Agent skill

Phy Regex Audit

by LeoYeAI in LeoYeAI/openclaw-master-skills

Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.

Apache-2.0Auto-check passedSecurity

Install Phy Regex Audit

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill phy-regex-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills phy-regex-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/phy-regex-audit .claude/skills/phy-regex-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
phy-regex-audit
GitHub stars
2.2k
Token cost
~5.1k tokens
SKILL.md length
404 words
Files
2
Skills in repo
1,235
Repo updated
First seen
Licence
Apache-2.0

At a glance

Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.

  • Works in 5 steps: Discover Source Files → Extract Regex Literals → Detect ReDoS Patterns → …
  • Catastrophic backtracking
  • SKILL.md covers Trigger Phrases, How to Provide Input, Step 1: Discover Source Files and Step 2: Extract Regex Literals, plus 3 more sections
  • Calls python3 and npx

What it does

Phy Regex Audit is an agent skill from LeoYeAI/openclaw-master-skills. Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases. Walks all source files to extract regex literals, detects catastrophic backtracking patterns (nested quantifiers, overlapping alternation, unbounded repetition on complex groups), severity-ranks each finding as CRITICAL/HIGH/MEDIUM, reports file and line number with the dangerous sub-pattern highlighted, identifies high-risk call sites (HTTP request handlers, form validators, URL parsers), and…

Its SKILL.md is about 5.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `_meta.json`).

It sits in Security, covering Vulnerability scanning and Static analysis and SAST. It works with Java, PHP, Python and Ruby. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.

When your agent uses it

  • Catastrophic backtracking
  • Regex vulnerability

Example prompts

  • “regex security”
  • “catastrophic backtracking”
  • “regex audit”
  • “/phy-regex-audit”

Requirements

  • Python 3
  • Node.js

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Discover Source Files
  2. Extract Regex Literals
  3. Detect ReDoS Patterns
  4. Run Full Scan
  5. Output Report

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Phy Regex Audit loads about 5.1k tokens when it runs. Until then it costs about 241 tokens; SKILL.md has 404 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~241
When it runs · the whole SKILL.md, loaded when a task matches
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 404 words, ~5,082 tokens.

Download SKILL.mdSave it as .claude/skills/phy-regex-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
phy-regex-audit
description
Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases. Walks all source files to extract regex literals, detects catastrophic backtracking patterns (nested quantifiers, overlapping alternation, unbounded repetition on complex groups), severity-ranks each finding as CRITICAL/HIGH/MEDIUM, reports file and line number with the dangerous sub-pattern highlighted, identifies high-risk call sites (HTTP request handlers, form validators, URL parsers), and suggests safe rewrites using atomic groups or simplified alternatives. Also detects hardcoded locale assumptions (character classes assuming ASCII), overly permissive patterns, and regexes missing anchors. Supports JS/TS, Python, Go, Java, Ruby, PHP, Rust. Zero external API — pure static analysis. Triggers on "regex security", "ReDoS", "catastrophic backtracking", "regex audit", "slow regex", "regex vulnerability", "/regex-audit".
license
Apache-2.0
metadata.author
PHY041
metadata.version
1.0.0
metadata.tags
security, regex, redos, performance, static-analysis, developer-tools, javascript, python, denial-of-service

ReDoS & Regex Quality Auditor

One regex. One crafted input. Your Node.js server hangs for 30 seconds.

ReDoS (Regular Expression Denial of Service) is real, underestimated, and embarrassingly fixable. This skill walks every source file in your project, extracts regex literals, identifies catastrophic backtracking patterns, and tells you exactly which ones are dangerous and how to fix them.

Supports JS/TS, Python, Go, Java, Ruby, PHP, Rust. Zero external API.


Trigger Phrases

  • "regex security", "ReDoS", "catastrophic backtracking"
  • "regex audit", "slow regex", "regex vulnerability"
  • "check my regexes", "regex denial of service"
  • "is this regex safe", "regex performance"
  • "hardcoded locale regex", "missing anchor"
  • "/regex-audit"

How to Provide Input

bash
# Option 1: Audit current directory (auto-detect all source files)
/regex-audit

# Option 2: Specific directory or file
/regex-audit src/
/regex-audit lib/validators.js

# Option 3: Focus on specific language
/regex-audit --lang js
/regex-audit --lang python

# Option 4: Show only CRITICAL and HIGH severity
/regex-audit --min-severity high

# Option 5: Check a single regex pattern for safety
/regex-audit --pattern "^(a+)+"

# Option 6: Focus on HTTP handler files (highest risk)
/regex-audit --high-risk-only

# Option 7: Output machine-readable JSON for CI
/regex-audit --json

Step 1: Discover Source Files

bash
python3 -c "
import glob, os
from pathlib import Path

# Language file patterns
patterns = {
    'JavaScript/TypeScript': ['**/*.js', '**/*.ts', '**/*.jsx', '**/*.tsx', '**/*.mjs'],
    'Python':    ['**/*.py'],
    'Go':        ['**/*.go'],
    'Java':      ['**/*.java'],
    'Ruby':      ['**/*.rb'],
    'PHP':       ['**/*.php'],
    'Rust':      ['**/*.rs'],
}

skip_dirs = {'node_modules', '.git', 'dist', 'build', '.next', 'vendor', '__pycache__', '.venv', 'venv'}

all_files = []
for lang, file_patterns in patterns.items():
    lang_files = []
    for p in file_patterns:
        for f in glob.glob(p, recursive=True):
            parts = set(Path(f).parts)
            if not parts & skip_dirs:
                lang_files.append(f)
    if lang_files:
        print(f'{lang}: {len(lang_files)} files')
        all_files.extend(lang_files)

print(f'\\nTotal: {len(all_files)} source files to scan')
"

Step 2: Extract Regex Literals

python
import re
from pathlib import Path
from dataclasses import dataclass
from typing import Optional

@dataclass
class RegexMatch:
    file: str
    line: int
    pattern: str
    raw_context: str      # the surrounding code line
    language: str
    in_handler: bool      # is this in an HTTP handler / validator?

# Language-specific regex extraction patterns
EXTRACTORS = {
    'js': [
        # Regex literals: /pattern/flags
        re.compile(r'(?<![=!<>])\/([^\/\n\r]{3,}?)\/([gimsuy]*)'),
        # new RegExp("pattern")
        re.compile(r'new\s+RegExp\(["\']([^"\']{3,})["\']'),
        # .test(), .match(), .exec() with string literal
        re.compile(r'\.(?:test|match|exec|replace|search)\(["\'/]([^"\'\/\n]{3,})["\'/]'),
    ],
    'python': [
        # re.compile(r"pattern")
        re.compile(r're\.(?:compile|match|search|fullmatch|findall|finditer|sub|subn|split)\(["\']([^"\']{3,})["\']'),
        re.compile(r're\.(?:compile|match|search|fullmatch|findall|finditer|sub|subn|split)\(r["\']([^"\']{3,})["\']'),
    ],
    'go': [
        # regexp.MustCompile(`pattern`)
        re.compile(r'regexp\.(?:MustCompile|Compile|Match|MatchString)\(["`]([^"`]{3,})["`]'),
    ],
    'java': [
        # Pattern.compile("pattern")
        re.compile(r'Pattern\.compile\(["\']([^"\']{3,})["\']'),
        re.compile(r'\.matches\(["\']([^"\']{3,})["\']'),
    ],
    'ruby': [
        # /pattern/ or Regexp.new("pattern")
        re.compile(r'\/([^\/\n]{3,})\/'),
        re.compile(r'Regexp\.new\(["\']([^"\']{3,})["\']'),
    ],
    'php': [
        # preg_match('/pattern/', ...)
        re.compile(r'preg_(?:match|replace|split|grep)\(["\']([^"\']{3,})["\']'),
    ],
    'rust': [
        # Regex::new(r"pattern")
        re.compile(r'Regex::new\([r]?["\']([^"\']{3,})["\']'),
    ],
}

# Keywords that indicate high-risk call sites
HIGH_RISK_CONTEXTS = [
    'app.get', 'app.post', 'app.put', 'app.delete',
    'router.', 'express', 'fastify', 'koa',
    'validate', 'validator', 'sanitize',
    'request.body', 'req.body', 'req.params', 'req.query',
    'process.argv', 'sys.argv',
    'input(', 'readline(',
    'url.parse', 'new URL(',
    '@app.route', 'flask.request',
    'r.URL.Query', 'r.FormValue',
]

LANG_MAP = {
    '.js': 'js', '.jsx': 'js', '.ts': 'js', '.tsx': 'js', '.mjs': 'js',
    '.py': 'python',
    '.go': 'go',
    '.java': 'java',
    '.rb': 'ruby',
    '.php': 'php',
    '.rs': 'rust',
}


def extract_regexes_from_file(fpath: str) -> list[RegexMatch]:
    """Extract all regex literals from a source file."""
    ext = Path(fpath).suffix.lower()
    lang = LANG_MAP.get(ext)
    if not lang or lang not in EXTRACTORS:
        return []

    try:
        lines = Path(fpath).read_text(encoding='utf-8', errors='replace').splitlines()
    except Exception:
        return []

    results = []
    for line_num, line in enumerate(lines, 1):
        # Check if this line is in a high-risk context (look at surrounding 5 lines)
        context_window = '\n'.join(lines[max(0, line_num-5):line_num+5])
        in_handler = any(kw in context_window for kw in HIGH_RISK_CONTEXTS)

        for extractor in EXTRACTORS[lang]:
            for m in extractor.finditer(line):
                pattern = m.group(1)
                if len(pattern) >= 3:
                    results.append(RegexMatch(
                        file=fpath,
                        line=line_num,
                        pattern=pattern,
                        raw_context=line.strip(),
                        language=lang,
                        in_handler=in_handler,
                    ))

    return results

Step 3: Detect ReDoS Patterns

python
from enum import Enum

class Severity(Enum):
    CRITICAL = 4   # Exponential backtracking — proven DoS vector
    HIGH = 3       # Polynomial backtracking — slow on long inputs
    MEDIUM = 2     # Potentially slow — context-dependent
    LOW = 1        # Style/quality issue

@dataclass
class ReDoSFinding:
    regex_match: RegexMatch
    severity: Severity
    vulnerability_type: str
    dangerous_subpattern: str
    description: str
    attack_input_example: str
    fix_suggestion: str


# ReDoS pattern signatures
REDOS_PATTERNS = [

    # ===== CRITICAL: Exponential Backtracking =====

    {
        'name': 'NESTED_QUANTIFIERS',
        'severity': Severity.CRITICAL,
        'detector': re.compile(r'\(([^()]{1,30}\+[^()]{0,10})\)\+|\(([^()]{1,30}\*[^()]{0,10})\)\+'),
        'description': 'Nested quantifiers (a+)+ or (a*)+ create exponential backtracking.',
        'attack_shape': 'Long string of matching chars followed by one non-matching char',
        'example_attack': '"aaaaaaaaaaaaaaaaaaaaaaaaaX"',
        'fix': 'Use atomic group (?>...) or possessive quantifier — rewrite to remove nesting.',
    },
    {
        'name': 'NESTED_STAR_PLUS',
        'severity': Severity.CRITICAL,
        'detector': re.compile(r'\(([^()]{1,30})\)\*\+|\(([^()]{1,30})\)\+\*'),
        'description': 'Nested star/plus combination enables exponential path explosion.',
        'attack_shape': 'Repeated matching chars followed by failure',
        'example_attack': '"aaaaaaaaaaaX"',
        'fix': 'Flatten quantifiers or use possessive quantifiers.',
    },

    # ===== HIGH: Polynomial Backtracking =====

    {
        'name': 'ALTERNATION_OVERLAP',
        'severity': Severity.HIGH,
        'detector': re.compile(r'\(([a-zA-Z]{1,5})\|([a-zA-Z]{1,5})\)\+|\(([a-zA-Z]{1,5})\|([a-zA-Z]{1,5})\)\*'),
        'description': 'Overlapping alternation with quantifier: (ab|a)+ causes polynomial backtracking.',
        'attack_shape': 'Long string that partially matches both alternatives',
        'example_attack': '"ababababababababX"',
        'fix': 'Reorder alternatives longest-first; avoid overlapping prefixes. Use (?>a(?:b)?)+ instead of (ab|a)+',
    },
    {
        'name': 'GREEDY_DOTSTAR_ANCHORED',
        'severity': Severity.HIGH,
        'detector': re.compile(r'\.\*.*\.\*'),
        'description': 'Multiple .* in sequence causes O(n²) backtracking on non-matching inputs.',
        'attack_shape': 'Long string that partially matches then fails at the end',
        'example_attack': '"a" * 10000 + "X"',
        'fix': 'Use [^\\n]* instead of .* when newlines are impossible; add anchors.',
    },

    # ===== MEDIUM: Potentially Slow =====

    {
        'name': 'UNBOUNDED_REPETITION_COMPLEX',
        'severity': Severity.MEDIUM,
        'detector': re.compile(r'\([^()]{5,}\)\{[0-9,]+\}'),
        'description': 'Large repetition count on complex group — can be slow on long non-matching inputs.',
        'attack_shape': 'Input that triggers maximum iterations before failing',
        'example_attack': 'Input matching N-1 repetitions but failing on last character',
        'fix': 'Add possessive quantifier or reduce repetition scope.',
    },
    {
        'name': 'MISSING_ANCHORS',
        'severity': Severity.MEDIUM,
        'detector': None,  # Checked separately
        'description': 'Regex without ^ or $ anchors on email/URL patterns causes full-text search instead of match.',
        'attack_shape': 'Input containing valid pattern embedded in garbage',
        'example_attack': '"evil.com/redirect?to=legit.com"',
        'fix': 'Add ^ at start and $ at end: /^pattern$/',
    },
]


def analyze_regex_for_redos(rm: RegexMatch) -> list[ReDoSFinding]:
    """Check a single regex for ReDoS vulnerabilities."""
    findings = []
    pattern = rm.pattern

    for sig in REDOS_PATTERNS:
        if sig['detector'] is None:
            continue
        match = sig['detector'].search(pattern)
        if match:
            findings.append(ReDoSFinding(
                regex_match=rm,
                severity=sig['severity'],
                vulnerability_type=sig['name'],
                dangerous_subpattern=match.group(0),
                description=sig['description'],
                attack_input_example=sig.get('example_attack', ''),
                fix_suggestion=sig['fix'],
            ))

    # Check for missing anchors on patterns that look like email/URL/phone validators
    looks_like_validator = any(
        kw in rm.raw_context.lower()
        for kw in ['email', 'url', 'phone', 'validate', 'isValid', 'check']
    )
    if looks_like_validator and not (pattern.startswith('^') or pattern.endswith('$')):
        findings.append(ReDoSFinding(
            regex_match=rm,
            severity=Severity.MEDIUM,
            vulnerability_type='MISSING_ANCHORS',
            dangerous_subpattern=pattern[:40],
            description='Validator regex lacks ^ and $ anchors — matches anywhere in string.',
            attack_input_example='"garbage_validinput_garbage"',
            fix_suggestion=f'Add anchors: /^{pattern[:40]}$/',
        ))

    return findings


def check_locale_assumptions(rm: RegexMatch) -> Optional[ReDoSFinding]:
    """Detect ASCII-only character classes that should be locale-aware."""
    ASCII_ONLY_HINTS = [
        (re.compile(r'\[a-zA-Z\]|\[a-z\]|\[A-Z\]'), 'Matches only ASCII letters — fails on é, ü, ñ, etc.'),
        (re.compile(r'\[0-9\]'), 'Use \\d or [0-9] explicitly; be aware \\d matches Unicode digits in some engines'),
    ]
    for detector, msg in ASCII_ONLY_HINTS:
        if detector.search(rm.pattern):
            return ReDoSFinding(
                regex_match=rm,
                severity=Severity.LOW,
                vulnerability_type='LOCALE_ASSUMPTION',
                dangerous_subpattern=detector.search(rm.pattern).group(0),
                description=f'ASCII-only character class: {msg}',
                attack_input_example='"Ångström" or "naïve"',
                fix_suggestion='Use \\p{L} (Unicode letter) if your regex engine supports it, or explicitly list the characters you need.',
            )
    return None

Step 4: Run Full Scan

python
import os
import glob

def run_regex_audit(target_dir='.', min_severity=Severity.LOW, high_risk_only=False):
    """Full scan: discover files, extract regexes, analyze, report."""

    # Discover files
    all_files = []
    for ext in ['.js', '.jsx', '.ts', '.tsx', '.mjs', '.py', '.go', '.java', '.rb', '.php', '.rs']:
        pattern = f'{target_dir}/**/*{ext}'
        for f in glob.glob(pattern, recursive=True):
            if not any(skip in f for skip in ['node_modules', '.git', 'dist', 'build', '.next', 'vendor']):
                all_files.append(f)

    # Extract and analyze
    all_findings = []
    total_regexes = 0

    for fpath in all_files:
        regexes = extract_regexes_from_file(fpath)
        total_regexes += len(regexes)

        for rm in regexes:
            if high_risk_only and not rm.in_handler:
                continue

            findings = analyze_regex_for_redos(rm)
            locale_finding = check_locale_assumptions(rm)
            if locale_finding:
                findings.append(locale_finding)

            for f in findings:
                if f.severity.value >= min_severity.value:
                    all_findings.append(f)

    # Sort by severity desc, then file
    all_findings.sort(key=lambda x: (-x.severity.value, x.regex_match.file, x.regex_match.line))

    return all_findings, total_regexes, len(all_files)

Step 5: Output Report

markdown
## ReDoS & Regex Security Audit
Project: my-app | Files scanned: 847 | Regexes found: 214

---

### Summary

| Severity | Count | Description |
|----------|-------|-------------|
| 🔴 CRITICAL | 2 | Exponential backtracking — proven DoS vector |
| 🟠 HIGH | 4 | Polynomial backtracking — slow on long inputs |
| 🟡 MEDIUM | 7 | Potentially slow or logic error |
| ⚪ LOW | 11 | Style/locale issues |

**⚠️ 3 findings are in HTTP request handlers — prioritize these.**

---

### 🔴 CRITICAL — Exponential Backtracking

**#1 — src/middleware/auth.js:47**
```js
// Context: JWT token format validator in Express middleware
app.use('/api', (req, res, next) => {
    const token = req.headers.authorization
    if (!/^([a-zA-Z0-9_-]+\.)+[a-zA-Z0-9_-]+$/.test(token)) { ... }

Dangerous pattern: ([a-zA-Z0-9_-]+\.)+ Vulnerability: NESTED_QUANTIFIERS — the inner + and outer + create exponential backtracking. Attack input: "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" (no dot — triggers backtracking) DoS potential: Input of length 30 takes ~2 seconds on Node.js. Length 50 takes minutes. In HTTP handler: ⚠️ YES — any unauthenticated request can trigger this.

Fix:

js
// Before (vulnerable):
/^([a-zA-Z0-9_-]+\.)+[a-zA-Z0-9_-]+$/

// After (safe):
// Option 1: Possessive quantifier (not supported in JS — use atomic group via lookbehind trick)
// Option 2: Rewrite without nested quantifiers:
/^[a-zA-Z0-9_-]+(?:\.[a-zA-Z0-9_-]+)+$/
// This eliminates the nested quantifier — the outer group cannot backtrack
// into positions already consumed by the inner match.

#2 — src/utils/email-validator.ts:12

ts
const EMAIL_RE = /^(([^<>()\[\]\\.,;:\s@"]+(\.[^<>()\[\]\\.,;:\s@"]+)*)|(".+"))@/

Dangerous pattern: ([^<>...]+(\.[^<>...]+)*) Vulnerability: NESTED_QUANTIFIERS inside alternation Attack input: "a.a.a.a.a.a.a.a.a.a.a.a.a.a.a.a.a.a.a@" (missing domain after @) Fix:

ts
// Use a proven safe email regex:
const EMAIL_RE = /^[^\s@]+@[^\s@]+\.[^\s@]+$/
// For strict RFC 5322: use the validator.js library (pre-audited, safe)
// npm install validator → isEmail(str)

🟠 HIGH — Polynomial Backtracking

#3 — src/api/search.js:89

js
// URL parameter parser
const queryRe = /.*id=.*&.*/

Vulnerability: GREEDY_DOTSTAR_ANCHORED — .*...* is O(n²) Attack input: 10,000-char query string with no id= → scans 10,000 × 10,000 positions In HTTP handler: ⚠️ YES — req.query passed directly

Fix:

js
// Before:
/.*id=.*&.*/
// After (anchored, no double .* scan):
/(?:^|&)id=([^&]+)/

🟡 MEDIUM — Missing Anchors

#5 — src/validation/phone.ts:3

ts
const PHONE_RE = /\+?[0-9]{10,15}/   // used in: validatePhone(userInput)

Issue: No ^ or $ anchor — matches +15551234567 embedded in "Call +15551234567 for support". Attack scenario: Attacker bypasses phone validation by embedding valid number in malicious input.

Fix:

ts
const PHONE_RE = /^\+?[0-9]{10,15}$/

Show full SKILL.md (156 more words)Show less
⚪ LOW — Locale Assumptions

#8 — src/utils/slugify.ts:7

ts
.replace(/[^a-zA-Z0-9-]/g, '-')

Issue: [a-zA-Z] excludes ñ, é, ü, ç, ș — slugs for non-English content will be all dashes. Fix: Normalize Unicode first: str.normalize('NFKD').replace(/[\u0300-\u036f]/g, '').replace(/[^a-z0-9-]/gi, '-')


CI Integration

Add to your test suite or pre-commit hook:

bash
# One-liner scan — exits non-zero if CRITICAL or HIGH found
python3 -c "
import re, sys, glob

NESTED_Q = re.compile(r'\(([^()]{1,30}\+[^()]{0,10})\)\+|\(([^()]{1,30})\)\*\+')
DOUBLE_STAR = re.compile(r'\.\*[^)]{0,10}\.\*')

found = []
for fpath in glob.glob('src/**/*.{js,ts,py}', recursive=True):
    lines = open(fpath, errors='replace').readlines()
    for i, line in enumerate(lines, 1):
        for m in re.finditer(r'/((?:[^/\\]|\\.){3,})/', line):
            pat = m.group(1)
            if NESTED_Q.search(pat) or DOUBLE_STAR.search(pat):
                found.append(f'{fpath}:{i}: {pat[:60]}')

if found:
    print(f'FAIL: {len(found)} ReDoS-vulnerable regex(es) found:')
    for f in found: print(' ', f)
    sys.exit(1)
else:
    print(f'PASS: No ReDoS patterns detected')
"

Resources
  • safe-regex npm package: npx safe-regex "your-pattern" — quick single-pattern check
  • vuln-regex-detector: more comprehensive, uses fuzzing
  • OWASP ReDoS prevention: https://owasp.org/www-community/attacks/ReDoS
  • Cloudflare outage 2019: caused by a single ReDoS regex in a WAF rule
  • Stack Overflow outage 2016: caused by \s* nested inside \s+ in a markdown parser

---

## Quick Mode Output

ReDoS Audit: my-app (847 files, 214 regexes)

🔴 CRITICAL (2): 2 exponential-backtracking patterns in HTTP handlers src/middleware/auth.js:47 — ([a-zA-Z0-9_-]+.)+ nested quantifiers src/utils/email-validator.ts:12 — complex email regex, nested groups

🟠 HIGH (4): polynomial backtracking src/api/search.js:89 — double .* in query parser (in HTTP handler ⚠️) src/parsers/csv.ts:23, src/lib/url.js:15, src/routes/user.ts:88

🟡 MEDIUM (7): missing anchors (5), unbounded complex groups (2) ⚪ LOW (11): locale assumptions in character classes

Priority: Fix auth.js:47 first — it's in unauthenticated middleware, CRITICAL severity Quick win: s/([a-zA-Z0-9_-]+.)+/[a-zA-Z0-9_-]+(?:.[a-zA-Z0-9_-]+)+/ → safe in 30 seconds

© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/phy-regex-audit of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • _meta.json

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Phy Regex Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Phy Regex Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Phy Regex Audit this skillLeoYeAI/openclaw-master-skills2.2k—~5.1kAutomated safety check: PassApache-2.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Skylosduriantaco/skylos844—~581Automated safety check: PassApache-2.0
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
Skylos Securityduriantaco/skylos844—~545Automated safety check: PassApache-2.0

Similar skills

  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check: notes
  • Skylos

    duriantaco/skylos

    Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

    844 GitHub stars~581 tokensUpdated today
    SecurityAuto-check passed
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 3 days ago
    SecurityAuto-check: notes
  • Skylos Security

    duriantaco/skylos

    Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

    844 GitHub stars~545 tokensUpdated today
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    283 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Phy Regex Audit

What does Phy Regex Audit do?

Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases. Phy Regex Audit is an agent skill from LeoYeAI/openclaw-master-skills. Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.

When should I use Phy Regex Audit?

Phy Regex Audit fits situations like: catastrophic backtracking; regex vulnerability.

How do I install Phy Regex Audit in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill phy-regex-audit -a claude-code`. Or copy the skill folder (skills/phy-regex-audit in LeoYeAI/openclaw-master-skills) into .claude/skills/phy-regex-audit in your project. Claude Code loads it when a task matches its description.

How do I install Phy Regex Audit in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill phy-regex-audit -a codex`. Or copy the skill folder (skills/phy-regex-audit in LeoYeAI/openclaw-master-skills) into .agents/skills/phy-regex-audit in your project. Codex loads it when a task matches its description.

Can I use Phy Regex Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill phy-regex-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phy-regex-audit, .gemini/skills/phy-regex-audit, .github/skills/phy-regex-audit and .opencode/skills/phy-regex-audit in your project.

What does Phy Regex Audit need to run?

Going by SKILL.md and its folder, Phy Regex Audit needs the command-line tools its instructions call (python3 and npx). Our summary lists: Python 3; Node.js.

Does Phy Regex Audit access the network?

SKILL.md names 1 domain. As links in the text: owasp.org. This is read from the text; nothing was executed.

Is Phy Regex Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Phy Regex Audit use?

Phy Regex Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Phy Regex Audit use?

About 5.1k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Phy Regex Audit?

Skills that share tags, products or a category with Phy Regex Audit: Security Review (github/awesome-copilot, 40k stars), CodeQL Security Scan (trailofbits/skills, 7.5k stars), Skylos (duriantaco/skylos, 844 stars) and Pyspector Security Audit (ParzivalHack/PySpector, 151 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Phy Regex Audit?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.