r/shortcuts • • 3d ago

Request (Mac) macOS Quick Action Shortcut for Encrypted ZIP (Passing Password + Folder Path to Shell Script without sandbox errors)

Hi everyone,

I'm trying to build a macOS Quick Action (Schnellaktion) using the built-in Shortcuts app to compress a folder into an encrypted ZIP file via a right-click.

My Goal:

  1. Right-click any folder in Finder (mostly in the Downloads folder).
  2. Select the Quick Action.
  3. A pop-up asks for a password (secure input).
  4. The folder gets zipped and encrypted using zip -er and the output .zip file is created directly in the same parent directory next to the original folder.
2 Upvotes

3 comments sorted by

1

u/EquivalentSky3094 2d ago

The zip -er route cannot work from a Quick Action, and it is not a sandbox problem. From zip's own man page, -e takes a password "entered on the terminal in response to a prompt", and "if standard error is not a tty, zip will exit with an error". Run Shell Script inside Shortcuts has no tty, so zip bails before it ever looks at your folder.

The only way to hand zip a password non-interactively is -P password, and the man page shouts "THIS IS INSECURE!" about it in capitals, because any other user or process can read your command line. The same page also calls the standard zip cipher "relatively weak". Info-ZIP has no AES at all, so if you want AES-256 inside a .zip you need 7-Zip (7zz), which has the same password-in-argv problem unless you let it prompt.

If you only need the contents encrypted and the .zip format itself is not a requirement, an encrypted disk image is a far stronger target and will take a password on stdin.

One thing worth fixing whichever route you take: cd "$(dirname "$1")" first, then zip using basename "$1". Otherwise the archive stores your whole /Users/you/Downloads/... path inside it, and the output lands wherever Shortcuts happened to be. The cd fixes both at once.

1

u/Apprehensive_Tea1579 2d ago

so how would the shell script look like? could you give an example por favor

1

u/EquivalentSky3094 2d ago

Yes. Swap the tool first: 7-Zip will take the password on stdin, so it never appears in a command line at all. Info-ZIP's zip has no way to do that.

brew install sevenzip gives you 7zz. Run which 7zz and use the full path in the script, since Shortcuts does not inherit your shell's PATH.

In the shortcut: Ask for Input for the password, then Run Shell Script with that as its input and Pass Input set to stdin. Put the folder in as a variable in the script text rather than as an argument, because the stdin slot is now taken by the password.

TARGET="<folder variable here>" cd "$(dirname "$TARGET")" || exit 1 NAME="$(basename "$TARGET")" /opt/homebrew/bin/7zz a -tzip -p -mem=AES256 "$NAME.zip" "$NAME"

Keep that flag order. Bare -p with no value attached is what makes it read the password instead of prompting on a tty it does not have. I ran exactly that on 7-Zip 25.01 with the password piped in, and 7zz l -slt out.zip reports Method = AES-256 on the entry, so it is real AES and not the old zip cipher.

The cd is doing two jobs: the archive lands next to the folder, and /Users/you/Downloads/... does not get stored inside the zip.

One limitation to know about before you rely on it. AES in a .zip encrypts file contents only, so 7zz l out.zip prints every file name with no password at all. If the names are sensitive, use -t7z -mhe=on instead of -tzip and live with a .7z.

Worth checking the method on the first archive you make. If it comes back without AES-256 in it, the password did not arrive from stdin, and the first thing I would look at is whether the line reaching the script is newline terminated.