regex-safety-audit-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@regex-safety-audit-mcpis this regex safe from ReDoS? ^(a|ab)+$"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
regex-safety-audit-mcp
An MCP server that parses a regex into a real hand-written AST to detect catastrophic-backtracking (ReDoS) risk —
without ever executing the pattern itself. A ReDoS scanner that runs the regex it's scanning would be able to
hang itself; this one never calls new RegExp(...).test() on anything.
What it catches
Nested unbounded quantifiers ((a+)+), ambiguous alternation inside a repeated group ((a|ab)+), and
backreferences — the three shapes behind almost every real-world ReDoS incident. Detection is structural (a real
parser, not regex-on-regex string heuristics), verified against the canonical literature examples during testing.
Related MCP server: js-reverse-analyzer
The JS-specific trap
Generic ReDoS advice tells you to wrap the offending group in an atomic group or use a possessive quantifier.
JavaScript has neither. analyze_redos_risk says so explicitly, and suggest_safe_rewrite gives the actual
JS-safe fix (collapsing redundant nesting, or restructuring with a negated character class) instead of advice that
would 400 as a syntax error if you tried it.
Tools
analyze_redos_risk
Full structural analysis. Returns a risk level, every finding with its exact reason, and the JS atomic-group/ possessive-quantifier caveat.
generate_attack_string
For a flagged pattern, generates candidate proof-of-concept inputs at a few sizes, plus a ready-to-run Node snippet that times the match with a hard OS-level subprocess timeout — so testing a genuinely catastrophic regex can't hang your own test process either.
suggest_safe_rewrite
Concrete rewritten pattern for the mechanically-fixable shapes; honest "no mechanical fix, here's what to change by hand" for the ones that aren't.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
npm install
node server.jsPart of a small suite
mcp-schema-audit-mcp, cron-schedule-audit-mcp, claude-cost-audit-mcp.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Explain a regex in plain English and detect catastrophic backtracking risk.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Detects database migration table locks, terraform cost leaks, and OWASP API flaws.
Discover exposed assets, leaked secrets, APIs & client-side vulns across your attack surface
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceRegexForge gives AI agents a reliable way to get a regex without asking an LLM to hallucinate one. Pass in labeled examples (strings that should match, strings that shouldn't) plus an optional description; get back the regex, a proof matrix showing it handles every example, and a backtracking-risk audit flagging catastrophic-backtracking patterns. Pure symbolic synthesis over a template bank with-
- AlicenseNot gradedqualityDmaintenanceProvides JavaScript reverse engineering capabilities including static analysis, dynamic execution, and bypassing anti-bot protections like Cloudflare 5-second challenge.10Apache 2.0
- AlicenseAqualityDmaintenanceProvides tools to test regex patterns for correctness, performance (ReDoS), and memory usage, and suggests safe rewrites. Enables LLMs to iterate on regex generation with verifiable feedback.9MIT
- AlicenseNot gradedqualityAmaintenanceProvides a tool to extract and validate regex patterns from text content, including flags, positions, and ReDoS risk assessment. Enables AI agents to identify potentially dangerous regular expressions in code or files without needing filesystem access.2MIT