Agent♥︎Age
Catalog

io.github.theluckystrike/zip-archive-create-extract-bomb-guard

Official12 toolsLive

by theluckystrike · JavaScript

Create, inspect and extract zip archives offline, with traversal, symlink and zip-bomb guards.

io.github.theluckystrike/zip-archive-create-extract-bomb-guard (MCP)

This MCP server creates, inspects, and extracts ZIP archives offline. It provides traversal, symlink, and zip-bomb guards, and supports packing a folder using a glob (e.g., **/*.csv, excluding node_modules). It can read the README entry from an archive without unpacking, and report archive contents before extraction.

🛠️ Key Features

  • Create ZIP archives and unpack them locally
  • Inspect ZIP contents and extract with traversal and symlink protections
  • Guard against ZIP bombs (e.g., mismatched declared vs actual entry sizes)
  • Handle absolute paths, .., symlinks, and duplicate entry names
  • Read a README from an archive without unpacking

🚀 Use Cases

  • Bundle a month of invoices, quotes, and exports into one ZIP for an accountant
  • Check what is inside a ZIP before opening it
  • Inspect archive contents while staying offline

⚡ Developer Benefits

  • Runs on the developer’s machine: no upload, no account, no API key, no network call
  • Supports predictable packaging via glob patterns

⚠️ Limitations

  • The provided description focuses on offline ZIP handling and guard checks; it does not mention support for non-ZIP formats or remote retrieval.

Topics

claudecursorinvoicemcpmcp-servermodel-context-protocolspreadsheetaccountingai-toolsbookkeepingclaude-desktopfreelanceinvoicinglocal-firstmcp-serverspdfself-hostedtime-trackingvatproductivity