Find every regex in a codebase, and report which can be driven into catastrophic backtracking
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add regex-le -- npx -y regex-le-mcp{
"mcpServers": {
"regex-le": {
"command": "npx",
"args": ["-y", "regex-le-mcp"]
}
}
}MCP Servers overview
<p align="center">
<img src="src/assets/images/icon.png" alt="Regex-LE Logo" width="96" height="96"/>
</p>
<h1 align="center">Regex-LE: Zero Hassle Regex Extraction & Validation</h1>
<p align="center">
<b>Find, test, and validate the regex patterns in the current file</b><br/>
<i>Literal patterns, RegExp constructors, ReDoS screening</i>
</p>
<p align="center">
<a href="https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.regex-le">
<img src="https://img.shields.io/badge/Install%20from-VS%20Code-blue?style=for-the-badge&logo=visualstudiocode" alt="Install from VS Code Marketplace" />
</a>
<a href="https://open-vsx.org/extension/OffensiveEdge/regex-le">
<img src="https://img.shields.io/open-vsx/dt/OffensiveEdge/regex-le?style=for-the-badge&label=Open%20VSX&color=blue" alt="Open VSX downloads" />
</a>
<a href="https://www.npmjs.com/package/regex-le-mcp">
<img src="https://img.shields.io/npm/v/regex-le-mcp?style=for-the-badge&label=MCP%20server&color=blue&logo=npm" alt="regex-le-mcp on npm" />
</a>
<a href="https://crates.io/crates/regex-le">
<img src="https://img.shields.io/crates/v/regex-le?style=for-the-badge&label=Rust%20CLI&color=blue&logo=rust" alt="regex-le on crates.io" />
</a>
<a href="https://letools.dev/tools/regex-le">
<img src="https://img.shields.io/badge/LE%20Tools-letools.dev-blue?style=for-the-badge" alt="LE Tools" />
</a>
</p>
---
<p align="center">
<img src="src/assets/images/demo.gif" alt="Regex-LE Demo" style="max-width: 100%; height: auto;" />
</p>
> **Useful?** A star or rating is how other developers find it —
> [★ GitHub](https://github.com/nolindnaidoo/regex-le) ·
> [★ Open VSX](https://open-vsx.org/extension/OffensiveEdge/regex-le/reviews) ·
> [★ Marketplace](https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.regex-le&ssr=false#review-details)
## What it does
Open any file and run one of three commands. **Extract** lists every regex pattern found in the document. **Test** (`Ctrl+Alt+R` / `Cmd+Alt+R`) runs a found — or manually entered — pattern against the file content and reports matches with real line/column positions and capture groups (named groups included). **Validate** checks every found pattern for syntax errors and screens it for catastrophic backtracking, reporting the input that causes it. Works in VS Code and VS Code–based editors like Cursor and VSCodium (installable from Open VSX).
## Install
| Where | What you get | Install |
|---|---|---|
| **VS Code** | The lint *and* the tester, in your editor | [Marketplace](https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.regex-le) |
| **Cursor, VSCodium, Windsurf** | The same extension | [Open VSX](https://open-vsx.org/extension/OffensiveEdge/regex-le) |
| **A terminal or a CI step** | The same run over a whole tree, with exit codes | `cargo install regex-le` · [crates.io](https://crates.io/crates/regex-le) |
| **Any MCP agent, via Node** | `extract_patterns` over stdio | `npx regex-le-mcp` · [npm](https://www.npmjs.com/package/regex-le-mcp) |
| **Zed** | The MCP server as a context server | [add it by hand](https://zed.dev/docs/ai/mcp) *(no listing yet)* |
## Use it from an AI agent
The same engine runs as an [MCP](https://modelcontextprotocol.io) server, so an agent can call it directly instead of you running a command.
| Editor | How |
|---|---|
| **VS Code** 1.101+ | Nothing to install — the extension registers `extract_patterns` with agent mode |
| **Zed** | No listing yet — [add the MCP server by hand](https://zed.dev/docs/ai/mcp) |
| **Claude Code** | `claude mcp add regex-le -- npx -y regex-le-mcp` |
| **Cursor, Windsurf, anything else** | point it at `npx regex-le-mcp` |
```
extract_patterns(content, format?, filename?, maxResults?)
```
Returns every pattern with its flags, 1-based position and a **ReDoS verdict**, so "are any of the regexes in this file dangerous?" is one call rather than two. A verdict that reports a blow-up carries the `witness` that caused it, so an agent can check the finding instead of trusting it.
The server takes content and returns data — it reads no files and makes no network requests of its own. Published as [`regex-le-mcp`](https://www.npmjs.com/package/regex-le-mcp) on npm and as `io.github.nolindnaidoo/regex-le` in the [MCP registry](https://registry.modelcontextprotocol.io).
<details>
<summary><b>Configuring it by hand</b> — any host with an MCP config file</summary>
Most hosts read a JSON config. Add one entry:
```json
{
"mcpServers": {
"regex-le": {
"command": "npx",
"args": ["-y", "regex-le-mcp"]
}
}
}
```
`-y` skips the install prompt on first run. Pin a version if you would rather not track releases — `regex-le-mcp@2.5.0`.
Prefer not to go through `npx` on every launch? Install it once and point at the binary instead:
```bash
npm install -g regex-le-mcp
```
```json
{
"mcpServers": {
"regex-le": { "command": "regex-le-mcp" }
}
}
```
It speaks MCP over stdio and needs no environment variables, no API key and no configuration of its own. To check it before wiring it into anything:
```bash
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | npx -y regex-le-mcp
```
That prints the tool list and exits — if you see `extract_patterns`, the server works.
</details>
## What gets extracted
Extraction scans the whole document, so constructors split across lines are found too. The document's language chooses which spellings to look for:
| Language | Form | Example |
|---|---|---|
| JavaScript, TypeScript, Ruby | Literal | `/[a-z]+/gi` |
| JavaScript, TypeScript | Constructor | `new RegExp('\\d{4}-\\d{2}', 'g')` — including multiline |
| JavaScript, TypeScript | Bare constructor call | `RegExp("x\|y", "i")` |
| Python | `re.compile` and friends | `re.compile(r'(a+)+')` |
| Rust | `Regex::new`, `RegexBuilder::new` | `Regex::new(r"(a+)+")` |
| Go | `regexp.MustCompile`, `regexp.Compile` | ``regexp.MustCompile(`(a+)+`)`` |
| Java | `Pattern.compile`, `Pattern.matches` | `Pattern.compile("(a+)+")` |
| Ruby | `Regexp.new` | `Regexp.new('(a+)+')` |
| PHP | `preg_match` and friends | `preg_match('/(a+)+/i', $s)` |
| C# | `new Regex(…)`, `Regex.IsMatch` and friends | `new Regex(@"(a+)+")` |
A language nothing recognises is not a refusal — every spelling above is looked for. Naming it buys precision: a Python file is not scanned for bare `/…/`, so `#!/usr/bin/env python` stops reading as a pattern.
What is deliberately **not** extracted:
- Division, dates, and filesystem paths (`a / b`, `10/29/2025`, `/usr/local/bin`): a `/` preceded by an identifier, number, `)`, `]`, `.`, or another `/` is not treated as a regex — after keywords like `return`, it is. That question is only asked where a bare `/…/` is legal.
- Candidates that are not a well-formed regular expression in any of these languages, or with invalid/duplicate flags. Another language's spelling is not a syntax error: `re.compile(r'(?P<word>\w+)+@')` is reported as written, and still flagged.
- Constructor calls whose pattern argument is a variable, or a template literal with a `${…}` substitution. String literals, static template literals and `` String.raw`…` `` are read.
- Flags, on anything but a JavaScript literal or constructor: every other language sets them with constants, builder methods or an inline `(?i)` rather than a string argument.
- **Anything written in a comment or a string.** A JSDoc block explaining a hazard, a commented-out line, a Python docstring with an example — none of them is code, and reporting one fails a build over a sentence. The rule is about where a candidate *starts*, so `re.compile(r"(a+)+b")` keeps its quoted argument while a docstring holding that whole line is prose. Only when the language is known: a document nothing recognises is scanned as written, because a comment rule guessed from the wrong grammar would drop real patterns instead of phantom ones.
Duplicate pattern+flags pairs are listed once. This is lexing by heuristic, not a parser for nine languages: a slash inside a string can still be picked up when its context looks expression-like.
## ReDoS screening
`Validate` (and `Test`, before running a risky pattern) reports a pattern **only when an input was found that demonstrably drives it into catastrophic backtracking** — and reports that input alongside it, as the `witness`.
Your pattern is never run. It is compiled to an automaton, and that automaton is walked the way a backtracking engine walks one — depth-first, every edge in order, a dead end unwound rather than remembered — while the steps are counted. An attack string is built, pumped at two lengths, and measured against a step budget. So a finding is falsifiable: run the witness and watch.
Nothing is reported on the strength of how a pattern is *shaped*. Shape is a poor predictor in both directions: `^[a-z0-9]+(?:-[a-z0-9]+)*$` looks dangerous and is not, because every iteration must eat a `-` the inner class cannot produce, while `(.*a){20}` looks bounded and is not. A separator forcing the split is a fact about strings, so no test on syntax settles it.
**Silence is not a clearance.** A pattern this cannot read — a backreference, lookaround, syntax it does not parse — comes back as `not decided: <reason>`, never as safe.
The reports also include a rough performance score based on execution time relative to input size — treat it as a hint, not a benchmark (memory is not measured).
## The CLI
The same lint runs from a terminal or a shell pipeline: a Rust CLI in
[`crate/`](crate/README.md), sharing one corpus with the extension —
[`crate/fixtures/`](crate/fixtures/) — so the two can never read a
document differently.
```bash
regex-le . # every vulnerable pattern in the tree
regex-le --severity high src/ # only the exponential shapes
regex-le --all src/ # every pattern, vulnerable or not
regex-le mcp # the same lint over MCP on stdio
```What people ask about regex-le
What is nolindnaidoo/regex-le?
+
nolindnaidoo/regex-le is mcp servers for the Claude AI ecosystem. Find every regex in a codebase, and report which can be driven into catastrophic backtracking It has 2 GitHub stars and its last recorded update is dated 2026-09-30.
How do I install regex-le?
+
You can install regex-le by cloning the repository (https://github.com/nolindnaidoo/regex-le) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is nolindnaidoo/regex-le safe to use?
+
Our security agent has analyzed nolindnaidoo/regex-le and assigned a Trust Score of 95/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.
Who maintains nolindnaidoo/regex-le?
+
nolindnaidoo/regex-le is maintained by nolindnaidoo. The last recorded GitHub activity is dated 2026-09-30, with 0 open issues.
Are there alternatives to regex-le?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy regex-le to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/nolindnaidoo-regex-le)<a href="https://claudewave.com/repo/nolindnaidoo-regex-le"><img src="https://claudewave.com/api/badge/nolindnaidoo-regex-le" alt="Featured on ClaudeWave: nolindnaidoo/regex-le" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.