Regex Lab

io.github.basitalisandhuv0.1.1Updated Oct 5, 2026

Test regular expressions in a timeout-guarded worker, explain them, find catastrophic backtracking.

VerifiedSTDIODesktop onlyDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Lets an assistant test JavaScript regular expressions against samples, explain a pattern piece by piece, and check for catastrophic backtracking.

What it does
Provides three tools for working with JavaScript (V8) regular expressions. test_regex runs a pattern and flags against up to 50 sample strings and returns every match with offsets, numbered and named groups, and an optional replacement preview. explain_regex describes literals, classes, escapes, anchors, groups, lookarounds, quantifiers and alternation, plus group count and flag meanings. check_redos reports static findings such as nested unbounded repeats and overlapping alternatives, then runs timed probes to confirm or clear the pattern.
When to use it
Useful when writing, debugging or reviewing regular expressions and you want match details, a plain-language explanation, or a quick check for ReDoS-prone patterns. Handy in editor or coding workflows where regex correctness and safety matter.
Requirements
Runs locally over stdio as an npm package, typically started with npx; Docker image ghcr.io/basitalisandhu/mcp-regex-lab:0.1.1 is also published. Requires Node.js for the npm route. No authentication, environment variables, headers, network access or local file access are declared.
Before you install
Executions run in a worker thread that is terminated after the timeout, and samples finished before a timeout are still returned, so partial results may be incomplete. Syntax follows V8; PCRE, RE2 and Python differ in places such as possessive quantifiers and lookbehind. The README notes that no findings and flat timings are evidence, not proof, that a pattern is safe. Pin the package version so updates cannot change what runs.

Installation

In SourceWeft

  1. Open Regex Lab in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

regex-lab MCP server

Tests JavaScript regular expressions against sample strings, explains a pattern construct by construct, and looks for catastrophic backtracking. Every execution runs in a worker thread that is terminated when it exceeds the timeout, so a pathological pattern cannot hang the server.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
test_regexpattern, flags?, samples[] (up to 50 of 20 000 chars), replacement?, timeout_ms? (50 to 10 000, default 2000)Every match per sample with offsets, text, numbered and named groups (with offsets), optional replace preview. Samples finished before a timeout are still returned.
explain_regexpattern, flags?Indented description of literals, classes, escapes, anchors, groups, lookarounds, quantifiers and alternation, plus the capturing group count and flag meanings.
check_redospattern, flags?, probe? (default true), timeout_ms?Static findings (nested unbounded repeats, overlapping alternatives under a repeat, adjacent overlapping repeats) with a probe character each, then timed runs against crafted inputs of growing length to confirm or clear the pattern.

Install

Claude Code:

bash
claude mcp add regex-lab -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "regex-lab": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/regex-lab/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: None.
  • Local files: None.
  • Telemetry: none.

Notes

  • Syntax follows V8 (Node.js). PCRE, RE2 and Python differ in places such as possessive quantifiers and lookbehind.
  • g and d flags are added automatically when matching; the replacement preview uses the flags you gave.
  • No findings and flat timings are evidence, not proof, that a pattern is safe.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-regex-labnpm test -w @basitalisandhu/mcp-regex-lab

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

Source: packages/regex-lab/README.md at commit 58c8c95

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.1LatestOct 5, 2026