zip-archive-create-extract-bomb-guard
Create, inspect and extract zip archives offline, with traversal, symlink and zip-bomb guards.
사용해야 할까요
품질 및 안전성
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"zip-archive-create-extract-bomb-guard": {
"command": "uvx",
"args": [
"https://github.com/theluckystrike/mcp-servers/releases/download/v0.22.0/zip.mcpb"
]
}
}
}실행 가능한 패키지
0.22.0stdio원격 엔드포인트
https://mcp.zovo.one/mcp/zipstreamable-http할 수 있는 일
도구 목록
도구 (12)
🟢license_status
Report this endpoint's licence state for your token as JSON: the product, the tier free or pro, why it is not Pro, and the checkout URL. Call it to explain a free-tier refusal. No arguments, nothing changes.
입력 스키마
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪license_activate(key)
Turn Pro on for this connection with key, an MCPL1.<payload>.<signature> issued at checkout for this server or the bundle. Data under your token stays; a wrong or expired key changes nothing. license_status confirms it.
입력 스키마
{
"type": "object",
"properties": {
"key": {
"type": "string",
"description": "License key from checkout, MCPL1.<payload>.<signature>"
}
},
"required": [
"key"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🔴zip_upload(name, content, content_base64, url)
Send a file to this hosted endpoint. There is no filesystem here, so instead of a path you upload the file once with zip_upload and then pass its name wherever a path is asked for: an archive to zip_list, zip_extract, zip_extract_text or zip_add, a plain file to zip_create. Give exactly one of content_base64 (the file's bytes, the only paste form an archive can take), content (text, for a text file to pack) or url. url: fetch a public file instead of pasting base64 (recommended above about 10 KB): the url is fetched here with a 10 second timeout, at most 3 redirects, public http(s) hosts only, and a 1 MB cap, and a name ending .zip is checked for the PK magic before anything is stored. Uploads are kept for your token between calls; zip_files lists them and zip_delete_upload removes one. The request body cap is 256 KB, so the practical ceiling on a paste is about 190 KB of file once it is base64 inside a JSON-RPC envelope.
입력 스키마
{
"type": "object",
"properties": {
"name": {
"type": "string",
"minLength": 1,
"maxLength": 70,
"description": "Name to refer to this file by: 1-64 characters of letters, digits, underscore or dash, with an optional extension. No extension means .zip, e.g. \"reports\" or \"notes.txt\""
},
"content": {
"type": "string",
"description": "The file as text (a .txt, .csv, .md or source file to pack). Not accepted for a .zip"
},
"content_base64": {
"type": "string",
"description": "The file's bytes, base64-encoded. This is the only paste form an archive can be uploaded in"
},
"url": {
"type": "string",
"description": "url: fetch a public file instead of pasting base64 (recommended above about 10 KB). Public http(s) only; private, link-local and this endpoint's own zone are refused"
}
},
"required": [
"name"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢zip_files
List the files stored for your token on this endpoint, with their sizes. These are the names every path argument here resolves against.
입력 스키마
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}🔴zip_delete_upload(name)
Delete one uploaded file stored for your token. The register rows zip_history lists are kept.
입력 스키마
{
"type": "object",
"properties": {
"name": {
"type": "string",
"minLength": 1,
"maxLength": 70
}
},
"required": [
"name"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡zip_create(out_path, paths, dir, patterns, exclude, ...)
Call this tool to pack files uploaded with zip_upload into a new .zip and get a download link valid for one hour. Entry names are always relative, so the archive cannot write outside where it is unpacked.
입력 스키마
{
"type": "object",
"properties": {
"out_path": {
"type": "string",
"description": "Name for the archive, e.g. reports. It comes back as a download link valid for one hour; a name already produced in this request is refused without overwrite"
},
"paths": {
"type": "array",
"items": {
"type": "string"
},
"description": "Names of files uploaded with zip_upload, each packed under that name"
},
"dir": {
"type": "string",
"description": "Not available on this hosted endpoint: there are no directories. Passing it is refused rather than ignored, so nobody believes a tree was packed"
},
"patterns": {
"type": "array",
"items": {
"type": "string"
},
"description": "Only entries matching one of these globs (* and ? inside a segment, ** across segments; a pattern with no slash also matches the file name at any depth)"
},
"exclude": {
"type": "array",
"items": {
"type": "string"
},
"description": "Drop entries matching one of these globs, applied after patterns"
},
"level": {
"type": "integer",
"minimum": 0,
"maximum": 9,
"description": "Deflate level 0 to 9, default 6. 0 stores without compressing"
},
"overwrite": {
"type": "boolean",
"description": "Replace out_path if a file is already there. Default false: an existing file is never overwritten"
},
"password": {
"type": "string",
"description": "Not supported. Passing it is refused rather than ignored, so no one believes an archive is encrypted when it is not"
}
},
"required": [
"out_path"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢zip_list(path, limit, patterns, max_ratio)
Call this tool to list an archive's entries with sizes and ratios and flag what is dangerous: absolute paths, .., symlinks, encrypted entries, duplicate names and bombs. Read-only. Run it before zip_extract.
입력 스키마
{
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "Path to the .zip file. Read-only: the archive is never modified and nothing is extracted"
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 2000,
"description": "How many entries to print, largest first (default 50). The totals always cover every entry"
},
"patterns": {
"type": "array",
"items": {
"type": "string"
},
"description": "Only entries matching one of these globs"
},
"max_ratio": {
"type": "number",
"minimum": 2,
"description": "Flag an entry whose uncompressed/compressed ratio is above this. Default 100"
}
},
"required": [
"path"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢zip_extract(path, out_dir, patterns, dry_run, overwrite, ...)
Call this tool to unpack an archive; every entry comes back as its own download link valid for one hour. Traversal, absolute-path and symlink entries are refused, a size and ratio cap stops a zip bomb, and dry_run reports exactly what would be written.
입력 스키마
{
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "Path to the .zip file"
},
"out_dir": {
"type": "string",
"description": "Ignored on this hosted endpoint: there are no directories, and every extracted entry comes back as its own download link valid for one hour"
},
"patterns": {
"type": "array",
"items": {
"type": "string"
},
"description": "Only entries matching one of these globs (* and ? inside a segment, ** across segments)"
},
"dry_run": {
"type": "boolean",
"description": "Report what would be written, byte counts included, and write nothing"
},
"overwrite": {
"type": "boolean",
"description": "Replace files that already exist in out_dir. Default false: the whole extraction is refused if any would be replaced"
},
"skip_unsafe": {
"type": "boolean",
"description": "Skip the dangerous entries and extract the rest, naming what was skipped. Default false: one bad entry refuses the whole archive"
},
"max_total_mb": {
"type": "number",
"minimum": 1,
"description": "Refuse if the selected entries declare more than this uncompressed. Default 1024"
},
"max_ratio": {
"type": "number",
"minimum": 2,
"description": "Refuse an entry whose uncompressed/compressed ratio is above this. Default 100"
}
},
"required": [
"path"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡zip_add(path, paths, prefix, replace, level, ...)
Call this tool to add files to an existing archive under their own names, or under prefix. A name clash is refused unless replace. An archive holding unsafe entries is refused rather than rewritten.
입력 스키마
{
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "Path to the existing .zip file"
},
"paths": {
"type": "array",
"items": {
"type": "string"
},
"minItems": 1,
"description": "Files to add, each stored under its own file name. A directory contributes its tree under its own name"
},
"prefix": {
"type": "string",
"description": "Put the new entries under this folder inside the archive, for example \"invoices\""
},
"replace": {
"type": "boolean",
"description": "Replace an entry whose name is already in the archive. Default false: a name clash is refused and nothing is changed"
},
"level": {
"type": "integer",
"minimum": 0,
"maximum": 9,
"description": "Deflate level 0 to 9 for the new entries, default 6"
},
"password": {
"type": "string",
"description": "Not supported. Passing it is refused rather than ignored"
}
},
"required": [
"path",
"paths"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢zip_extract_text(path, entry, max_chars)
Call this tool to read one text entry out of an archive without unpacking anything: give the entry name and the text comes back inline. Binary entries are refused by name rather than printed as noise.
입력 스키마
{
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "Path to the .zip file"
},
"entry": {
"type": "string",
"description": "Exact entry name, as zip_list prints it. A glob is accepted when it matches exactly one entry"
},
"max_chars": {
"type": "integer",
"minimum": 100,
"maximum": 200000,
"description": "Stop after this many characters (default 200000). The answer says when it was cut"
}
},
"required": [
"path",
"entry"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡zip_bundle_month(month, out_path, servers, overwrite, dry_run)
Local (stdio) install only. On this hosted endpoint /mcp/invoice, /mcp/quotes, /mcp/expense-tracker, /mcp/docx and /mcp/resume return their documents as one-hour download links and keep no output folder to read, so there is nothing for this tool to bundle. Pack the files with zip_upload plus zip_create instead.
입력 스키마
{
"type": "object",
"properties": {
"month": {
"type": "string",
"pattern": "^\\d{4}-\\d{2}$",
"description": "Month as YYYY-MM. Default: this month. Files are chosen by their modification date"
},
"out_path": {
"type": "string",
"description": "Name for the bundle. Default: the month, e.g. 2026-09"
},
"servers": {
"type": "array",
"items": {
"type": "string"
},
"description": "Only these sibling servers: invoice, quotes, expense-tracker, docx, resume. Default: all five"
},
"overwrite": {
"type": "boolean",
"description": "Replace out_path if it exists. Default false"
},
"dry_run": {
"type": "boolean",
"description": "Report what would go in and write nothing"
}
},
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢zip_history(limit)
List the archives created for your token, newest first, with entry counts, sizes and names, plus how much of the free 20 a month is used. Each download link expires after an hour; the row keeps the name.
입력 스키마
{
"type": "object",
"properties": {
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 200,
"description": "How many rows to show, newest first (default 20)"
}
},
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}커뮤니티
증거