Regex Safety & Performance Analyzer

Regex Safety & Performance Analyzer MCP Connector for Claude

A+

Detects catastrophic backtracking and ReDoS vulnerabilities in regular expressions using AST traversal.

3 tools Official Updated Oct 1, 2026 Official Vinkius Partner

Protect your applications from Regular Expression Denial of Service (ReDoS) attacks. This MCP server connects AI agents to a deterministic engine that parses regex patterns into an Abstract Syntax Tree (AST). By inspecting the structural relationship between elements, it identifies dangerous patterns like nested quantifiers and overlapping alternatives without executing the pattern. Use analyze_regex_pattern to perform deep security audits, classify_risk_level to interpret risk scores, and compare_patterns_safety to find the most resilient pattern for your production code.

regexsecurityredosperformanceastvulnerability-scanner

3 tools expose this connector's capabilities to your AI agent.

analyze_regex_pattern

Performs a deep security audit on a specific regular expression pattern

compare_patterns_safety

Determines which of two regex patterns is more performance-resilient

classify_risk_level

Converts a raw numerical risk score into a human-readable security classification

See how to talk to your AI agent using Regex Safety & Performance Analyzer.

Check if this regex is safe: (a+)+

The `analyze_regex_pattern` tool identifies a nested quantifier at index 3, resulting in a high risk score of 0.95.

What is the risk level for this pattern?

The `classify_risk_level` tool classifies this pattern as 'Critical' with a recommended policy of 'Immediate refactor required'.

Which regex is safer: (a|a) or (a+)?

The `compare_patterns_safety` tool determines that (a+) is the safer pattern, with a risk difference of 0.0.

It is a performance failure where the engine explores every possible permutation of matches, causing exponential growth in computation time relative to input length.

Related Connectors