zip-archive-create-extract-bomb-guard

Create, inspect and extract zip archives offline, with traversal, symlink and zip-bomb guards.

Sollte ich dies verwenden

Qualität und Sicherheit

A
Qualität der Beschreibung
100%
Vollständigkeit des Schemas
85%
Qualität der Benennung
80%
Risiko der Vergiftung
100%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~2,748Tokens (Tool-Definitionen)
~1.8 KBTypische Antwortgröße
Erhebliche Auswirkung auf die Aufmerksamkeit (2.15% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "zip-archive-create-extract-bomb-guard": {
      "command": "uvx",
      "args": [
        "https://github.com/theluckystrike/mcp-servers/releases/download/v0.22.0/zip.mcpb"
      ]
    }
  }
}

Ausführbare Pakete

mcpbhttps://github.com/theluckystrike/mcp-servers/releases/download/v0.22.0/zip.mcpb0.22.0stdio

Remote-Endpunkte

https://mcp.zovo.one/mcp/zipstreamable-http

Was es kann

Tool-Inventar

Tools (12)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
🟢license_status

Report this endpoint's licence state for your token as JSON: the product, the tier free or pro, why it is not Pro, and the checkout URL. Call it to explain a free-tier refusal. No arguments, nothing changes.

Eingabe-Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪license_activate(key)

Turn Pro on for this connection with key, an MCPL1.<payload>.<signature> issued at checkout for this server or the bundle. Data under your token stays; a wrong or expired key changes nothing. license_status confirms it.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "key": {
      "type": "string",
      "description": "License key from checkout, MCPL1.<payload>.<signature>"
    }
  },
  "required": [
    "key"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🔴zip_upload(name, content, content_base64, url)

Send a file to this hosted endpoint. There is no filesystem here, so instead of a path you upload the file once with zip_upload and then pass its name wherever a path is asked for: an archive to zip_list, zip_extract, zip_extract_text or zip_add, a plain file to zip_create. Give exactly one of content_base64 (the file's bytes, the only paste form an archive can take), content (text, for a text file to pack) or url. url: fetch a public file instead of pasting base64 (recommended above about 10 KB): the url is fetched here with a 10 second timeout, at most 3 redirects, public http(s) hosts only, and a 1 MB cap, and a name ending .zip is checked for the PK magic before anything is stored. Uploads are kept for your token between calls; zip_files lists them and zip_delete_upload removes one. The request body cap is 256 KB, so the practical ceiling on a paste is about 190 KB of file once it is base64 inside a JSON-RPC envelope.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 70,
      "description": "Name to refer to this file by: 1-64 characters of letters, digits, underscore or dash, with an optional extension. No extension means .zip, e.g. \"reports\" or \"notes.txt\""
    },
    "content": {
      "type": "string",
      "description": "The file as text (a .txt, .csv, .md or source file to pack). Not accepted for a .zip"
    },
    "content_base64": {
      "type": "string",
      "description": "The file's bytes, base64-encoded. This is the only paste form an archive can be uploaded in"
    },
    "url": {
      "type": "string",
      "description": "url: fetch a public file instead of pasting base64 (recommended above about 10 KB). Public http(s) only; private, link-local and this endpoint's own zone are refused"
    }
  },
  "required": [
    "name"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢zip_files

List the files stored for your token on this endpoint, with their sizes. These are the names every path argument here resolves against.

Eingabe-Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🔴zip_delete_upload(name)

Delete one uploaded file stored for your token. The register rows zip_history lists are kept.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 70
    }
  },
  "required": [
    "name"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡zip_create(out_path, paths, dir, patterns, exclude, ...)

Call this tool to pack files uploaded with zip_upload into a new .zip and get a download link valid for one hour. Entry names are always relative, so the archive cannot write outside where it is unpacked.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "out_path": {
      "type": "string",
      "description": "Name for the archive, e.g. reports. It comes back as a download link valid for one hour; a name already produced in this request is refused without overwrite"
    },
    "paths": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Names of files uploaded with zip_upload, each packed under that name"
    },
    "dir": {
      "type": "string",
      "description": "Not available on this hosted endpoint: there are no directories. Passing it is refused rather than ignored, so nobody believes a tree was packed"
    },
    "patterns": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Only entries matching one of these globs (* and ? inside a segment, ** across segments; a pattern with no slash also matches the file name at any depth)"
    },
    "exclude": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Drop entries matching one of these globs, applied after patterns"
    },
    "level": {
      "type": "integer",
      "minimum": 0,
      "maximum": 9,
      "description": "Deflate level 0 to 9, default 6. 0 stores without compressing"
    },
    "overwrite": {
      "type": "boolean",
      "description": "Replace out_path if a file is already there. Default false: an existing file is never overwritten"
    },
    "password": {
      "type": "string",
      "description": "Not supported. Passing it is refused rather than ignored, so no one believes an archive is encrypted when it is not"
    }
  },
  "required": [
    "out_path"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢zip_list(path, limit, patterns, max_ratio)

Call this tool to list an archive's entries with sizes and ratios and flag what is dangerous: absolute paths, .., symlinks, encrypted entries, duplicate names and bombs. Read-only. Run it before zip_extract.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "path": {
      "type": "string",
      "description": "Path to the .zip file. Read-only: the archive is never modified and nothing is extracted"
    },
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 2000,
      "description": "How many entries to print, largest first (default 50). The totals always cover every entry"
    },
    "patterns": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Only entries matching one of these globs"
    },
    "max_ratio": {
      "type": "number",
      "minimum": 2,
      "description": "Flag an entry whose uncompressed/compressed ratio is above this. Default 100"
    }
  },
  "required": [
    "path"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢zip_extract(path, out_dir, patterns, dry_run, overwrite, ...)

Call this tool to unpack an archive; every entry comes back as its own download link valid for one hour. Traversal, absolute-path and symlink entries are refused, a size and ratio cap stops a zip bomb, and dry_run reports exactly what would be written.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "path": {
      "type": "string",
      "description": "Path to the .zip file"
    },
    "out_dir": {
      "type": "string",
      "description": "Ignored on this hosted endpoint: there are no directories, and every extracted entry comes back as its own download link valid for one hour"
    },
    "patterns": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Only entries matching one of these globs (* and ? inside a segment, ** across segments)"
    },
    "dry_run": {
      "type": "boolean",
      "description": "Report what would be written, byte counts included, and write nothing"
    },
    "overwrite": {
      "type": "boolean",
      "description": "Replace files that already exist in out_dir. Default false: the whole extraction is refused if any would be replaced"
    },
    "skip_unsafe": {
      "type": "boolean",
      "description": "Skip the dangerous entries and extract the rest, naming what was skipped. Default false: one bad entry refuses the whole archive"
    },
    "max_total_mb": {
      "type": "number",
      "minimum": 1,
      "description": "Refuse if the selected entries declare more than this uncompressed. Default 1024"
    },
    "max_ratio": {
      "type": "number",
      "minimum": 2,
      "description": "Refuse an entry whose uncompressed/compressed ratio is above this. Default 100"
    }
  },
  "required": [
    "path"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡zip_add(path, paths, prefix, replace, level, ...)

Call this tool to add files to an existing archive under their own names, or under prefix. A name clash is refused unless replace. An archive holding unsafe entries is refused rather than rewritten.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "path": {
      "type": "string",
      "description": "Path to the existing .zip file"
    },
    "paths": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "minItems": 1,
      "description": "Files to add, each stored under its own file name. A directory contributes its tree under its own name"
    },
    "prefix": {
      "type": "string",
      "description": "Put the new entries under this folder inside the archive, for example \"invoices\""
    },
    "replace": {
      "type": "boolean",
      "description": "Replace an entry whose name is already in the archive. Default false: a name clash is refused and nothing is changed"
    },
    "level": {
      "type": "integer",
      "minimum": 0,
      "maximum": 9,
      "description": "Deflate level 0 to 9 for the new entries, default 6"
    },
    "password": {
      "type": "string",
      "description": "Not supported. Passing it is refused rather than ignored"
    }
  },
  "required": [
    "path",
    "paths"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢zip_extract_text(path, entry, max_chars)

Call this tool to read one text entry out of an archive without unpacking anything: give the entry name and the text comes back inline. Binary entries are refused by name rather than printed as noise.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "path": {
      "type": "string",
      "description": "Path to the .zip file"
    },
    "entry": {
      "type": "string",
      "description": "Exact entry name, as zip_list prints it. A glob is accepted when it matches exactly one entry"
    },
    "max_chars": {
      "type": "integer",
      "minimum": 100,
      "maximum": 200000,
      "description": "Stop after this many characters (default 200000). The answer says when it was cut"
    }
  },
  "required": [
    "path",
    "entry"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡zip_bundle_month(month, out_path, servers, overwrite, dry_run)

Local (stdio) install only. On this hosted endpoint /mcp/invoice, /mcp/quotes, /mcp/expense-tracker, /mcp/docx and /mcp/resume return their documents as one-hour download links and keep no output folder to read, so there is nothing for this tool to bundle. Pack the files with zip_upload plus zip_create instead.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "month": {
      "type": "string",
      "pattern": "^\\d{4}-\\d{2}$",
      "description": "Month as YYYY-MM. Default: this month. Files are chosen by their modification date"
    },
    "out_path": {
      "type": "string",
      "description": "Name for the bundle. Default: the month, e.g. 2026-09"
    },
    "servers": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Only these sibling servers: invoice, quotes, expense-tracker, docx, resume. Default: all five"
    },
    "overwrite": {
      "type": "boolean",
      "description": "Replace out_path if it exists. Default false"
    },
    "dry_run": {
      "type": "boolean",
      "description": "Report what would go in and write nothing"
    }
  },
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢zip_history(limit)

List the archives created for your token, newest first, with entry counts, sizes and names, plus how much of the free 20 a month is used. Each download link expires after an hour; the row keeps the name.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "limit": {
      "type": "integer",
      "minimum": 1,
      "maximum": 200,
      "description": "How many rows to show, newest first (default 20)"
    }
  },
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet12 Tools
verifiziertVersion nicht aufgezeichnet12 Tools
verifiziertVersion nicht aufgezeichnet12 Tools