
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
envsync-le-mcp
Advanced tools
Compare dotenv files and report which keys are missing or extra, by name only.
An MCP server that compares dotenv files and reports which keys are missing from which — names only, never values — the comparison engine behind the EnvSync-LE editor extension, exposed as a tool an agent can call.
No dependencies, no network calls, no filesystem access. Content goes in, structured results come out.
Point any MCP host at npx envsync-le-mcp.
Claude Code
claude mcp add envsync-le -- npx -y envsync-le-mcp
Anything with a JSON config — Cursor, Windsurf, Claude Desktop:
{
"mcpServers": {
"envsync-le": {
"command": "npx",
"args": ["-y", "envsync-le-mcp"]
}
}
}
VS Code needs nothing here. Install the extension instead — it carries this server and registers it for you: VS Code Marketplace · Open VSX
No Node? The same compare_env_files tool ships in a static Rust
binary: cargo install envsync-le, then envsync-le mcp
(crates.io). The two servers answer
identically — one fixture corpus runs against both and CI fails if they
diverge. The binary additionally offers envsync_le_check, which
discovers the dotenv files in a directory; this server reads no files,
which is what lets an agent call it anywhere.
Prefer a global install to npx on every launch:
npm install -g envsync-le-mcp
{
"mcpServers": {
"envsync-le": { "command": "envsync-le-mcp" }
}
}
No environment variables, no API key, no configuration of its own. To check it before wiring it into anything:
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | npx -y envsync-le-mcp
If that prints the tool name, the server works.
compare_env_files| argument | type | |
|---|---|---|
files | object[] | required. The dotenv files to compare, each { "path": ".env", "content": "…" }. |
mode | string | auto (the default) compares every file against the union of all keys, so nothing can be extra; template compares every file against one. |
templatePath | string | Which file is the template. Required when mode is template. |
caseSensitive | boolean | Compare key names case-sensitively. Default true. |
maxResults | number | Default 500, ceiling 5000. |
Returns the overall status — in-sync, missing-keys, extra-keys or
parse-error — each file with its key count, and the keys missing from each
file (and, in template mode, extra in it) by name only. A value never
leaves the tool. maxResults caps the mismatches returned, and
meta.truncated says whether any were dropped.
{
"ok": true,
"data": {
"status": "missing-keys",
"files": [
{"path": ".env", "type": "base", "keyCount": 2},
{"path": ".env.example", "type": "example", "keyCount": 1}
],
"missingKeys": [
{
"filepath": ".env.example",
"keys": ["DB_HOST"],
"reference": ".env"
}
],
"extraKeys": []
},
"diagnostics": [],
"meta": {
"tool": "compare_env_files",
"count": 1,
"truncated": false
}
}
Extraction is heuristic, and what it deliberately does not match is documented as carefully as what it does — see the extension README.
io.github.nolindnaidoo/envsync-le —
registry.modelcontextprotocol.io
One tool each, same shape: content in, structured data out, no network and no
filesystem. Every one is on npm as <name>-mcp and in the MCP registry as
io.github.nolindnaidoo/<name>.
| Package | Tool | Extracts |
|---|---|---|
urls-le-mcp | extract_urls | URLs, with protocol and position |
colors-le-mcp | extract_colors | colors from stylesheets and code |
dates-le-mcp | extract_dates | dates and timestamps |
paths-le-mcp | extract_paths | file and directory paths |
numbers-le-mcp | extract_numbers | numeric values |
string-le-mcp | extract_strings | string values |
regex-le-mcp | extract_patterns | regexes, with a ReDoS verdict |
secrets-le-mcp | detect_secrets | credentials, masked — never the value |
scrape-le-mcp | analyze_robots_txt | whether a path may be crawled |
Every tool in the family, one page: letools.dev
Nolin Naidoo — Chief Engineer, AI/ML & Platform Architecture. nolindnaidoo.com · GitHub · LinkedIn
Twelve Rust tools built the same way: small, single-purpose, and driven by a machine rather than a person. pixelcoords and pixelactions make up one loop — pixelcoords answers where, pixelactions acts there. The ten LE crates are the terminal half of the extensions they sit in: the same detection, held to the extension's own corpus, and an exit code instead of a results editor.
| pixelcoords | Freeze your screen, mark regions, get pixel-exact coordinates and crops | site · crates.io · docs.rs |
| pixelactions | Consume human-verified coordinates, perform the interaction, confirm it landed | site · crates.io · docs.rs |
| paths-le | Find every path in a codebase and report whether it still points at anything | crates.io |
| secrets-le | Find hardcoded credentials, and never print one | crates.io |
| urls-le | Extract every URL from a codebase, with its protocol and exact position | crates.io |
| regex-le | Find every regex in a codebase and report which can be driven into catastrophic backtracking | crates.io |
| string-le | Get every string in a codebase out where a person can read them | crates.io |
| numbers-le | Find every hardcoded number in a codebase so a person can check them | crates.io |
| envsync-le | Compare the dotenv files in a tree and say which keys are missing from which | crates.io |
| colors-le | Find every colour in a codebase, and say which are not in your palette | crates.io |
| dates-le | Extract every date and timestamp, and the exact instant each one resolves to | crates.io |
| scrape-le | Check whether a page is scrapeable before the scraper is written | crates.io |
MIT © Nolin Naidoo
FAQs
Compare dotenv files and report which keys are missing or extra, by name only.
The npm package envsync-le-mcp receives a total of 460 weekly downloads. As such, envsync-le-mcp popularity was classified as not popular.
We found that envsync-le-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.