MCP serverio.github.theluckystrike/zip-archive-create-extract-bomb-guard
Create, inspect and extract zip archives offline, with traversal, symlink and zip-bomb guards.
Overview
Score?
UNRATED 0.780
of what a free look can see, on 24 looks
Looks
32
last 1 hr ago
Tools
12
changed 24 days ago
More info
URL
mcp.zovo.one/mcp/zip
streamable-http
Says it is
mcp-zip 0.22.0
protocol 2025-06-18
In the record since
29 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.780 · highest on record 0.8561
Toolsfrom sha256:92715ca0a1…f20c3e · +0 −0 24 days ago
| Tool | Schema |
|---|---|
| license_activate Turn Pro on for this connection with key, an MCPL1.<payload>.<signature> issued at checkout for this server or the bundle. Data under your token stays; a wrong or expired key chang |
input · no output |
| license_status Report this endpoint's licence state for your token as JSON: the product, the tier free or pro, why it is not Pro, and the checkout URL. Call it to explain a free-tier refusal. No |
input · no output |
| zip_add Call this tool to add files to an existing archive under their own names, or under prefix. A name clash is refused unless replace. An archive holding unsafe entries is refused rath |
input · no output |
| zip_bundle_month Local (stdio) install only. On this hosted endpoint /mcp/invoice, /mcp/quotes, /mcp/expense-tracker, /mcp/docx and /mcp/resume return their documents as one-hour download links and |
input · no output |
| zip_create Call this tool to pack files uploaded with zip_upload into a new .zip and get a download link valid for one hour. Entry names are always relative, so the archive cannot write outsi |
input · no output |
| zip_delete_upload Delete one uploaded file stored for your token. The register rows zip_history lists are kept. |
input · no output |
| zip_extract Call this tool to unpack an archive; every entry comes back as its own download link valid for one hour. Traversal, absolute-path and symlink entries are refused, a size and ratio |
input · no output |
| zip_extract_text Call this tool to read one text entry out of an archive without unpacking anything: give the entry name and the text comes back inline. Binary entries are refused by name rather th |
input · no output |
| zip_files List the files stored for your token on this endpoint, with their sizes. These are the names every path argument here resolves against. |
input · no output |
| zip_history List the archives created for your token, newest first, with entry counts, sizes and names, plus how much of the free 20 a month is used. Each download link expires after an hour; |
input · no output |
| zip_list Call this tool to list an archive's entries with sizes and ratios and flag what is dangerous: absolute paths, .., symlinks, encrypted entries, duplicate names and bombs. Read-only. |
input · no output |
| zip_upload Send a file to this hosted endpoint. There is no filesystem here, so instead of a path you upload the file once with zip_upload and then pass its name wherever a path is asked for: |
input · no output |
Verify it yourself
npx teppi-check https://mcp.zovo.one/mcp/zipcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1RE55SYCT2Z2ZHFT1490V68