Unicode Normalization and Homoglyph Detector

Unicode Normalization and Homoglyph Detector MCP Connector for Claude

A+

Detects malicious Unicode homoglyph attacks and identifies invisible characters in strings.

3 tools Official Updated Oct 1, 2026 Official Vinkius Partner

This MCP server provides specialized tools to identify security threats within Unicode strings. It detects malicious homoglyph substitutions (such as Cyrillic 'а' vs Latin 'a') and flags invisible zero-width characters that are often used to bypass code reviews or text filters. Using analyze_string_security, you can perform a high-level assessment of any input string. The server also provides detect_hidden_characters to find non-printing codepoints and inspect_homoglyph_substitutions to isolate visual spoofing attempts. All detection is performed via deterministic integer codepoint comparison, ensuring reliable security analysis.

unicodehomoglyphsecuritynormalizationdetectionspoofing

3 tools expose this connector's capabilities to your AI agent.

analyze_string_security

Provides a high-level security assessment of a provided string

inspect_homoglyph_substitutions

Isolates and reports only the visual substitutions found in a string

detect_hidden_characters

Scans for the presence of invisible or zero-width characters

See how to talk to your AI agent using Unicode Normalization and Homoglyph Detector.

Analyze this string for security threats: 'pаypal.com'

The string 'pаypal.com' is unsafe because it contains a Cyrillic 'а' instead of a Latin 'a', which is a homoglyph substitution.

Are there any hidden characters in this text?

The scan found one hidden character at position 5 (U+200B).

Check if 'hello' has any visual substitutions.

No visual substitutions were detected in the string 'hello'.

Homoglyph attacks occur when visually similar characters from different scripts (like Cyrillic or Greek) are used to impersonate Latin characters, potentially creating deceptive URLs or usernames.

Related Connectors