Skip to main content
Glama
tylerscomic-lab

regex-safety-audit-mcp

README.md
# regex-safety-audit-mcp

[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)
[![Live on MCPize](https://img.shields.io/badge/Live%20on-MCPize-6d28d9)](https://mcpize.com/mcp/regex-safety-audit-mcp)

An MCP server that parses a regex into a real hand-written AST to detect catastrophic-backtracking (ReDoS) risk —
**without ever executing the pattern itself.** A ReDoS scanner that runs the regex it's scanning would be able to
hang itself; this one never calls `new RegExp(...).test()` on anything.

## What it catches

Nested unbounded quantifiers (`(a+)+`), ambiguous alternation inside a repeated group (`(a|ab)+`), and
backreferences — the three shapes behind almost every real-world ReDoS incident. Detection is structural (a real
parser, not regex-on-regex string heuristics), verified against the canonical literature examples during testing.

## The JS-specific trap

Generic ReDoS advice tells you to wrap the offending group in an atomic group or use a possessive quantifier.
**JavaScript has neither.** `analyze_redos_risk` says so explicitly, and `suggest_safe_rewrite` gives the actual
JS-safe fix (collapsing redundant nesting, or restructuring with a negated character class) instead of advice that
would 400 as a syntax error if you tried it.

## Tools

### `analyze_redos_risk`
Full structural analysis. Returns a risk level, every finding with its exact reason, and the JS atomic-group/
possessive-quantifier caveat.

### `generate_attack_string`
For a flagged pattern, generates candidate proof-of-concept inputs at a few sizes, plus a ready-to-run Node
snippet that times the match with a **hard OS-level subprocess timeout** — so testing a genuinely catastrophic
regex can't hang your own test process either.

### `suggest_safe_rewrite`
Concrete rewritten pattern for the mechanically-fixable shapes; honest "no mechanical fix, here's what to change by
hand" for the ones that aren't.

## Use it

**Hosted (recommended):** [MCPize](https://mcpize.com/mcp/regex-safety-audit-mcp) — free tier, $7/mo Pro.

**Self-host:**
```bash
npm install
node server.js
```

## Part of a small suite

[mcp-schema-audit-mcp](https://github.com/tylerscomic-lab/mcp-schema-audit-mcp),
[cron-schedule-audit-mcp](https://github.com/tylerscomic-lab/cron-schedule-audit-mcp),
[claude-cost-audit-mcp](https://github.com/tylerscomic-lab/claude-cost-audit-mcp).

## License

MIT