Regex Check
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| PORT | No | Port used when serving stateless MCP over Streamable HTTP at POST /mcp (started with --http); default 3000. | 3000 |
| REGEX_CHECK_TIMEOUT_MS | No | Each engine runs in its own worker thread with a time limit (5 s per call, REGEX_CHECK_TIMEOUT_MS to change it): a pattern that backtracks forever on an input stops that engine only, which is replaced, and the others still answer. | 5000 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| check_redosA | Checks a regex for catastrophic backtracking (ReDoS): safe or vulnerable, exponential or polynomial, the part of the pattern to blame, an attack string, and how long each real engine (JavaScript, Python, PCRE2, RE2) takes on it. Use before a pattern runs on untrusted input. |
| test_regexA | Runs a regex on real engines: JavaScript (V8), Python (CPython re), PCRE2 (PHP, grep -P), RE2 (Go, BigQuery). Each gives its compile error with position, or every match with groups and named groups, and the replacement result in its own syntax. Positions are in characters. Lists where engines disagree. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 2 tools
The two tools have clearly distinct purposes: check_redos analyzes a pattern for catastrophic backtracking safety, while test_regex executes a pattern to report matches, groups, and engine differences. An agent can easily tell which to call based on whether the goal is safety analysis or behavior testing.
Both names follow the same snake_case verb_noun convention (check_redos, test_regex), with 'redos' and 'regex' as the clear noun targets. The pattern is fully predictable and consistent.
Two tools is on the thin side, but each is a substantial, well-defined operation covering a genuinely narrow domain (regex safety and engine behavior analysis). The scope justifies the small surface, though a third operation could round it out.
The surface covers the two core needs—vulnerability detection and cross-engine matching/testing—giving decent lifecycle coverage for the domain. Minor gaps exist (e.g., no pattern explanation or syntax conversion), but agents can work around them.