https://mcp.zovo.one/mcp/zip ↗
Create, inspect and extract zip archives offline, with traversal, symlink and zip-bomb guards.
io.github.theluckystrike/zip-archive-create-extract-bomb-guard is a remote MCP server published at mcp.zovo.one. It has been probed 10 times since 9/12/2026. It answered in 10 of them (100.0%), a near-uninterrupted record. Median response time is 50 ms, placing it among the faster endpoints. It offers a narrow, focused set of 12 tools. On the protocol side it still runs 2025-11-25 and has not moved to the newer spec.
Can an LLM agent pick the right tool here — names, descriptions and parameter clarity are assessed.
| Run | Era | Modern | ms | Legacy | ms | Versions |
|---|---|---|---|---|---|---|
| 2026-09-13 10:45:14 | Legacy | 401 | 130 | 200 | 502 | 2025-11-25 |
| 2026-09-13 08:43:04 | Auth-gated | 401 | 38 | 429 | 49 | — |
| 2026-09-13 06:40:42 | Auth-gated | 401 | 119 | 429 | 133 | — |
| 2026-09-13 04:35:29 | Legacy | 401 | 44 | 200 | 59 | 2025-11-25 |
| 2026-09-13 01:33:33 | Legacy | 401 | 34 | 200 | 53 | 2025-11-25 |
| 2026-09-12 23:31:36 | Legacy | 401 | 39 | 200 | 108 | 2025-11-25 |
| 2026-09-12 21:29:15 | Legacy | 401 | 41 | 200 | 50 | 2025-11-25 |
| 2026-09-12 19:27:29 | Legacy | 401 | 39 | 200 | 56 | 2025-11-25 |
| 2026-09-12 17:24:09 | Legacy | 401 | 42 | 200 | 55 | 2025-11-25 |
| 2026-09-12 15:21:42 | Auth-gated | 401 | 40 | 429 | 46 | — |
tools/list structure, inputSchema validity, and a functional smoke test — the components of the 0-100 score.
Tools the server advertised in the latest measurement — measured, not catalog-claimed.
license_statusReport this endpoint's licence state for your token as JSON: the product, the tier free or pro, why it is not Pro, and the checkout URL. Call it to explain a free-tier refusal. No arguments, nothing changes.
license_activateTurn Pro on for this connection with key, an MCPL1.<payload>.<signature> issued at checkout for this server or the bundle. Data under your token stays; a wrong or expired key changes nothing. license_status confirms it.
keystringrequiredzip_uploadSend a file to this hosted endpoint. There is no filesystem here, so instead of a path you upload the file once with zip_upload and then pass its name wherever a path is asked for: an archive to zip_list, zip_extract, zip_extract_text or zip_add, a plain file to zip_create. Give exactly one of content_base64 (the file's bytes, the only paste form an archive can take), content (text, for a text file to pack) or url. url: fetch a public file instead of pasting base64 (recommended above about 10 KB): the url is fetched here with a 10 second timeout, at most 3 redirects, public http(s) hosts only, and a 1 MB cap, and a name ending .zip is checked for the PK magic before anything is stored. Uploads are kept for your token between calls; zip_files lists them and zip_delete_upload removes one. Th
namestringrequiredcontentstringcontent_base64stringurlstringzip_filesList the files stored for your token on this endpoint, with their sizes. These are the names every path argument here resolves against.
zip_delete_uploadDelete one uploaded file stored for your token. The register rows zip_history lists are kept.
namestringrequiredzip_createCall this tool to pack files uploaded with zip_upload into a new .zip and get a download link valid for one hour. Entry names are always relative, so the archive cannot write outside where it is unpacked.
out_pathstringrequiredpathsarraydirstringpatternsarrayexcludearraylevelintegeroverwritebooleanpasswordstringzip_listCall this tool to list an archive's entries with sizes and ratios and flag what is dangerous: absolute paths, .., symlinks, encrypted entries, duplicate names and bombs. Read-only. Run it before zip_extract.
pathstringrequiredlimitintegerpatternsarraymax_rationumberzip_extractCall this tool to unpack an archive; every entry comes back as its own download link valid for one hour. Traversal, absolute-path and symlink entries are refused, a size and ratio cap stops a zip bomb, and dry_run reports exactly what would be written.
pathstringrequiredout_dirstringpatternsarraydry_runbooleanoverwritebooleanskip_unsafebooleanmax_total_mbnumbermax_rationumberzip_addCall this tool to add files to an existing archive under their own names, or under prefix. A name clash is refused unless replace. An archive holding unsafe entries is refused rather than rewritten.
pathstringrequiredpathsarrayrequiredprefixstringreplacebooleanlevelintegerpasswordstringzip_extract_textCall this tool to read one text entry out of an archive without unpacking anything: give the entry name and the text comes back inline. Binary entries are refused by name rather than printed as noise.
pathstringrequiredentrystringrequiredmax_charsintegerzip_bundle_monthLocal (stdio) install only. On this hosted endpoint /mcp/invoice, /mcp/quotes, /mcp/expense-tracker, /mcp/docx and /mcp/resume return their documents as one-hour download links and keep no output folder to read, so there is nothing for this tool to bundle. Pack the files with zip_upload plus zip_create instead.
monthstringout_pathstringserversarrayoverwritebooleandry_runbooleanzip_historyList the archives created for your token, newest first, with entry counts, sizes and names, plus how much of the free 20 a month is used. Each download link expires after an hour; the row keeps the name.
limitintegerEach block is one measurement round. Green: working response. Amber: responded but the server was returning errors (5xx). Red: no response at all.
Each cell is one probe run. Faded cells are incomplete probes — one leg did not answer, so the era is inconclusive.
The two probe legs separately: modern server/discover and legacy initialize.
Derived by comparing consecutive probes — changes in era, protocol version, build and reachability.
Add this badge to your README — it updates automatically as measurements change.
[](https://mcpmetrics.io/servers/io-github-theluckystrike-zip-archive-create-extract-bomb-guard)<a href="https://mcpmetrics.io/servers/io-github-theluckystrike-zip-archive-create-extract-bomb-guard"><img src="https://mcpmetrics.io/badge/io.github.theluckystrike/zip-archive-create-extract-bomb-guard/era.svg" alt="mcpmetrics"></a>You are seeing the last 7 days. Sign up for the full history. Which check failed and why is in the dashboard.
Sign up free to seeThe catalog entries whose name and description are closest to this one, found with the same index the search box uses.
Merge, split, extract, rotate, reorder and stamp PDF pages from your AI chat, all offline.
QR codes and barcodes offline: WiFi, vCards, SEPA payment codes, Code 128, EAN-13, SVG or PNG.
Create real Word .docx files from your AI chat: proposals, quotes, contracts, statements of work.
Open, inspect, filter, edit and convert xlsx and csv files from your AI chat. Processing is local.
Create PDF invoices from your AI chat: clients, numbering, VAT, overdue reports. All data is local.
Thailand Leceipt e-Tax: AI agents create, poll and download e-Tax Invoices, stateless BYO.
Comments
Sign in to write a comment
No comments yet. Be the first.