Skip to content
Limited Edition DevTools

Unicode-LE

Find the Unicode that hides meaning — bidi controls, invisibles, homoglyphs, mixed scripts

FreeOpen sourceMITNo network access

The command-line tool and its MCP server are written and tested. The VS Code extension is not written yet, so there is nothing to install from the Marketplace or Open VSX — those links appear here when it ships rather than before.

No editor in the loop? unicode-le mcp runs the same engine as an MCP server, so an agent can call detect_unicode_risks over stdio, with no editor and no Node, and cargo install unicode-le puts the same check in a terminal. Every way to install it.

Unicode-LE in use: Find the Unicode that hides meaning — bidi controls, invisibles, homoglyphs, mixed scripts

What Unicode-LE does

Some characters are not what they look like. Unicode-LE scans a tree for the ones that hide meaning: the bidirectional controls behind CVE-2021-42574, zero-width and other invisibles, homoglyphs, words no single script accounts for, text that is not in Normalization Form C, and the spaces that are not the space. It reports codepoints and never the characters themselves, because a report that pasted one raw would reorder the terminal, the diff and the pull request of whoever read it. It rewrites nothing. A file plainly written in another script is refused for the homoglyph checks rather than judged by them, which is what lets the screen stay on in an internationalised repository instead of being switched off for noise.

What people use it for

Gate CI on Trojan Source

Fail the build on the bidirectional-control class alone, or on every finding — the exit code is the interface.

Screen for forged names

A Cyrillic character sitting in an otherwise Latin word is a finding; a word written wholly in Cyrillic is not.

Explain the string that never matches

A zero-width space between two values a hash calls different and a person calls identical, reported at its key.

Install Unicode-LE

Command lineComing soon

cargo install unicode-le

Not on crates.io yet — v0.2.1 builds from the repository today, and this command starts working the day it publishes. Follow the repository.

VS CodeComing soon

ext install nolindnaidoo.unicode-le

The extension is not written yet, so this id resolves to nothing on the Marketplace. It is the id it will take. Follow the repository.

Cursor / VSCodiumComing soon

cursor --install-extension OffensiveEdge.unicode-le

Same again for the forks, which resolve Open VSX rather than the Marketplace. Follow the repository.

Zed

unicode-le mcp

Works in Zed today — add the command above as a custom MCP server from the agent panel, and detect_unicode_risks appears in its tool list. There is no one-click listing in Zed's extension registry yet.

AI agents

unicode-le mcp

Runs Unicode-LE's engine as an MCP server over stdio, so an agent can call detect_unicode_risks with no editor and no Node. The binary is the server — there is nothing else to install.

Where it ships

One engine, 6 places to get it. The ids differ by registry — copy the one for the editor you use.

Where Unicode-LE lives

The other 15

Extract every string in a codebase, with its position, so a person can read them

Extract every hardcoded number in a codebase, so a person can check them

Extract every file path in a codebase, and say whether it still points at anything

Extract every color in a codebase, and say which ones are not in your palette

Extract every URL in a codebase, with its protocol and exact position

Extract every date and timestamp, and the exact instant each one resolves to

Extract every quantity with its unit, normalized, and refuse the ambiguous ones by name

Extract every UUID, ULID, NanoID, ObjectId and Snowflake, and decode the time inside

Extract every IP address, CIDR block and MAC, normalized and classified by scope

Find every regex in a codebase, and report which can be driven into catastrophic backtracking

Check whether a page is scrapeable before the scraper is written, and say when it cannot tell

Find where one dependency is constrained differently across a repository's manifests

Identify the i18n library a project uses, then audit its catalogs by that library's rules

Find hardcoded credentials in a codebase, and never print one into the report

Compare the dotenv files in a tree, and say which keys are missing from which