Find every regex in a codebase, and report which can be driven into catastrophic backtracking
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add regex-le -- npx -y regex-le-mcp{
"mcpServers": {
"regex-le": {
"command": "npx",
"args": ["-y", "regex-le-mcp"]
}
}
}Resumen de MCP Servers
<p align="center">
<img src="src/assets/images/icon.png" alt="Regex-LE Logo" width="96" height="96"/>
</p>
<h1 align="center">Regex-LE: Zero Hassle Regex Extraction & Validation</h1>
<p align="center">
<b>Find, test, and validate the regex patterns in the current file</b><br/>
<i>Literal patterns, RegExp constructors, ReDoS screening</i>
</p>
<p align="center">
<a href="https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.regex-le">
<img src="https://img.shields.io/badge/Install%20from-VS%20Code-blue?style=for-the-badge&logo=visualstudiocode" alt="Install from VS Code Marketplace" />
</a>
<a href="https://open-vsx.org/extension/OffensiveEdge/regex-le">
<img src="https://img.shields.io/open-vsx/dt/OffensiveEdge/regex-le?style=for-the-badge&label=Open%20VSX&color=blue" alt="Open VSX downloads" />
</a>
<a href="https://www.npmjs.com/package/regex-le-mcp">
<img src="https://img.shields.io/npm/v/regex-le-mcp?style=for-the-badge&label=MCP%20server&color=blue&logo=npm" alt="regex-le-mcp on npm" />
</a>
<a href="https://crates.io/crates/regex-le">
<img src="https://img.shields.io/crates/v/regex-le?style=for-the-badge&label=Rust%20CLI&color=blue&logo=rust" alt="regex-le on crates.io" />
</a>
<a href="https://letools.dev/tools/regex-le">
<img src="https://img.shields.io/badge/LE%20Tools-letools.dev-blue?style=for-the-badge" alt="LE Tools" />
</a>
</p>
---
<p align="center">
<img src="src/assets/images/demo.gif" alt="Regex-LE Demo" style="max-width: 100%; height: auto;" />
</p>
> **Useful?** A star or rating is how other developers find it —
> [★ GitHub](https://github.com/nolindnaidoo/regex-le) ·
> [★ Open VSX](https://open-vsx.org/extension/OffensiveEdge/regex-le/reviews) ·
> [★ Marketplace](https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.regex-le&ssr=false#review-details)
## What it does
Open any file and run one of three commands. **Extract** lists every regex pattern found in the document. **Test** (`Ctrl+Alt+R` / `Cmd+Alt+R`) runs a found — or manually entered — pattern against the file content and reports matches with real line/column positions and capture groups (named groups included). **Validate** checks every found pattern for syntax errors and screens it for catastrophic backtracking, reporting the input that causes it. Works in VS Code and VS Code–based editors like Cursor and VSCodium (installable from Open VSX).
## Install
| Where | What you get | Install |
|---|---|---|
| **VS Code** | The lint *and* the tester, in your editor | [Marketplace](https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.regex-le) |
| **Cursor, VSCodium, Windsurf** | The same extension | [Open VSX](https://open-vsx.org/extension/OffensiveEdge/regex-le) |
| **A terminal or a CI step** | The same run over a whole tree, with exit codes | `cargo install regex-le` · [crates.io](https://crates.io/crates/regex-le) |
| **Any MCP agent, via Node** | `extract_patterns` over stdio | `npx regex-le-mcp` · [npm](https://www.npmjs.com/package/regex-le-mcp) |
| **Zed** | The MCP server as a context server | [add it by hand](https://zed.dev/docs/ai/mcp) *(no listing yet)* |
## Use it from an AI agent
The same engine runs as an [MCP](https://modelcontextprotocol.io) server, so an agent can call it directly instead of you running a command.
| Editor | How |
|---|---|
| **VS Code** 1.101+ | Nothing to install — the extension registers `extract_patterns` with agent mode |
| **Zed** | No listing yet — [add the MCP server by hand](https://zed.dev/docs/ai/mcp) |
| **Claude Code** | `claude mcp add regex-le -- npx -y regex-le-mcp` |
| **Cursor, Windsurf, anything else** | point it at `npx regex-le-mcp` |
```
extract_patterns(content, format?, filename?, maxResults?)
```
Returns every pattern with its flags, 1-based position and a **ReDoS verdict**, so "are any of the regexes in this file dangerous?" is one call rather than two. A verdict that reports a blow-up carries the `witness` that caused it, so an agent can check the finding instead of trusting it.
The server takes content and returns data — it reads no files and makes no network requests of its own. Published as [`regex-le-mcp`](https://www.npmjs.com/package/regex-le-mcp) on npm and as `io.github.nolindnaidoo/regex-le` in the [MCP registry](https://registry.modelcontextprotocol.io).
<details>
<summary><b>Configuring it by hand</b> — any host with an MCP config file</summary>
Most hosts read a JSON config. Add one entry:
```json
{
"mcpServers": {
"regex-le": {
"command": "npx",
"args": ["-y", "regex-le-mcp"]
}
}
}
```
`-y` skips the install prompt on first run. Pin a version if you would rather not track releases — `regex-le-mcp@2.5.0`.
Prefer not to go through `npx` on every launch? Install it once and point at the binary instead:
```bash
npm install -g regex-le-mcp
```
```json
{
"mcpServers": {
"regex-le": { "command": "regex-le-mcp" }
}
}
```
It speaks MCP over stdio and needs no environment variables, no API key and no configuration of its own. To check it before wiring it into anything:
```bash
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | npx -y regex-le-mcp
```
That prints the tool list and exits — if you see `extract_patterns`, the server works.
</details>
## What gets extracted
Extraction scans the whole document, so constructors split across lines are found too. The document's language chooses which spellings to look for:
| Language | Form | Example |
|---|---|---|
| JavaScript, TypeScript, Ruby | Literal | `/[a-z]+/gi` |
| JavaScript, TypeScript | Constructor | `new RegExp('\\d{4}-\\d{2}', 'g')` — including multiline |
| JavaScript, TypeScript | Bare constructor call | `RegExp("x\|y", "i")` |
| Python | `re.compile` and friends | `re.compile(r'(a+)+')` |
| Rust | `Regex::new`, `RegexBuilder::new` | `Regex::new(r"(a+)+")` |
| Go | `regexp.MustCompile`, `regexp.Compile` | ``regexp.MustCompile(`(a+)+`)`` |
| Java | `Pattern.compile`, `Pattern.matches` | `Pattern.compile("(a+)+")` |
| Ruby | `Regexp.new` | `Regexp.new('(a+)+')` |
| PHP | `preg_match` and friends | `preg_match('/(a+)+/i', $s)` |
| C# | `new Regex(…)`, `Regex.IsMatch` and friends | `new Regex(@"(a+)+")` |
A language nothing recognises is not a refusal — every spelling above is looked for. Naming it buys precision: a Python file is not scanned for bare `/…/`, so `#!/usr/bin/env python` stops reading as a pattern.
What is deliberately **not** extracted:
- Division, dates, and filesystem paths (`a / b`, `10/29/2025`, `/usr/local/bin`): a `/` preceded by an identifier, number, `)`, `]`, `.`, or another `/` is not treated as a regex — after keywords like `return`, it is. That question is only asked where a bare `/…/` is legal.
- Candidates that are not a well-formed regular expression in any of these languages, or with invalid/duplicate flags. Another language's spelling is not a syntax error: `re.compile(r'(?P<word>\w+)+@')` is reported as written, and still flagged.
- Constructor calls whose pattern argument is a variable, or a template literal with a `${…}` substitution. String literals, static template literals and `` String.raw`…` `` are read.
- Flags, on anything but a JavaScript literal or constructor: every other language sets them with constants, builder methods or an inline `(?i)` rather than a string argument.
- **Anything written in a comment or a string.** A JSDoc block explaining a hazard, a commented-out line, a Python docstring with an example — none of them is code, and reporting one fails a build over a sentence. The rule is about where a candidate *starts*, so `re.compile(r"(a+)+b")` keeps its quoted argument while a docstring holding that whole line is prose. Only when the language is known: a document nothing recognises is scanned as written, because a comment rule guessed from the wrong grammar would drop real patterns instead of phantom ones.
Duplicate pattern+flags pairs are listed once. This is lexing by heuristic, not a parser for nine languages: a slash inside a string can still be picked up when its context looks expression-like.
## ReDoS screening
`Validate` (and `Test`, before running a risky pattern) reports a pattern **only when an input was found that demonstrably drives it into catastrophic backtracking** — and reports that input alongside it, as the `witness`.
Your pattern is never run. It is compiled to an automaton, and that automaton is walked the way a backtracking engine walks one — depth-first, every edge in order, a dead end unwound rather than remembered — while the steps are counted. An attack string is built, pumped at two lengths, and measured against a step budget. So a finding is falsifiable: run the witness and watch.
Nothing is reported on the strength of how a pattern is *shaped*. Shape is a poor predictor in both directions: `^[a-z0-9]+(?:-[a-z0-9]+)*$` looks dangerous and is not, because every iteration must eat a `-` the inner class cannot produce, while `(.*a){20}` looks bounded and is not. A separator forcing the split is a fact about strings, so no test on syntax settles it.
**Silence is not a clearance.** A pattern this cannot read — a backreference, lookaround, syntax it does not parse — comes back as `not decided: <reason>`, never as safe.
The reports also include a rough performance score based on execution time relative to input size — treat it as a hint, not a benchmark (memory is not measured).
## The CLI
The same lint runs from a terminal or a shell pipeline: a Rust CLI in
[`crate/`](crate/README.md), sharing one corpus with the extension —
[`crate/fixtures/`](crate/fixtures/) — so the two can never read a
document differently.
```bash
regex-le . # every vulnerable pattern in the tree
regex-le --severity high src/ # only the exponential shapes
regex-le --all src/ # every pattern, vulnerable or not
regex-le mcp # the same lint over MCP on stdio
```Lo que la gente pregunta sobre regex-le
¿Qué es nolindnaidoo/regex-le?
+
nolindnaidoo/regex-le es mcp servers para el ecosistema de Claude AI. Find every regex in a codebase, and report which can be driven into catastrophic backtracking Tiene 2 estrellas en GitHub y su última actualización registrada es del 2026-09-30.
¿Cómo se instala regex-le?
+
Puedes instalar regex-le clonando el repositorio (https://github.com/nolindnaidoo/regex-le) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar nolindnaidoo/regex-le?
+
Nuestro agente de seguridad ha analizado nolindnaidoo/regex-le y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene nolindnaidoo/regex-le?
+
nolindnaidoo/regex-le es mantenido por nolindnaidoo. La última actividad registrada en GitHub es del 2026-09-30, con 0 issues abiertos.
¿Hay alternativas a regex-le?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega regex-le en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/nolindnaidoo-regex-le)<a href="https://claudewave.com/repo/nolindnaidoo-regex-le"><img src="https://claudewave.com/api/badge/nolindnaidoo-regex-le" alt="Featured on ClaudeWave: nolindnaidoo/regex-le" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.