ZIP MCP server: create, inspect, verify, extract securely, modify without recompression. 13 tools
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
MCP server for ZIP archives β deterministic creation, inspection and listing without extracting, random-access entry reads, secure-by-default extraction, one-call verification, forward scanning of truncated streams, incremental modification without recompression, CRC-32 and raw-DEFLATE inflation β 13 tools on the zipnative engine (zero-dependency, ISO/IEC 21320-1 conformance validated in CI), for Claude Desktop, Cursor, ChatGPT and any MCP client.
zipnative-mcp exposes 13 tools to any MCP host:
| Tool | What it does | Read-only |
|---|---|---|
inspect_zip | ONE-call archive report: sizes, entry / file / directory counts, Zip64, comment, compressed vs uncompressed totals, per-method counts, encrypted / symlink / data-descriptor / Zip64 / cp437 / duplicate / unsafe-name counts, date range, a determinism verdict (the structural one: epoch timestamps + canonical order + UTF-8 flags) and every engine diagnostic. Opens eagerly: every entry's real extent is checked up front β overlapping entries, entries reaching into the central directory or past EOF, Zip64 spoofing β and refused with their ZIP_* code (a method / CRC / size divergence between central and local headers is caught by verify_zip and on read, not here). check: [β¦] + assert: {β¦} turn it into a CI gate. | β |
list_zip_entries | Paged central-directory inventory, nothing decompressed β every entry as a full row (sizes, CRC-32, method, timestamp, flags, Unix mode, symlink, Zip64, offsets, extra fields, the sanitized path an extraction would use, raw name bytes). filter by names / prefix / glob, offset + limit (200 default, 2000 max). | β |
read_zip_entry | ONE entry by name or index without extracting: decompressed content as base64 or UTF-8 text (CRC-verified), a byte range through the chunked stream, the raw compressed payload (mode: 'raw'), or a non-throwing integrity check (mode: 'verify'). | β |
verify_zip | Deep verification in one call β the engine's verifyZip report verbatim: structure, every entry's CRC-32 / size / local-header agreement, encrypted entries honestly skipped β while an entry whose method has no codec here (anything but 0 store / 8 deflate) is reported failed, not skipped. Never isError for an archive problem: branch on ok and error.code. | β |
extract_zip | Secure by default: zip-slip / device names, symlinks, duplicate paths, declared-size and ratio bombs, overlapping entries and central/local divergence refused with frozen ZIP_* codes; relaxations are explicit named inputs that skip, never emit. Inline files (includeData: false = dry run β it opens eagerly and refuses an overlapping, offset-into-CD or Zip64-spoofed archive before returning any plan) or streamed into the sandbox with resource links. | |
scan_zip_forward | Walk local headers in stream order with bounded memory β the only tool that works on a truncated download or a cut / unseekable stream that starts at a local header, and the only one whose result is NOT authoritative (trust: 'local-headers-only'). tolerateTruncation: true returns the partial inventory plus the error. It cannot skip an SFX / prepended prefix and refuses one (ZIP_SIGNATURE_MISMATCH): inspect_zip reports it (prependedData, ZIP_PREPENDED_DATA) and modify_zip mode: 'compact' drops it. | β |
sanitize_entry_paths | The engine's single traversal gate over a list of names: the safe /-relative form each maps to, or null with the rule that fired (traversal, absolute, drive, UNC, NUL, ADS, device name). No archive needed. | β |
create_zip | Write a ZIP from inline text / base64 / sandbox files (up to 100 000 entries β Zip64 auto-promotes past 65 535). Reproducible on one runtime by default (canonical order, DOS-epoch timestamps, UTF-8 names); compression.deterministic: true for identical bytes on every runtime β summary.deterministic is true ONLY then (a default call reports false with deflateTier: 'node-zlib'); store / deflate at archive or entry level; order: 'insertion' for EPUB / JAR; comments, Unix modes, extra fields; streamed sources; the worker pool (parallel, byte-identical); includeSha256 proofs in base64 and file mode. | |
modify_zip | add / replace / remove / rename / setComment without recompressing anything. mode: 'append' keeps the original bytes verbatim (removed content stays recoverable β data remanence, said loudly); mode: 'compact' rewrites canonically so it is truly gone. | |
compute_crc32 | The ZIP checksum (IEEE 802.3 CRC-32, the engine's slice-by-8) of text, base64 or a sandbox file streamed in 1 MiB chunks; seed chains chunks, expect compares. | β |
inflate_raw | Raw DEFLATE (RFC 1951) through the engine's resumable inflater with a mandatory maxOutput bound: exact bytesConsumed, trailing bytes as leftover. Feed it read_zip_entry mode: 'raw'. | |
describe_engine | Offline preflight: versions, deflate tiers, runtime codecs and workers, the engine's default limits, the operator ceilings, every server cap, sandbox / cache state, the 39 error codes and 11 diagnostic codes, the deliberately unexposed engine exports. network is always 'none'. | β |
draft_governance_issue | Draft a governance-compliant GitHub issue locally for a human to review and submit β never submits, no network, no GitHub write path. |
What every tool guarantees:
rejectTraversal, rejectSymlinks, onDuplicate, limits) that skips, never emits an unsafe path or materialises a link. Overlaps, central/local divergence and Zip64 spoofing have no opt-out at all.ZIPNATIVE_MCP_OUTPUT_DIR.create_zip emits canonical order, DOS-epoch timestamps and UTF-8 names unless you opt out, so the bytes are stable on one runtime; compression.deterministic: true pins the pure-TypeScript encoder for identical SHA-256 on every runtime and is the only setting under which summary.deterministic is true; inspect_zip.determinism is the separate structural verdict (epoch timestamps required); parallel is byte-identical.ZIP_* error codes, verbatim β the engine's 39-code vocabulary reaches you unchanged in _meta.error.code (with the entry name, the limit that fired, both CRCs, β¦), plus the wrapper's own 16 codes. Branch on the code, never on the message.verbosity: 'summary' and fields: [β¦]; produced archives are delivered once as an embedded resource block, never duplicated into structuredContent.All archive-producing tools support two output modes:
base64 (default) β the archive is returned once as an embedded resource content block (a data:application/zip;base64,β¦ URI); structuredContent carries { mode, sizeBytes, summary, diagnostics, diagnosticCounts }.file β the archive is streamed into a sandboxed directory configured via ZIPNATIVE_MCP_OUTPUT_DIR (β€ 4 GiB, never overwritten) and the result carries a resource_link. File I/O is disabled unless this variable is set; absolute paths, traversal, non-container extensions and NUL bytes are all rejected, and the real path of every file read and of every parent written must stay inside the sandbox (a planted symlink or junction is SECURITY_VIOLATION on both sides). The same sandbox serves zipPath / sourcePath inputs, so a create_zip β modify_zip β verify_zip β extract_zip chain never re-sends the bytes.Token-frugal reads. The read tools (inspect_zip, list_zip_entries, read_zip_entry, verify_zip, scan_zip_forward, sanitize_entry_paths, describe_engine) and extract_zip accept two optional inputs:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/zipnative-mcp-zip-creation-inspection-secure-extraction-verifica)<a href="https://allmcps.com/mcp/zipnative-mcp-zip-creation-inspection-secure-extraction-verifica"><img src="https://allmcps.com/api/badge/zipnative-mcp-zip-creation-inspection-secure-extraction-verifica?style=directory" alt="Zipnative MCP β ZIP creation, inspection, secure extraction & verification on AllMCPs" /></a>