IPs-LE
io.github.nolindnaidoov1.0.0更新於 Oct 4, 2026
Extract every IP address, CIDR block and MAC, normalized and classified by scope.
概覽
從文字中擷取所有 IPv4、IPv6、CIDR 區塊與 MAC 位址,並加以正規化、依作用域分類。
- 功能
- 此伺服器提供 extract_ips 工具,會掃描傳入的內容,回傳每個位址的類型(ipv4、ipv6、cidr、mac)、正規形式、行列位置,以及作用域分類,例如 loopback、private、link-local、documentation。CIDR 結果另含前綴、網路位址、最後一個位址與主機數量。若文字存在多種合理讀法,會以具名拒絕回報,而不是自行猜測。它不進行 DNS、查詢或網路請求,也不讀取檔案。
- 適用情境
- 適合在檢視設定檔、允許清單或日誌時使用,尤其是同一位址可能以多種寫法出現的情況;也適合讓助理依正規形式而非原始文字比對位址。它用於檢查與回報,不用於解析或改寫位址。
- 執行需求
- 透過 npm 套件 ips-le-mcp 以 npx 在本機以 stdio 執行,需要 Node.js。不需要環境變數、API 金鑰或額外設定。工具以參數接收內容,不需要網路存取。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 IPs-LE,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
IPs-LE: One Address, One Spelling
Find every IP address, CIDR block and MAC in a document, normalized and classified, and refuse the ambiguous ones by name
IPv4 · IPv6 (RFC 5952) · CIDR · MAC — no DNS, no lookups, no sockets
[Install from VS Code Marketplace] [Open VSX downloads] [ips-le-mcp on npm] [ips-le on crates.io] [LE Tools]
Useful? A star or rating is how other developers find it — ★ GitHub · ★ Open VSX · ★ Marketplace
What it does
An allow-list review asks whether 2001:0db8::0001 is already on the list. The list says 2001:db8::1. A diff of the raw text calls them two addresses; they are one.
Open a document, press Ctrl+Alt+A (Cmd+Alt+A on Mac), and every IPv4 and IPv6 address, CIDR block and MAC address in it is listed by kind with its line and column, the key it sits under, its canonical form and what it is for — loopback, private, link-local, documentation and the rest. A CIDR block comes with its network, its last address and how many addresses it holds. The report opens beside the editor. Works in VS Code and in VS Code–based editors like Cursor and VSCodium (installable from Open VSX).
- Reviewing a config or an allow-list — one spelling per address, and the private ones named as private
- Reading a log — every peer and upstream, even inside a URL or a
[host]:port - Before trusting
010.1.1.1— which is two different hosts depending on who reads it
Text it cannot read unambiguously is reported with the reason, never guessed at. It resolves nothing, looks nothing up and rewrites nothing.
Install
What it answers
One address, one form. IPv6 is normalized per
RFC 5952 —
2001:0db8:0000:0000:0000:0000:0000:0001, 2001:db8:0:0:0:0:0:1,
2001:0db8::0001 and 2001:DB8::1 all come back as 2001:db8::1.
Sorting the raw text gives four addresses; sorting the normalized form
gives one.
Four kinds. ipv4, ipv6, cidr, mac.
Ten classes, closed. A class this cannot name is a class it does not claim.
An IPv4-mapped IPv6 address takes the IPv4 class, so ::ffff:127.0.0.1
is loopback rather than global — which is the miss an allow-list
review is looking for.
Where it is. Line, column, and the key it sits under: JSON, YAML,
TOML, INI, dotenv, CSV and logs all supply one. Everything else is still
scanned — the search runs over the bytes, so a .tf, a .rules or a
rotated access.log.1 yields its addresses and only loses the key path.
Blocks, with their arithmetic. A CIDR finding carries prefix,
network, broadcast (IPv4 only — IPv6 has none), last and hosts.
hosts is a decimal string, because ::/0 holds 2^128 addresses, which
is one more than a u128 and far more than a JSON number.
What it refuses
Where the text supports more than one reading, ips-le reports the
text, names the ambiguity, and stops.
Six reasons, each a place where two answers are equally defensible:
The two that matter most:
010.1.1.1is not resolved. A leading-zero octet is octal to some resolvers and decimal to others, so that text names two different hosts. Neither reading appears anywhere in the output — a tool that picked one would be the thing hiding the bug.2130706433is decoded only next to the flag. Under an address key it is reported asinteger_form, with127.0.0.1inside the refusal message. What you never get is a loopback address quietly appearing in a list of addresses with the flag gone.
A refusal is a finding, not a failure. It does not move the exit
code, and no filter can hide it — filtering to private still shows you the
octal hazard, because that is the finding a filtered report would most
regret dropping. --strict is there for the pipeline that wants an
unresolved ambiguity to stop the build.
crate/SPEC.md says exactly when each reason fires.
It never touches a network
No DNS, no geolocation, no ASN, no WHOIS, no reachability check, no telemetry. Not behind a flag, not once. Classification is arithmetic over the bits and the IANA registries; a lookup would make the answer depend on the network the auditor happened to be sitting on.
It also never rewrites a file, and it never gives a verdict. It says what an address is, never whether it should be there.
Use it from an AI agent
The same engine runs as an MCP server, so an agent can call it directly instead of deciding by eye whether two spellings are one address.
It returns the findings the editor renders, refusals included, as data — capped at 500 by default with meta.truncated. It reads no files and makes no network requests. Published as ips-le-mcp on npm and as io.github.nolindnaidoo/ips-le in the MCP registry. It answers exactly as the Rust CLI's server does: one corpus runs against both, and a differential test feeds both thousands of generated documents in every format — broken JSON included, where both report the parser's own words and position — and compares every answer.
Configuring it by hand — any host with an MCP config file
Or install it once with npm install -g ips-le-mcp and point at ips-le-mcp. It needs no environment variables, no API key and no configuration of its own. To check it:
The CLI
The same extraction runs over a whole tree from a terminal or a CI step: a Rust CLI in crate/, sharing one corpus with the extension — crate/fixtures/ — so the two can never read an address differently.
Exit codes follow grep — 0 at least one address named, 1 none, 2 the question was malformed. A refusal does not move the exit code; --strict is how a pipeline turns one into a failure.
Commands
Settings
Languages
Twelve languages besides English:
German · Spanish · French · Indonesian · Italian · Japanese · Korean · Portuguese (Brazil) · Russian · Ukrainian · Vietnamese · Chinese (Simplified)
Both halves are covered — the manifest (command titles, setting names and descriptions) and everything shown while the extension runs (notifications, the status bar and the report's headings). A refusal's detail is the engine's English, identical to the CLI's.
Privacy & security
- No network access. The extension never sends data anywhere: no DNS, no geolocation, no lookups of any kind. The
telemetryEnabledsetting only writes events to a local Output Channel you can inspect (IPs-LE). - The MCP server holds the same line. It takes content as an argument and returns data: no filesystem access, no network calls, no telemetry.
- Error notifications redact home directories and credential-shaped fragments.
Documentation
Performance
Median of 7 runs after warmup, on Apple M5 Pro, 24 GB RAM, Node 24.3.0. Inputs are generated
by scripts/benchmark.ts rather than checked in, so the sizes above are
exactly what was measured. Reproduce with bun run benchmark.
These are machine-specific and are not asserted in CI — a benchmark that gates a build only tells you how busy the runner was.
Testing
103 test cases across 11 files, plus an integration suite that runs
in a real VS Code extension host and an end-to-end test that installs the
built .vsix into a clean profile.
Generated from a real run — coverage/coverage-summary.json and
coverage/test-results.json — by scripts/coverage-readme.js; CI fails if
this section drifts. Reproduce with bun run test:coverage, and the case
count is the one vitest prints.
More from the LE family
Sixteen single-purpose tools for the work in front of every model. Each ships a Rust CLI and an MCP server. One page: letools.dev
Get it out
- String-LE — Extract every string in a codebase, with its position, so a person can read them
- Numbers-LE — Extract every hardcoded number in a codebase, so a person can check them
- Units-LE — Extract every quantity with its unit, normalized, and refuse the ambiguous ones by name
- Dates-LE — Extract every date and timestamp, and the exact instant each one resolves to
- IDs-LE — Extract every UUID, ULID, NanoID, ObjectId and Snowflake, and decode the time inside
- IPs-LE — Extract every IP address, CIDR block and MAC, normalized and classified by scope
- URLs-LE — Extract every URL in a codebase, with its protocol and exact position
- Paths-LE — Extract every file path in a codebase, and say whether it still points at anything
- Colors-LE — Extract every color in a codebase, and say which ones are not in your palette
Check it
- Regex-LE — Find every regex in a codebase, and report which can be driven into catastrophic backtracking
- Versions-LE — Find where one dependency is constrained differently across a repository's manifests
- i18n-LE — Identify the i18n library a project uses, then audit its catalogs by that library's rules
- Scrape-LE — Check whether a page is scrapeable before the scraper is written, and say when it cannot tell
Guard it
- Secrets-LE — Find hardcoded credentials in a codebase, and never print one into the report
- EnvSync-LE — Compare the dotenv files in a tree, and say which keys are missing from which
- Unicode-LE — Find the Unicode that hides meaning — bidi controls, invisibles, homoglyphs, mixed scripts
Each stands on its own: no shared crate, no published core. Where two of them agree, it is because the same answer was right twice.
Contact — nolindnaidoo.com · GitHub · LinkedIn
Also by nolindnaidoo
Rust — pixelcoords and pixelactions are one loop: pixelcoords answers where, pixelactions acts there. Their own tools, their own voice — not part of the LE family.
- pixelcoords — Freeze your screen, mark regions, get pixel-exact coordinates and crops pixelcoords.dev · crates.io · docs.rs
- pixelactions — Consume human-verified coordinates, perform the interaction, confirm it landed pixelactions.dev · crates.io · docs.rs
License
MIT © nolindnaidoo
來源:README.md,提交 79f19c5
工具
0版本歷史
1- v1.0.0最新Oct 4, 2026


