Ross ROSS = Recommend OSS · open-source software intelligence for agents

ptoomey3/evilarc

Create tar/zip archives that can exploit directory traversal vulnerabilities observed · 2026-08-28

github.com/ptoomey3/evilarc · Python observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 5666
  • days_rel: n/a
  • days_push: 1917
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1055 stars · 188 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

evilarc is a Python CLI tool that creates tar and zip archives containing files with directory traversal characters in their embedded paths. It is used to generate malicious archives that exploit vulnerable extraction libraries to write files to arbitrary locations on a target system.

Use cases

  • create zip files that exploit directory traversal on extraction
  • test whether an application is vulnerable to zip slip
  • generate malicious tar archives for penetration testing
  • demonstrate archive extraction vulnerabilities in Java or PHP libraries
  • craft archives that write files outside the extraction directory

When to choose

  • you are penetration testing or security researching archive extraction flaws
  • you need to test whether your own code safely handles malicious zip/tar paths
  • you want a simple Python tool to craft traversal archives

When to avoid

  • you need a general-purpose archive creation tool
  • you require a maintained project with an explicit license and active releases
  • you need protection against zip slip rather than a way to demonstrate it

Facets

cli-tool · maturity maintenance

security cli compression security penetration-testing developer-tools python cli cross-platform zip-slip directory-traversal archive-exploitation penetration-testing-tool

1 source

Member repositories

RepositoryRoleHealth v2
ptoomey3/evilarcmain32

For agents

markdown · JSON · MCP: product_card(name="ptoomey3/evilarc")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem