Back to Browse

Ghostchars MCP Server

Developer ToolsModerate5.7MCP RegistryLocal
Free

Server data from the Official MCP Registry

Find and remove invisible Unicode: zero-width, tag smuggling, bidi, homoglyphs. Offline.

About

Find and remove invisible Unicode: zero-width, tag smuggling, bidi, homoglyphs. Offline.

Security Report

5.7
Moderate5.7Moderate Risk

Ghostchars is a well-maintained Unicode text cleaning tool with a clean architecture, proper dependency management, and no security vulnerabilities detected. The MCP server implementation follows security best practices with no authentication requirements (appropriate for a text-processing utility), proper input handling, and clear separation of concerns. Minor code quality observations exist but do not impact security. Supply chain analysis found 2 known vulnerabilities in dependencies (1 critical, 0 high severity). Package verification found 1 issue.

4 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

env_vars

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-ghostchars-ghostchars": {
      "args": [
        "-y",
        "ghostchars"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Ghostchars

Ghostchars finds and removes the characters that hide in text: zero-width spaces, bidi overrides, tag characters, soft hyphens, stray variation selectors, noncharacters, and the typography that reads as machine written. It runs offline. Nothing you clean leaves your machine.

This repository is the engine behind ghostchars.com and the free tools built on it. The same cleaner exists twice, in Python and in TypeScript, and one fixture file proves the two agree on every codepoint.

What is here

pathwhat it is
strip_invisible.pyThe reference engine. Stdlib only, one file. See PYTHON.md.
clean_file.py, style_report.pyDocuments (.docx, .odt, .html) and the style report, on the same engine.
web/src/engine/The TypeScript port. The website, the CLI and the MCP server run this.
cli/ghostchars on npm: a Node CLI, a stdio MCP server, and the agent skill, hook and pre-commit files.
tools/The generators for the Unicode tables and the golden fixtures, and the parity gates.
tests/The Python tests.

Quick start

npx -y ghostchars check --bar text        # the gate: exit 1 if the tree is dirty
pbpaste | npx -y ghostchars clean         # clean the clipboard
./strip_invisible.py --show draft.md      # the reference engine, no install

cli/README.md documents every command, the three bars, ghostchars.json and the agent integrations.

How the two engines stay identical

The Python engine is the specification. tools/gen_golden.py runs it over every fixture and records the findings and the cleaned output for each flag combination in web/src/engine/__fixtures__/golden.json. The TypeScript engine replays that file in its test suite, so a port that disagrees with the reference by one codepoint fails its build. The Unicode property tables the port needs are generated from the same unicodedata snapshot by tools/gen_unicode_tables.py. Two commands fail when anything drifts:

python3 tools/gen_golden.py --check
python3 tools/gen_unicode_tables.py --check

Working on it

Python 3.10 or newer for the reference engine and the tools. Node 22 or newer with pnpm for cli/ and the engine tests under web/. The tree holds its own prose to the text bar with its own CLI: ghostchars.json at the root names the surface and its pins, and npx -y ghostchars check from the root runs it.

The Mac app and the Chrome extension are built on this engine and available at ghostchars.com.

Issues

Bugs and questions about the engine or the CLI go to github.com/ghostchars/ghostchars/issues.

Licence

MIT, with the Unicode licence covering the generated character tables. See LICENSE. The npm package carries its own copy with the notices for what it bundles.

Reviews

No reviews yet

Be the first to review this server!