omdsh-dev/dsh-tool-regex
DSH regex tool plug-in: test matching/extract capture group/safe replacement/statically interpret regex (no code execution), zero dependency, register regex tool
A deterministic regex tool plugin for DSH with four actions — test, find (index/full match/numbered captures/named groups), replace (global safe replacement with $1/$<name>/$$ semantics, no eval), and explain (statically parses a pattern into a human-readable node sequence without executing any match — naturally ReDoS-immune). Multi-layer ReDoS defense: worker-thread hard timeout (1,000ms terminate), input length cap (64,000 bytes), resource caps (pattern ≤ 16KB, replacement ≤ 16KB, output ≤ 1MB, match count ≤ 1,000), and zero-execution explain. Catches SyntaxError with position info; validates flags character by character.
Install
dsh plugin --profile web add github:omdsh-dev/dsh-tool-regexProfile Bundle (recommended, DSH 0.1.2-alpha.1): dsh plugin --profile web add github:omdsh-dev/dsh-tool-regex (also headless: dsh plugin --profile headless add github:omdsh-dev/dsh-tool-regex), or npm pack then dsh plugin --profile web add ./dsh-tool-regex-<version>.tgz. The bundled dsh.bundle.patch auto-adds the plugin layer (row id: tool-regex). Standalone build: npm install → typecheck → test → build → pack. Launch: npx -p @deepseek-ai/dsh@next dsh web.
Compatibility
DSH 0.1.2-alpha.1 (profile bundle); web and headless profiles. Zero-dependency, pure functions; works on the standard cordis patch-bundle model.
Details
- Repo: omdsh-dev/dsh-tool-regex
- Category: Coding & Development
- Stars: 3
- Version: GitHub source (profile-bundle install; no npm registry package)
- Last push: 2026-09-10
- First seen: 2026-08-07
Recent updates
regex test/find/replace/explain tools; ReDoS multi-layer defense (worker timeout + caps + zero-exec explain); deterministic JSON output.
FAQ
- How do I install it?
- Run dsh plugin --profile web add github:omdsh-dev/dsh-tool-regex — the dsh.bundle.patch auto-adds the layer; restart the profile.
- What makes explain ReDoS-safe?
- It only runs a static tokenizer and never constructs a RegExp instance, so any pattern returns immediately.
- What are the input limits?
- Input ≤ 64,000 bytes; pattern/replacement ≤ 16KB each; output ≤ 1MB; find reports ≤ 1,000 matches.
Alternatives
omdsh-dev/dsh-tool-json · omdsh-dev/dsh-tool-csv · omdsh-dev/dsh-tool-markdown