vendor

Vendor directory

Rulepacks cover 133 endpoint families across 77 vendors. The vendor directory covers the rest by attribution: 120 vendor rows and 299 hosts, so an unrecognized pixel still gets a name. Full inventory: docs/STANDARDS.md.

bash
$ pixellint validate url 'https://trc.taboola.com/actions?a=1'rulepack: directory (vendor: taboola)  info  directory.no_rulepack_coverage  This endpoint belongs to Taboola (native). No Pixellint rulepack covers it, so only the core checks ran. The `vendor/taboola` rulepack covers other Taboola endpoints, not this one.

Directory entries make one claim, that a host belongs to a vendor. They carry no parameter contracts, the finding is always info, and attribution never changes an exit code. See docs/VENDOR_DIRECTORY.md.

bash
pixellint list-vendorspixellint list-vendors --json

Select packs per run:

bash
pixellint validate url "$ARTIFACT" --rulepack corepixellint validate url "$ARTIFACT" --except vendor/metapixellint list-rulepacks --json

Full rule inventory with citations: docs/STANDARDS.md.

Evidence levels

Findings say where their authority comes from, and you can hold packs to different standards accordingly:

  • normative: a formal standard such as the WHATWG URL Standard or an RFC
  • official_vendor: a parameter contract the vendor publishes, with the URL
  • official_template: vendor-published templates or SDK behavior
  • ecosystem_reference: consistent real-world behavior the vendor generates in its own UI but does not document
  • heuristic: Pixellint's judgment, labeled as such

The manifest loader refuses to compile a pack that claims official_vendor without citing documentation.

Custom rulepacks

Rulepacks are data, not code. First-party vendor packs are written in the same JSON format you can write for an internal endpoint:

json
{  "id": "custom/acme",  "display_name": "Acme internal pixel",  "description": "Contract for the internal conversion endpoint.",  "vendor": "acme",  "source_level": "heuristic",  "match": { "hosts": ["px.acme.example"], "path_prefixes": ["/collect"] },  "params": [    { "name": "aid", "requirement": "required", "format": { "kind": "integer" } },    { "name": "ev", "requirement": "required", "format": { "kind": "enum", "values": ["view", "purchase"] } }  ]}
bash
pixellint validate url 'https://px.acme.example/collect?ev=purchase' --rulepack-file acme.json

The format is documented in docs/RULEPACK_SCHEMA.md.

Private pixels that only need a name, not a parameter contract, belong in a directory overlay:

bash
pixellint validate url 'https://px.acme.example/collect' --directory-file extra.json

The overlay uses the same entry shape as the built-in directory. New hosts only; it cannot steal a first-party host. Contribute an upstream host through a PR: CONTRIBUTING.md.

What Pixellint does not do

  • It does not extract artifacts from documents. html, js, and gtm are not validation kinds; the CLI exits 2 if you pass them. Callers such as Vastlint parse VAST, HTML, or GTM containers and hand Pixellint the URLs they found. pixellint validate-many wraps those extracted URLs. The document result model is in docs/MULTI_ARTIFACT_SCHEMA.md.
  • It does not fire requests or check whether an endpoint responds.
  • It does not auto-fix. Findings carry fix hints; applying them is on you.

Evidence

Every rule is backed by tests: unit tests in crates/pixellint-core/src/, a golden corpus in fixtures/ with one directory per rulepack, and integration tests that drive the real CLI binary and the real MCP stdio transport.

bash
cargo test --workspace

Benchmark

In-process engine speed over the golden corpus, D1-shaped synthetic pixels, and large validate-many batches:

bash
cargo run -p pixellint-bench --release -- --quickcargo run -p pixellint-bench --releasecargo run -p pixellint-bench --release -- --mode load --heavy

See bench/README.md.

Docs

License

Apache-2.0. Pixellint is not affiliated with or endorsed by any vendor named in its rulepacks; see NOTICE.

來源:README.md,提交 8e445d5

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.31.12最新Oct 4, 2026