AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Backtrack

skill-lkc-studio-claude-plugins-backtrack · by lkc-studio

This skill should be used when a regex might be exploitable or slow — when the user says "is this regex safe", "ReDoS", "catastrophic backtracking", "the regex hangs", "one request pins the CPU", "check my regexes for denial of service", or is writing a pattern that validates user-supplied input. Statically flags backtracking-prone regexes, then proves the dangerous ones by feeding them a crafted…

No reviews yet
0 installs
30 views
0.0% view→install

Install

$ agentstack add skill-lkc-studio-claude-plugins-backtrack

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-lkc-studio-claude-plugins-backtrack)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Backtrack? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Backtrack: regexes a single input can freeze

Some regex shapes take exponential time on a crafted string. (a+)+$ against "aaaaaaaaaaaaaaaaaaaaaaX" makes the engine try every way to partition the a's before it can conclude there is no match — a couple of dozen characters can pin a CPU for minutes. When that regex validates user input, one request is a denial of service.

The vulnerability is called ReDoS, and it is common precisely because the patterns look innocent. (\d+)*, (\w+\s?)+, (a|a)* — all ordinary-looking, all catastrophic.

Static suspicion is not enough — this proves it

The distinctive move: structure analysis only suspects. Whether a pattern actually blows up depends on subtleties (anchoring, whether the branches truly overlap) that are hard to settle by reading. So backtrack then proves — it feeds each suspect a growing attack string, times the match, and confirms only the ones whose runtime actually explodes.

suspect     nested/overlapping quantifier found by structure
CONFIRMED   runtime measured to blow up super-linearly with input length

A confirmed finding comes with the exact attack string and the measured slowdown. That is evidence, not a heuristic — you can hand it to whoever owns the regex and they can reproduce it.

Step 1: scan

scripts/backtrack.py app.py            # one file, static + dynamic
scripts/backtrack.py --all src/        # a tree
scripts/backtrack.py --static-only x.py  # skip timing (fast, CI-friendly)
scripts/backtrack.py --json app.py     # machine-readable

Standard library only. It extracts regex literals passed to re.*, flags the suspect structures, then confirms.

  app.py:2  [CONFIRMED]
      /^(a+)+$/
      nested quantifier -- a group repeated inside another repeat
      attack: 'a' * 26 + a non-matching byte   (~260x slower over 8 more chars)

Exit code: 2 if anything is confirmed, 1 if only unproven suspects, 0 if clean.

The dynamic pass is safe

A catastrophic regex cannot be timed in-process — Python's re has no per-call timeout and the C matcher ignores signals mid-run, so a blow-up would hang the scanner itself. Each timing run therefore happens in a separate process group that is SIGKILLed at the timeout. Nothing is left burning CPU. (This is the lesson from the strays skill applied deliberately; a tool that hunts runaway processes must not create them.)

Step 2: fix a confirmed pattern

The cause is always the same: the engine has more than one way to match the same input, so on failure it tries them all. Remove the ambiguity.

  • Nested quantifiers (a+)+ → collapse to a single quantifier: a+.

The nesting adds nothing but backtracking.

  • Overlapping alternation (a|ab)* → make the branches mutually exclusive,

or anchor so only one can match at each position.

  • Adjacent open-ended repeats .*x.* → anchor, or bound the repeats

([^x]*x.*) so they cannot overlap.

Engine-level fixes when the pattern cannot be simplified:

  • Possessive quantifiers / atomic groups ((?>...), a++) tell the engine

never to backtrack into that group. Available in the regex module on PyPI, not the stdlib re.

  • A non-backtracking engine — Go's regexp, Rust's regex, or RE2 — runs

in guaranteed linear time. Best for regexes that must handle untrusted input at scale.

  • Bound the input length before matching. A cap of a few hundred characters

turns "minutes" into "milliseconds" and is a cheap defence in depth even after the pattern is fixed.

references/redos.md has the vulnerable-shape catalog, worked rewrites, and per-language engine notes.

Step 3: verify the fix

Rerun backtrack.py on the fixed pattern. A correct rewrite drops from CONFIRMED to absent — the same attack string no longer blows up. Re-running is the proof the fix worked, exactly as the original run was the proof it was broken.

Limits

  • Only literal regexes passed to re.* are seen. Patterns built at runtime

from concatenated strings are invisible to static extraction.

  • The dynamic pass can have false negatives. A pattern needing a longer or

differently-shaped input than the tool tries may not blow up within the time budget. suspect-but-unconfirmed still deserves a look.

  • False positives are possible in the static pass and are exactly why the

dynamic pass exists — trust CONFIRMED over suspect.

  • Confirmation proves a pattern is vulnerable; absence of confirmation does not

prove it is safe. For regexes on untrusted input, prefer a linear-time engine regardless.

Resources

  • scripts/backtrack.py — static structural analysis plus a killable,

process-group-isolated dynamic confirmation pass. --static-only, --all, --json.

  • references/redos.md — the catalog of catastrophic shapes, side-by-side

rewrites, engine and language options, and input-hardening.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.