{"name":"io.github.Nizoka/zipnative-mcp","slug":"nizoka-zipnative-mcp","title":"zipnative MCP — ZIP creation, inspection, secure extraction & verification","description":"ZIP MCP server: create, inspect, verify, extract securely, modify without recompression. 13 tools","url":"https://mcp.market/server/nizoka-zipnative-mcp","rating":null,"grade":"B","score":83,"certified":false,"status":"active","category":"scraping","tags":["scraping"],"presence":{"score":27,"stars":0,"forks":0,"downloads_week":55,"last_push_at":"2026-09-10T22:32:41.000Z","license":"MIT"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/Nizoka/zipnative-mcp","website":"https://github.com/Nizoka/zipnative-mcp#readme","version":"1.0.0","remotes":[],"packages":[{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"zipnative-mcp","version":"1.0.0","runtimeHint":"npx","transport":{"type":"stdio"},"runtimeArguments":[{"value":"-y","type":"positional","valueHint":"skip-confirm"},{"value":"zipnative-mcp","type":"positional","valueHint":"package"}],"environmentVariables":[{"description":"Absolute path of the one sandbox directory: zipPath / sourcePath inputs are read from it and outputMode='file' / outputDir outputs are written under it (never overwritten; the real path of every file read and of every parent written must stay inside — a planted symlink or junction is SECURITY_VIOLATION). Unset: every tool works on base64 only (no file I/O beyond the opt-in cache).","format":"filepath","name":"ZIPNATIVE_MCP_OUTPUT_DIR"},{"description":"Opt-in content-addressed response cache directory (SHA-256 keyed, 1h TTL, 256 MiB LRU, plaintext at rest). Never caches zipPath / sourcePath inputs, file output, defaultDate='now', parallel, describe_engine or draft_governance_issue.","format":"filepath","name":"ZIPNATIVE_MCP_CACHE_DIR"},{"description":"Serve Streamable HTTP on this loopback port (POST /mcp) instead of stdio (MCP 2026-07-28, stateless, legacy fallback). Unauthenticated unless ZIPNATIVE_MCP_HTTP_TOKEN is set.","format":"number","name":"ZIPNATIVE_MCP_PORT"},{"description":"Opt-in bearer token for the HTTP transport (>= 16 chars, no whitespace; a weaker value refuses to start). When set, /mcp requires 'Authorization: Bearer <token>' or answers 401. Compared constant-time, never logged.","isSecret":true,"name":"ZIPNATIVE_MCP_HTTP_TOKEN"},{"description":"Operator ceiling for limits.maxEntryUncompressedSize and limits.maxTotalUncompressedSize in bytes (default 8589934592 = 8 GiB, the engine default). Integer >= 1024, read once at startup; an invalid value refuses to start. A per-call value above it is refused with LIMIT_CEILING_EXCEEDED.","format":"number","name":"ZIPNATIVE_MCP_MAX_UNCOMPRESSED_BYTES"},{"description":"Operator ceiling for limits.maxEntries and scan_zip_forward maxEntries (default 100000, the engine default; the scanner's default budget of 10000 is clamped to it, only an explicit value above it is refused). Integer >= 1, read once at startup; an invalid value refuses to start.","format":"number","name":"ZIPNATIVE_MCP_MAX_ENTRIES"},{"description":"Operator ceiling for create_zip parallel.workers (default 8; with no explicit workers the engine default max(1, min(cores - 1, 8)) applies, bounded by this ceiling; 0 disables worker threads and keeps compression on the calling thread). Integer >= 0, read once at startup; an invalid value refuses to start.","format":"number","name":"ZIPNATIVE_MCP_WORKERS"}]}],"tools":[{"name":"draft_issue_workflow","description":"Step-by-step workflow for drafting a GitHub issue with the draft_governance_issue tool and handing it to a human for review and submission.","write_action":false,"price_micros":0,"input_schema":null},{"name":"forensic_scan","description":"When and how to use scan_zip_forward, what its local-headers-only result can and cannot tell you, and how to reconcile it with the authoritative readers.","write_action":false,"price_micros":0,"input_schema":null},{"name":"governance_contract","description":"The non-negotiable AI-governance / Human-In-The-Loop contract for zipnative-mcp: the agent is a draftsman, the human is the only gate, zero runtime dependencies, no autonomous GitHub writes, no network.","write_action":false,"price_micros":0,"input_schema":null},{"name":"incremental_update","description":"How modify_zip edits without recompression, what append mode leaves behind (remanence, the 7-Zip stale-payload differential), and when to compact.","write_action":true,"price_micros":0,"input_schema":null},{"name":"reproducible_archive","description":"How to obtain the same bytes from repeated create_zip calls and across runtimes: pinned dates, canonical order, the deterministic encoder pin, and how to prove it.","write_action":false,"price_micros":0,"input_schema":null},{"name":"secure_extraction","description":"Recipe for taking in an archive from an untrusted source: verify, inspect with CI checks, dry-run the plan, extract with every guard on, and when (not) to relax a guard.","write_action":false,"price_micros":0,"input_schema":null},{"name":"verify_before_trust","description":"The minimal read-only sequence (verify_zip → inspect_zip checks → list → dry run) to run on any archive before extracting it.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":83,"grade":"B","scanned_at":"2026-09-20T00:26:48.271Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-20T00:26:48.285Z","components":{"code":{"score":25,"max":25,"notes":["76 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 9 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"zipnative-mcp","version":"1.0.0","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":3,"publishedAt":"2026-09-07T18:19:23.401Z","repositoryUrl":"git+https://github.com/Nizoka/zipnative-mcp.git","weeklyDownloads":55}],"repo":{"found":true,"owner":"Nizoka","repo":"zipnative-mcp","archived":false,"pushedAt":"2026-09-10T22:32:41Z","stars":0,"forks":0,"openIssues":9,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/129803615?v=4","ownerCreatedAt":"2023-04-03T22:56:40Z","license":"MIT"},"icon":{"url":"https://avatars.githubusercontent.com/u/129803615?v=4&s=128","source":"github"},"presence":{"stars":0,"forks":0,"downloadsWeek":55,"license":"MIT","lastPushAt":"2026-09-10T22:32:41.000Z","score":27}}}},"grade_history":[],"reviews":[]}