Ziplark MCP Server
io.github.zhitongblog/ziplark
Archive server: extract & create ZIP, 7z, tar, gz/xz/zst; read RAR/RAR5 & ISO with AES-256 encryption.
What is the Ziplark MCP server?
The Ziplark MCP server is a Model Context Protocol interface to a Rust-based archive engine that extracts and creates multiple archive formats (ZIP, 7z, tar, gz/xz/zst) with AES-256 encryption support, and reads RAR, RAR5, and ISO disc images. It provides read tools always available and optional write tools, with pagination for large archives to avoid flooding the LLM context.
Ziplark gives AI agents the ability to inspect, list, extract, and create archives across multiple formats. It handles complex scenarios like multi-volume RAR sets, encrypted headers, damaged archives, and preserves file metadata (permissions, timestamps, symlinks). The MCP server is lightweight, safe (with path traversal guards), and designed to work efficiently with large archives through pagination.
How to install Ziplark
Copy-paste configuration for popular MCP clients.
Tools & capabilities
Tools this server exposes to the agent.
ziplark_info— Get metadata about an archive fileziplark_list— List archive contents with pagination support; returns entry counts by directory for large archivesziplark_test— Verify archive integrityziplark_extract— Extract files from an archive (requires --allow-write flag)ziplark_create— Create a new archive in ZIP, 7z, or tar format with optional AES-256 encryption (requires --allow-write flag)
Use cases
- Inspect and extract files from downloaded RAR multi-volume sets or damaged archives
- List contents of large ISO disc images without loading the entire archive into memory
- Create encrypted ZIP or 7z backups with AES-256 protection
- Verify integrity of archives before extraction to identify missing volumes or corruption
- Extract specific files matching patterns from archives without decompressing everything
Ziplark MCP server FAQ
Ziplark is an MCP server that lets Claude and other AI agents work with archives. It can read ZIP, RAR, RAR5, 7z, tar, ISO and compressed variants; create ZIP, 7z, and tar archives with optional AES-256 encryption; and verify archive integrity.
Yes, Ziplark is free and open-source under the MIT license.
Download the MCP Bundle (ziplark-mcp-<version>.mcpb) from the releases page, or build from source. Register it in your MCP client config with the command path and optional --allow-write flag for extraction/creation.
No, Ziplark does not require any authentication or API keys.
The ziplark_list tool uses pagination (default 200 entries per page) and returns top-level directory summaries so large archives don't flood the LLM context.
Yes. It can create ZIP and 7z archives with AES-256 encryption, read encrypted RAR/RAR5 archives including those with encrypted headers, and read ZipCrypto-encrypted ZIPs.
README (reference)
Source of truth, from the repository.
<a href="https://ziplark.com"><img src="assets/banner.png" alt="Ziplark — every archive, one small app" width="640" /></a>
Free, fast, cross-platform archiver. Extracts ZIP, RAR (incl. RAR5), 7z, tar, ISO and the common compressed-tar variants; creates ZIP (with AES-256), 7z and tar archives. One small Rust engine, three ways to drive it: a desktop app, a CLI, and an MCP server.
Download · Website · Report a bug
</div>Install
# macOS — Homebrew
brew install --cask zhitongblog/tap/ziplark # desktop app
brew install zhitongblog/tap/ziplark # CLI + MCP (ziplark, ziplark-mcp)
# Windows — Scoop (CLI + MCP)
scoop bucket add ziplark https://github.com/zhitongblog/scoop-bucket
scoop install ziplark
Or grab a build for any platform from the releases page
(macOS .dmg, Windows .msi/.exe, Linux .deb/.AppImage, and CLI archives).
| Read / Extract | Create | Encryption | |
|---|---|---|---|
| ZIP | ✅ | ✅ | AES-256 (read ZipCrypto) |
| 7z | ✅ | ✅ | AES-256 |
| RAR / RAR5 (incl. multi-volume, SFX) | ✅ | — | reads encrypted, incl. encrypted headers |
| tar | ✅ | ✅ | — |
| tar.gz / .bz2 / .xz / .zst / .lz4 | ✅ | ✅ | — |
| gz / bz2 / xz / zst / lz4 (single stream) | ✅ | ✅ | — |
| ISO 9660 / Joliet (disc image) | ✅ | — | — |
RAR and ISO are extract-only: RAR's compression format is proprietary, and ISO is a disc-image container (we read ISO 9660 + Joliet with our own dependency-free parser). Everything else can be created as well as read.
RAR, properly
RAR is the format people arrive with — a download split into volumes, packed solid, sometimes one volume short — so it gets first-class treatment rather than a checkbox:
- A volume set is one archive.
movie.part03.rar, or the oldermovie.r01, opens the whole set: any file of the set resolves to the first volume, the parts are listed, and an entry that spans volumes comes out whole. Both naming schemes are handled, including the legacy one whose first volume ismovie.rarrather thanmovie.r01. - A missing volume is named. Ziplark says which file it needs next instead of failing with a generic error, and refuses to start writing rather than stopping half-way.
- Damage is survivable.
--keep-broken(in the app: "Extract what's readable") gets every intact file out of a damaged or incomplete archive and reports exactly which entries failed and which were written incomplete. Verifying reports every bad entry, so you know which file to re-download. - Verifying writes nothing. Integrity is checked by decompressing each entry and discarding the bytes — not, as a surprising number of tools do, by extracting the whole archive to a temporary directory.
- Metadata survives. Permissions (an executable stays executable), 100-nanosecond RAR5 timestamps, symlinks as symlinks, per-entry compressed sizes, solid/recovery-record/lock flags, and the archive comment.
- Encrypted headers work. An archive whose file names are encrypted
(
rar -hp) lists and extracts with a password like any other. - Self-extracting archives open. A
.exewith a RAR payload behind the stub is read as the archive it is. - Pick single files out of it.
--exact(and ticking rows in the app) extracts exactly the entries you name, rather than everything whose path happens to contain the text.
Ziplark drives libunrar's C API directly — see
formats/rar/raw.rs for why the
wrapper crates were not enough (multi-volume reads out of bounds there, a failed
entry throws away the archive handle, and the struct layouts do not match the
library's packed headers, which silently mis-reads every field past file_attr).
Why Ziplark
- Small. Size-optimized release profile (
opt-level=z, LTO, stripped,panic=abort). The desktop app uses the OS webview (no bundled Chromium). - Faithful. Permissions, modification times and symlinks survive the round trip, so an extracted binary still runs and an extracted tree still looks like the one you archived.
- Safe. Every extraction path is funneled through a single guard, and it
checks both ways out: the entry name (
../, absolute paths) and what is actually on disk, so a symlink — planted by an earlier entry of the same archive or sitting in the destination already — can't be used to redirect a write. No entry can escape the destination directory. - One engine. The GUI, CLI and MCP server are thin shells over
ziplark-core; whatever the CLI does, the app does identically.
Repository layout
crates/ziplark-core the archive engine (all formats, the security guard)
crates/ziplark-cli the `ziplark` command-line tool
crates/ziplark-mcp the MCP server (drive Ziplark from any LLM)
src-tauri the Tauri 2 desktop app (Rust commands)
ui the desktop frontend (vanilla HTML/CSS/JS)
1. Desktop app
# dev run (opens the window)
cargo tauri dev # or: cargo run -p ziplark-gui
# build a release .app + .dmg (macOS), .exe/.msi (Windows), AppImage/deb (Linux)
cargo tauri build
Drag an archive onto the window to inspect & extract it, or switch to Create to drag in files/folders, pick a format + compression level (and optional password), and save.
2. CLI — ziplark
cargo build --release -p ziplark-cli # binary at target/release/ziplark
ziplark list movie.rar
ziplark extract photos.zip -o ./out
ziplark create backup.tar.zst ./src ./README.md --level best
ziplark create secret.zip ./private --password hunter2
ziplark test download.7z
ziplark info mystery.bin
Every command takes --json for scripting. --include <PAT> filters entries on
extract; --level store|fast|default|best and --password apply to create.
Right-click (file-manager) integration
Add Extract here with Ziplark and Compress to ZIP with Ziplark to your OS file manager's context menu:
ziplark shell-integration install # enable
ziplark shell-integration status # show what's installed
ziplark shell-integration uninstall # remove
Per platform: macOS installs two Automator Quick Actions (Finder → right-click →
Quick Actions); Windows adds per-user (HKCU, no admin) shell verbs on archive
file types and on files/folders; Linux installs KDE service menus and Nautilus
scripts. Every entry just calls the ziplark CLI (extract-here / compress-zip),
so it follows wherever the binary lives. Both helper commands are also usable
directly:
ziplark extract-here movie.zip # → ./movie/ next to the archive
ziplark compress-zip ./photos ./a.txt # → ./Archive.zip next to them
3. MCP server — ziplark-mcp
A Model Context Protocol server (JSON-RPC over stdio). Read tools
(ziplark_info, ziplark_list, ziplark_test) are always available; the write tools
(ziplark_extract, ziplark_create) require --allow-write.
cargo build --release -p ziplark-mcp
Or install the MCP Bundle — ziplark-mcp-<version>.mcpb on the
releases page, one file
carrying the server for macOS, Windows and Linux. Ziplark is listed in the
official MCP registry
as io.github.zhitongblog/ziplark, so clients that read the registry can find it
on their own.
Register it with an MCP client:
{
"mcpServers": {
"ziplark": {
"command": "/path/to/target/release/ziplark-mcp",
"args": ["--allow-write"]
}
}
}
Big archives don't flood the context
ziplark_list is paged. It returns at most limit entries (default 200) starting
at offset, always alongside the archive's true total_entries, so listing a
200 000-entry disc image costs the same as listing a small ZIP:
{ "name": "ziplark_list", "arguments": { "path": "disc.iso", "limit": 200 } }
// -> { "total_entries": 203411, "returned": 200, "next_offset": 200,
// "truncated": true, "top_level": [ { "prefix": "usr/share", "entries": 88120 }, … ] }
When the result is truncated it also carries top_level — entry counts grouped by
directory, descending past a single root — so a client can see the shape of a huge
archive without paging through it. To go straight to what you want, filter instead of
paging: include takes path patterns, matched as globs when they contain * or ?
and as substrings otherwise, and applies before paging. dirs selects only files or
only directories.
{ "name": "ziplark_list",
"arguments": { "path": "disc.iso", "include": ["*/etc/*.conf"], "dirs": false } }
Building & testing
cargo test # engine round-trip + security tests
cargo build --release # all crates, size-optimized
License
MIT © 2026 doaipm — a doaipm project. See LICENSE.
Ziplark bundles third-party open-source components under their own licenses, acknowledged in THIRD_PARTY_LICENSES.md. Note in particular that RAR extraction uses the UnRAR library, which is under the UnRAR license (not MIT) and may not be used to re-create the RAR compression algorithm.
Related MCP servers

SoloMD
AI-native markdown editor with bundled MCP server for reading, searching, and managing notes with agent automation.

Unterm
AI-controllable terminal with MCP server: spawn panes, run commands, read screens, and orchestrate multi-agent workflows.

Chenji Affect
Affect analysis, 3D avatar params, empathy hints and somatic emotion decode.

AI-powered image generation with Google Gemini models—Flash speed meets 4K quality

Which domain officially belongs to which software product or company. Ownership only, never safety.
View repository →Fill and sign PDFs in the browser, send for signature, and track who has signed.