pkh covered the package lifecycle but never validated the packaging itself: broken control stanzas, unparsable changelog versions or uncommitted debian/ edits only surfaced at build or upload time. pkh lint lints a source tree with day-one lintian parity plus a native Rust engine for the checks lintian cannot have. The wrapper reuses the pkh build output next to the tree when it matches the current changelog entry and no tree content is newer (mtime walk, skipping .git/.pc), else packs fresh with dpkg-source -b using weak gzip compression (the artifact is ephemeral; xz dominated the run at 9.8 s versus 2.7 s on a 111 MB tree) and symlinks quilt orig tarballs from the tree's parent, which dpkg-source searches in cwd. Findings are parsed from the installed lintian into a unified report, deduplicated by tag name against the native engine, and rendered lintian-shaped (<L>: <pkg> <type>: <tag> <details>) as text or JSON, colorized at render time (--color auto/always/never). Exit codes follow lintian's contract (0 clean, 1 findings at/above --fail-on, 2 runtime error); lintian's own exit code is ignored because it uses 2 both for findings and for runtime errors. -d/--dist maps to lintian --profile so the target distro's rules apply even on a foreign host. The native engine hosts the first workflow check lintian cannot know: pkh-debian-changes-not-committed flags debian/ content that is not committed to git, since the pkh flow builds and uploads the tree as-is. Checks register in a static registry validated by a unit test, and the wrapper's parser is pinned by golden tests captured from lintian 2.129 output. Strategies for lintian's Ubuntu blind spots (its vendor data there is one file plus 14 disabled tags) are specced in plans/pkh-lint.md, deliberately not implemented yet.