regex-le-mcp

regex-le-mcp

Provides a tool to extract and validate regex patterns from text content, including flags, positions, and ReDoS risk assessment. Enables AI agents to identify potentially dangerous regular expressions in code or files without needing filesystem access.

Category
访问服务器

README

<p align="center"> <img src="src/assets/images/icon.png" alt="Regex-LE Logo" width="96" height="96"/> </p> <h1 align="center">Regex-LE: Zero Hassle Regex Extraction & Validation</h1> <p align="center"> <b>Find, test, and validate the regex patterns in the current file</b><br/> <i>Literal patterns, RegExp constructors, ReDoS screening</i> </p>

<p align="center"> <a href="https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.regex-le"> <img src="https://img.shields.io/badge/Install%20from-VS%20Code-blue?style=for-the-badge&logo=visualstudiocode" alt="Install from VS Code Marketplace" /> </a> <a href="https://open-vsx.org/extension/OffensiveEdge/regex-le"> <img src="https://img.shields.io/open-vsx/dt/OffensiveEdge/regex-le?style=for-the-badge&label=Open%20VSX&color=blue" alt="Open VSX downloads" /> </a> <a href="https://www.npmjs.com/package/regex-le-mcp"> <img src="https://img.shields.io/npm/v/regex-le-mcp?style=for-the-badge&label=MCP%20server&color=blue&logo=npm" alt="regex-le-mcp on npm" /> </a> <a href="https://letools.dev"> <img src="https://img.shields.io/badge/LE%20Tools-letools.dev-blue?style=for-the-badge" alt="LE Tools" /> </a> </p>


<p align="center"> <img src="src/assets/images/demo.gif" alt="Regex-LE Demo" style="max-width: 100%; height: auto;" /> </p>

Useful? A star or rating is how other developers find it — ★ GitHub · ★ Marketplace · ★ Open VSX

What it does

Open any file and run one of three commands. Extract lists every regex pattern found in the document. Test (Ctrl+Alt+R / Cmd+Alt+R) runs a found — or manually entered — pattern against the file content and reports matches with real line/column positions and capture groups (named groups included). Validate checks every found pattern for syntax errors and screens it for ReDoS-prone shapes. Works in VS Code and VS Code–based editors like Cursor and VSCodium (installable from Open VSX).

Use it from an AI agent

The same engine runs as an MCP server, so an agent can call it directly instead of you running a command.

Editor How
VS Code 1.101+ Nothing to install — the extension registers extract_patterns with agent mode
Zed Regex-LEpending review
Claude Code claude mcp add regex-le -- npx -y regex-le-mcp
Cursor, Windsurf, anything else point it at npx regex-le-mcp
extract_patterns(content, maxResults?)

Returns every pattern with its flags, 1-based position and a ReDoS verdict, so "are any of the regexes in this file dangerous?" is one call rather than two.

The server takes content and returns data — it reads no files and makes no network requests of its own. Published as regex-le-mcp on npm and as io.github.nolindnaidoo/regex-le in the MCP registry.

<details> <summary><b>Configuring it by hand</b> — any host with an MCP config file</summary>

Most hosts read a JSON config. Add one entry:

{
  "mcpServers": {
    "regex-le": {
      "command": "npx",
      "args": ["-y", "regex-le-mcp"]
    }
  }
}

-y skips the install prompt on first run. Pin a version if you would rather not track releases — regex-le-mcp@2.2.1.

Prefer not to go through npx on every launch? Install it once and point at the binary instead:

npm install -g regex-le-mcp
{
  "mcpServers": {
    "regex-le": { "command": "regex-le-mcp" }
  }
}

It speaks MCP over stdio and needs no environment variables, no API key and no configuration of its own. To check it before wiring it into anything:

echo '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | npx -y regex-le-mcp

That prints the tool list and exits — if you see extract_patterns, the server works.

</details>

What gets extracted

Extraction scans the whole document (any file type), so constructors split across lines are found too:

Form Example
Literal /[a-z]+/gi
Constructor new RegExp('\\d{4}-\\d{2}', 'g') — including multiline
Bare constructor call RegExp("x|y", "i")

What is deliberately not extracted:

  • Division, dates, and filesystem paths (a / b, 10/29/2025, /usr/local/bin): a / preceded by an identifier, number, ), ], ., or another / is not treated as a regex — after keywords like return, it is.
  • Candidates that do not compile as JavaScript regexes, or with invalid/duplicate flags.
  • Constructor calls whose pattern argument is a variable or template literal (only literal string arguments are visible to a text scanner).

Duplicate pattern+flags pairs are listed once. This is lexing by heuristic, not a full JS parser: a slash inside a string or comment can still be picked up when its context looks expression-like.

ReDoS screening

Validate (and Test, before running a risky pattern) screens for the common catastrophic-backtracking shapes:

  • High severity — nested unbounded quantifiers: (a+)+, ([a-z]+)*
  • Medium severity — quantified alternation with overlapping branches: (a|ab)+

This is a structural scanner, not an automaton analysis: it cannot prove a pattern safe, only flag the dangerous shapes it recognizes. The reports also include a rough performance score based on execution time relative to input size — treat it as a hint, not a benchmark (memory is not measured).

Commands

Command Description
Regex-LE: Test Regex (Ctrl+Alt+R / Cmd+Alt+R) Test a found or entered pattern against the file
Regex-LE: Extract Patterns List every regex pattern found in the document
Regex-LE: Validate Regex Syntax + ReDoS report for every found pattern
Regex-LE: Open Settings Open Regex-LE settings
Regex-LE: Help & Troubleshooting Built-in documentation

Settings

Setting Default Description
regex-le.openResultsSideBySide true Open results beside the current editor
regex-le.copyToClipboardEnabled false Also copy results to the clipboard
regex-le.notificationsLevel silent all = every notification, important = warnings + errors, silent = errors only
regex-le.safety.enabled true Guardrails for very large files and outputs
regex-le.safety.fileSizeWarnBytes 1000000 Refuse processing above this file size
regex-le.safety.largeOutputLinesThreshold 50000 Refuse result documents above this line count
regex-le.statusBar.enabled true Show the status bar item
regex-le.telemetryEnabled false Local-only event log (see Privacy)
regex-le.regex.redosDetectionEnabled true ReDoS screening in Test/Validate
regex-le.regex.maxMatchLimit 1000 Cap on matches collected per test (10–10000)

Languages

Twelve languages besides English:

German · Spanish · French · Indonesian · Italian · Japanese · Korean · Portuguese (Brazil) · Russian · Ukrainian · Vietnamese · Chinese (Simplified)

Both halves are covered — the manifest (command titles, setting names and descriptions) and everything shown while the extension runs (notifications, the status bar, quick-picks and prompts). The extension follows VS Code's display language, so it matches whatever the editor is already set to; no setting of its own.

Privacy & security

  • No network access. The extension never sends data anywhere. The telemetryEnabled setting only writes events to a local Output Channel you can inspect (Regex-LE Telemetry).
  • Testing a pattern the ReDoS screen rates high-severity asks for confirmation first.
  • The MCP server holds the same line. It takes content as an argument and returns data: no filesystem access, no network calls, no telemetry. Your agent already has file-read tools, so duplicating them inside the server would add a path-traversal surface for no capability. check:mcp-bundle fails the build if the server ever imports something that could reach either.
  • Error notifications redact home directories and credential-shaped fragments.

Development

bun install
bun run build            # esbuild bundle -> dist/extension.js
bun run typecheck        # tsc --noEmit (includes tests)
bun run test             # vitest unit suite
bun run test:integration # real VS Code extension host
bun run lint             # biome
bun run package          # VSIX into release/

Architecture and conventions live in AGENTS.md. Changes are tracked in CHANGELOG.md.

Performance

<!-- performance:start -->

Input Size Found Time Rate Scan speed
JS with literals 1.12 MB 25,000 44.19 ms 565,679/sec 25.4 MB/s
JS with constructors 1.27 MB 25,000 41.86 ms 597,268/sec 30.3 MB/s
Source without regexes 1.24 MB 0 18.75 ms 66 MB/s

Median of 7 runs after warmup, on Apple M5 Pro, 24 GB RAM, Node 24.3.0. Inputs are generated by scripts/benchmark.ts rather than checked in, so the sizes above are exactly what was measured. Reproduce with bun run benchmark.

These are machine-specific and are not asserted in CI — a benchmark that gates a build only tells you how busy the runner was. <!-- performance:end -->

Testing

<!-- coverage:start -->

Metric Coverage
Statements 90.66%
Branches 75.89%
Functions 97.36%
Lines 91.16%

133 test cases across 12 files, plus an integration suite that runs in a real VS Code extension host and an end-to-end test that installs the built .vsix into a clean profile.

Generated from coverage/coverage-summary.json by scripts/coverage-readme.js; CI fails if this section drifts from a fresh run. Reproduce with bun run test:coverage. <!-- coverage:end -->

More from the LE Family

Every tool in the family, one page: letools.dev

All ten also ship as MCP servers — npx <name>-mcp gives any agent the same engine.

  • String-LE - Extract string values for i18n from JSON, YAML, CSV, TOML, INI, and .env
  • Numbers-LE - Extract numeric values from JSON, YAML, CSV, TOML, INI, and .env
  • EnvSync-LE - Spot missing keys across your .env files, with a markdown report
  • Paths-LE - Extract file paths from JS/TS imports, JSON, HTML, CSS, TOML, CSV, and .env
  • Secrets-LE - Detect and sanitize credentials locally, before you commit
  • Scrape-LE - Check whether a page is scrapeable before you write the scraper
  • Colors-LE - Extract and analyze colors from CSS, SCSS, LESS, Stylus, HTML, JS/TS, and SVG
  • URLs-LE - Extract URLs from documentation, configs, and code
  • Dates-LE - Extract and analyze dates from logs, configs, and code

Also by nolindnaidoo

Rust

Contact DeveloperGitHub · LinkedIn

License

MIT © nolindnaidoo

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选
mcp-server-qdrant

mcp-server-qdrant

这个仓库展示了如何为向量搜索引擎 Qdrant 创建一个 MCP (Managed Control Plane) 服务器的示例。

官方
精选