MCPサーバー

zip-archive-create-extract-bomb-guard

io.github.theluckystrike/zip-archive-create-extract-bomb-guard
開発者向けツール セキュリティ 公開・接続可能 MCP 2026-07-28

このMCPでできること

Uploads, creates, inspects, extracts, and reads ZIP archives with protections against path traversal, symlinks, duplicate entries, and ZIP bombs.

license_activate
Activate license
Turn Pro on for this connection with key, an MCPL1.<payload>.<signature> issued at checkout for this server or the bundle. Data under your token stays; a wrong or expired key changes nothing. license_status confirms it.
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['key'], 'properties': {'key': {'type': 'string', 'description': 'License key from checkout, MCPL1.<payload>.<signature>'}}, 'additionalProperties': False}
license_status
License status
Report this endpoint's licence state for your token as JSON: the product, the tier free or pro, why it is not Pro, and the checkout URL. Call it to explain a free-tier refusal. No arguments, nothing changes.
読み取り専用 冪等
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
zip_add
Add files to a zip
Call this tool to add files to an existing archive under their own names, or under prefix. A name clash is refused unless replace. An archive holding unsafe entries is refused rather than rewritten.
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['path', 'paths'], 'properties': {'path': {'type': 'string', 'description': 'Path to the existing .zip file'}, 'level': {'type': 'integer', 'maximum': 9, 'minimum': 0, 'description': 'Deflate level 0 to 9 for the new entries, default 6'}, 'paths': {'type': 'array', 'items': {'type': 'string'}, 'minItems': 1, 'description': 'Files to add, each stored under its own file name. A directory contributes its tree under its own name'}, 'prefix': {'type': 'string', 'description': 'Put the new entries under this folder inside the archive, for example "invoices"'}, 'replace': {'type': 'boolean', 'description': 'Replace an entry whose name is already in the archive. Default false: a name clash is refused and nothing is changed'}, 'password': {'type': 'string', 'description': 'Not supported. Passing it is refused rather than ignored'}}, 'additionalProperties': False}
zip_bundle_month
Bundle a month of documents
Local (stdio) install only. On this hosted endpoint /mcp/invoice, /mcp/quotes, /mcp/expense-tracker, /mcp/docx and /mcp/resume return their documents as one-hour download links and keep no output folder to read, so there is nothing for this tool to bundle. Pack the files with zip_upload plus zip_create instead.
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'month': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}$', 'description': 'Month as YYYY-MM. Default: this month. Files are chosen by their modification date'}, 'dry_run': {'type': 'boolean', 'description': 'Report what would go in and write nothing'}, 'servers': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Only these sibling servers: invoice, quotes, expense-tracker, docx, resume. Default: all five'}, 'out_path': {'type': 'string', 'description': 'Name for the bundle. Default: the month, e.g. 2026-09'}, 'overwrite': {'type': 'boolean', 'description': 'Replace out_path if it exists. Default false'}}, 'additionalProperties': False}
zip_create
Create a zip archive
Call this tool to pack files uploaded with zip_upload into a new .zip and get a download link valid for one hour. Entry names are always relative, so the archive cannot write outside where it is unpacked.
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['out_path'], 'properties': {'dir': {'type': 'string', 'description': 'Not available on this hosted endpoint: there are no directories. Passing it is refused rather than ignored, so nobody believes a tree was packed'}, 'level': {'type': 'integer', 'maximum': 9, 'minimum': 0, 'description': 'Deflate level 0 to 9, default 6. 0 stores without compressing'}, 'paths': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Names of files uploaded with zip_upload, each packed under that name'}, 'exclude': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Drop entries matching one of these globs, applied after patterns'}, 'out_path': {'type': 'string', 'description': 'Name for the archive, e.g. reports. It comes back as a download link valid for one hour; a name already produced in this request is refused without overwrite'}, 'password': {'type': 'string', 'description': 'Not supported. Passing it is refused rather than ignored, so no one believes an archive is encrypted when it is not'}, 'patterns': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Only entries matching one of these globs (* and ? inside a segment, ** across segments; a pattern with no slash also matches the file name at any depth)'}, 'overwrite': {'type': 'boolean', 'description': 'Replace out_path if a file is already there. Default false: an existing file is never overwritten'}}, 'additionalProperties': False}
zip_delete_upload
Delete an uploaded file
Delete one uploaded file stored for your token. The register rows zip_history lists are kept.
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'maxLength': 70, 'minLength': 1}}, 'additionalProperties': False}
zip_extract
Extract a zip archive
Call this tool to unpack an archive; every entry comes back as its own download link valid for one hour. Traversal, absolute-path and symlink entries are refused, a size and ratio cap stops a zip bomb, and dry_run reports exactly what would be written.
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['path'], 'properties': {'path': {'type': 'string', 'description': 'Path to the .zip file'}, 'dry_run': {'type': 'boolean', 'description': 'Report what would be written, byte counts included, and write nothing'}, 'out_dir': {'type': 'string', 'description': 'Ignored on this hosted endpoint: there are no directories, and every extracted entry comes back as its own download link valid for one hour'}, 'patterns': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Only entries matching one of these globs (* and ? inside a segment, ** across segments)'}, 'max_ratio': {'type': 'number', 'minimum': 2, 'description': 'Refuse an entry whose uncompressed/compressed ratio is above this. Default 100'}, 'overwrite': {'type': 'boolean', 'description': 'Replace files that already exist in out_dir. Default false: the whole extraction is refused if any would be replaced'}, 'skip_unsafe': {'type': 'boolean', 'description': 'Skip the dangerous entries and extract the rest, naming what was skipped. Default false: one bad entry refuses the whole archive'}, 'max_total_mb': {'type': 'number', 'minimum': 1, 'description': 'Refuse if the selected entries declare more than this uncompressed. Default 1024'}}, 'additionalProperties': False}
zip_extract_text
Read one entry as text
Call this tool to read one text entry out of an archive without unpacking anything: give the entry name and the text comes back inline. Binary entries are refused by name rather than printed as noise.
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['path', 'entry'], 'properties': {'path': {'type': 'string', 'description': 'Path to the .zip file'}, 'entry': {'type': 'string', 'description': 'Exact entry name, as zip_list prints it. A glob is accepted when it matches exactly one entry'}, 'max_chars': {'type': 'integer', 'maximum': 200000, 'minimum': 100, 'description': 'Stop after this many characters (default 200000). The answer says when it was cut'}}, 'additionalProperties': False}
zip_files
List uploaded files
List the files stored for your token on this endpoint, with their sizes. These are the names every path argument here resolves against.
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
zip_history
Archives created
List the archives created for your token, newest first, with entry counts, sizes and names, plus how much of the free 20 a month is used. Each download link expires after an hour; the row keeps the name.
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'limit': {'type': 'integer', 'maximum': 200, 'minimum': 1, 'description': 'How many rows to show, newest first (default 20)'}}, 'additionalProperties': False}
zip_list
List a zip archive
Call this tool to list an archive's entries with sizes and ratios and flag what is dangerous: absolute paths, .., symlinks, encrypted entries, duplicate names and bombs. Read-only. Run it before zip_extract.
読み取り専用 冪等
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['path'], 'properties': {'path': {'type': 'string', 'description': 'Path to the .zip file. Read-only: the archive is never modified and nothing is extracted'}, 'limit': {'type': 'integer', 'maximum': 2000, 'minimum': 1, 'description': 'How many entries to print, largest first (default 50). The totals always cover every entry'}, 'patterns': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Only entries matching one of these globs'}, 'max_ratio': {'type': 'number', 'minimum': 2, 'description': 'Flag an entry whose uncompressed/compressed ratio is above this. Default 100'}}, 'additionalProperties': False}
zip_upload
Upload a file or an archive
Send a file to this hosted endpoint. There is no filesystem here, so instead of a path you upload the file once with zip_upload and then pass its name wherever a path is asked for: an archive to zip_list, zip_extract, zip_extract_text or zip_add, a plain file to zip_create. Give exactly one of content_base64 (the file's bytes, the only paste form an archive can take), content (text, for a text file to pack) or url. url: fetch a public file instead of pasting base64 (recommended above about 10 KB): the url is fetched here with a 10 second timeout, at most 3 redirects, public http(s) hosts only, and a 1 MB cap, and a name ending .zip is checked for the PK magic before anything is stored. Uploads are kept for your token between calls; zip_files lists them and zip_delete_upload removes one. The request body cap is 256 KB, so the practical ceiling on a paste is about 190 KB of file once it is base64 inside a JSON-RPC envelope.
入力スキーマ
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'url': {'type': 'string', 'description': "url: fetch a public file instead of pasting base64 (recommended above about 10 KB). Public http(s) only; private, link-local and this endpoint's own zone are refused"}, 'name': {'type': 'string', 'maxLength': 70, 'minLength': 1, 'description': 'Name to refer to this file by: 1-64 characters of letters, digits, underscore or dash, with an optional extension. No extension means .zip, e.g. "reports" or "notes.txt"'}, 'content': {'type': 'string', 'description': 'The file as text (a .txt, .csv, .md or source file to pack). Not accepted for a .zip'}, 'content_base64': {'type': 'string', 'description': "The file's bytes, base64-encoded. This is the only paste form an archive can be uploaded in"}}, 'additionalProperties': False}
変更
zip_history
2026年9月21日2:56
変更
zip_bundle_month
2026年9月21日2:56
変更
zip_extract_text
2026年9月21日2:56
変更
zip_add
2026年9月21日2:56
変更
zip_extract
2026年9月21日2:56
変更
zip_list
2026年9月21日2:56
変更
zip_create
2026年9月21日2:56
変更
license_activate
2026年9月21日2:56
変更
license_status
2026年9月21日2:56
追加
zip_history
2026年9月17日12:52
追加
zip_bundle_month
2026年9月17日12:52
追加
zip_extract_text
2026年9月17日12:52
追加
zip_add
2026年9月17日12:52
追加
zip_extract
2026年9月17日12:52
追加
zip_list
2026年9月17日12:52
追加
zip_create
2026年9月17日12:52
追加
zip_delete_upload
2026年9月17日12:52
追加
zip_files
2026年9月17日12:52
追加
zip_upload
2026年9月17日12:52
追加
license_activate
2026年9月17日12:52
追加
license_status
2026年9月17日12:52

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…