Unicode-LE
Find the Unicode that hides meaning — bidi controls, invisibles, homoglyphs, mixed scripts
The command-line tool and its MCP server are written and tested. The VS Code extension is not written yet, so there is nothing to install from the Marketplace or Open VSX — those links appear here when it ships rather than before.
No editor in the loop? unicode-le mcp runs the same engine as an MCP server, so an agent can call detect_unicode_risks over stdio, with no editor and no Node, and cargo install unicode-le puts the same check in a terminal. Every way to install it.

What Unicode-LE does
Some characters are not what they look like. Unicode-LE scans a tree for the ones that hide meaning: the bidirectional controls behind CVE-2021-42574, zero-width and other invisibles, homoglyphs, words no single script accounts for, text that is not in Normalization Form C, and the spaces that are not the space. It reports codepoints and never the characters themselves, because a report that pasted one raw would reorder the terminal, the diff and the pull request of whoever read it. It rewrites nothing. A file plainly written in another script is refused for the homoglyph checks rather than judged by them, which is what lets the screen stay on in an internationalised repository instead of being switched off for noise.
What people use it for
Gate CI on Trojan Source
Fail the build on the bidirectional-control class alone, or on every finding — the exit code is the interface.
Screen for forged names
A Cyrillic character sitting in an otherwise Latin word is a finding; a word written wholly in Cyrillic is not.
Explain the string that never matches
A zero-width space between two values a hash calls different and a person calls identical, reported at its key.
Install Unicode-LE
Command lineComing soon
cargo install unicode-leNot on crates.io yet — v0.2.1 builds from the repository today, and this command starts working the day it publishes. Follow the repository.
VS CodeComing soon
ext install nolindnaidoo.unicode-leThe extension is not written yet, so this id resolves to nothing on the Marketplace. It is the id it will take. Follow the repository.
Cursor / VSCodiumComing soon
cursor --install-extension OffensiveEdge.unicode-leSame again for the forks, which resolve Open VSX rather than the Marketplace. Follow the repository.
Zed
unicode-le mcpWorks in Zed today — add the command above as a custom MCP server from the agent panel, and detect_unicode_risks appears in its tool list. There is no one-click listing in Zed's extension registry yet.
AI agents
unicode-le mcpRuns Unicode-LE's engine as an MCP server over stdio, so an agent can call detect_unicode_risks with no editor and no Node. The binary is the server — there is nothing else to install.
Where it ships
One engine, 6 places to get it. The ids differ by registry — copy the one for the editor you use.
VS Code Marketplace
VS Code itselfnolindnaidoo.unicode-leOpenthe extension is not written yet — this links the sourceOpen VSX
Cursor, Windsurf, VSCodium and the other forksOffensiveEdge/unicode-leOpenthe extension is not written yet — this links the sourceMCP server
the same engine, callable by an agent with no editor in the loopunicode-le mcpOpenshipped by the binary, not by npm — no package to link yetZed
as a custom MCP server todayunicode-le mcpOpenno listing yet — this links Zed’s instructions for adding it by hand
Where Unicode-LE lives
- GitHubsource, issues, changelog
- MCP registryio.github.nolindnaidoo/unicode-le
The other 15
Extract every string in a codebase, with its position, so a person can read them
Extract every hardcoded number in a codebase, so a person can check them
Extract every file path in a codebase, and say whether it still points at anything
Extract every color in a codebase, and say which ones are not in your palette
Extract every URL in a codebase, with its protocol and exact position
Extract every date and timestamp, and the exact instant each one resolves to
Extract every quantity with its unit, normalized, and refuse the ambiguous ones by name
Extract every UUID, ULID, NanoID, ObjectId and Snowflake, and decode the time inside
Extract every IP address, CIDR block and MAC, normalized and classified by scope
Find every regex in a codebase, and report which can be driven into catastrophic backtracking
Check whether a page is scrapeable before the scraper is written, and say when it cannot tell
Find where one dependency is constrained differently across a repository's manifests
Identify the i18n library a project uses, then audit its catalogs by that library's rules
Find hardcoded credentials in a codebase, and never print one into the report
Compare the dotenv files in a tree, and say which keys are missing from which