Mmcp.market

Zip Archive Create Extract Bomb Guard MCP server

by theluckystrike·io.github.theluckystrike/zip-archive-create-extract-bomb-guard·v0.22.0

Create, inspect and extract zip archives offline, with traversal, symlink and zip-bomb guards.

A88/100grade A
What users say
No reviews yet
Be the first
Safety scan
A88/100

full report

Adoption
Growing

0 stars

Reviews

Write one

Nobody has reviewed Zip Archive Create Extract Bomb Guard yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Zip Archive Create Extract Bomb Guard tools (12, 3 write)

write = sends, deletes, buys or posts
  • license_activateFree

    Turn Pro on for this connection with key, an MCPL1.<payload>.<signature> issued at checkout for this server or the bundle. Data under your token stays; a wrong or expired key changes nothing. license_status confirms it.

  • license_statusFree

    Report this endpoint's licence state for your token as JSON: the product, the tier free or pro, why it is not Pro, and the checkout URL. Call it to explain a free-tier refusal. No arguments, nothing changes.

  • zip_addFree

    Call this tool to add files to an existing archive under their own names, or under prefix. A name clash is refused unless replace. An archive holding unsafe entries is refused rather than rewritten.

  • zip_bundle_monthFree

    Local (stdio) install only. On this hosted endpoint /mcp/invoice, /mcp/quotes, /mcp/expense-tracker, /mcp/docx and /mcp/resume return their documents as one-hour download links and keep no output folder to read, so there is nothing for this tool to bundle. Pack the files with zip_upload plus zip_create instead.

  • zip_createwrite actionFree

    Call this tool to pack files uploaded with zip_upload into a new .zip and get a download link valid for one hour. Entry names are always relative, so the archive cannot write outside where it is unpacked.

  • zip_delete_uploadwrite actionFree

    Delete one uploaded file stored for your token. The register rows zip_history lists are kept.

  • zip_extractFree

    Call this tool to unpack an archive; every entry comes back as its own download link valid for one hour. Traversal, absolute-path and symlink entries are refused, a size and ratio cap stops a zip bomb, and dry_run reports exactly what would be written.

  • zip_extract_textFree

    Call this tool to read one text entry out of an archive without unpacking anything: give the entry name and the text comes back inline. Binary entries are refused by name rather than printed as noise.

  • zip_filesFree

    List the files stored for your token on this endpoint, with their sizes. These are the names every path argument here resolves against.

  • zip_historyFree

    List the archives created for your token, newest first, with entry counts, sizes and names, plus how much of the free 20 a month is used. Each download link expires after an hour; the row keeps the name.

  • zip_listFree

    Call this tool to list an archive's entries with sizes and ratios and flag what is dangerous: absolute paths, .., symlinks, encrypted entries, duplicate names and bombs. Read-only. Run it before zip_extract.

  • zip_uploadwrite actionFree

    Send a file to this hosted endpoint. There is no filesystem here, so instead of a path you upload the file once with zip_upload and then pass its name wherever a path is asked for: an archive to zip_list, zip_extract, zip_extract_text or zip_add, a plain file to zip_create. Give exactly one of content_base64 (the file's bytes, the only paste form an archive can take), content (text, for a text file to pack) or url. url: fetch a public file instead of pasting base64 (recommended above about 10 KB): the url is fetched here with a 10 second timeout, at most 3 redirects, public http(s) hosts only, and a 1 MB cap, and a name ending .zip is checked for the PK magic before anything is stored. Uploads are kept for your token between calls; zip_files lists them and zip_delete_upload removes one. The request body cap is 256 KB, so the practical ceiling on a paste is about 190 KB of file once it is base64 inside a JSON-RPC envelope.

Public scan report

scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it

no findings
  • Code scanpackage could not be scannedn/a
  • Live reliabilityremote reachable in 206ms20/20
  • Tool poisoning12 tool descriptions checked15/15
  • Auth qualityAPI key sent as a header8/15
  • Maintenancelast push 1 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 88/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Grade history

  • 2026-09-19restoreCAscore 88

Install directly

claude mcp add --transport http zip-archive-create-extract-bomb-guard https://mcp.zovo.one/mcp/zip
Add to Cursor

Zip Archive Create Extract Bomb Guard: common questions

Is Zip Archive Create Extract Bomb Guard MCP server safe?
Yes, by our scan: it is graded A (88/100). Read the Zip Archive Create Extract Bomb Guard safety report
How do I install Zip Archive Create Extract Bomb Guard?
It runs remotely at mcp.zovo.one. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does Zip Archive Create Extract Bomb Guard need an API key?
Yes. The registry entry asks for MCP_LICENSE_KEY, Authorization.
Is Zip Archive Create Extract Bomb Guard maintained?
The last commit was in the last day (2026-09-19). The latest release is v0.22.0.
Is Zip Archive Create Extract Bomb Guard up?
100% of our last 1 checks got an answer. We check remote servers about four times a day.
What can I use instead of Zip Archive Create Extract Bomb Guard?
Servers from other publishers that do the same job: Ziplark MCP server, Pullzip MCP server and Brightdata MCP server. Compare all Zip Archive Create Extract Bomb Guard alternatives.

Alternatives to Zip Archive Create Extract Bomb Guard

Same job from other publishers: the closest match first, then the best rated.

All Zip Archive Create Extract Bomb Guard alternatives →
  • Ziplark
    Archive server: extract & create ZIP, 7z, tar, gz/xz/zst; read RAR/RAR5 & ISO. AES-256, safe.
    B
  • Pullzip
    Inspect, search and safely extract zip/7z/rar/tar archives; repair garbled CJK file names.
    B
  • Brightdata
    Bright Data's Web MCP server enabling AI agents to search, extract & navigate the web
    B
  • Zenrows
    Zenrows MCP server — Fetch, Extract, Batch, and Browser Sessions for AI coding assistants
    A
  • shaft-mcp
    SHAFT browser automation, capture, and offline deterministic failure diagnosis
    A

More from theluckystrike