Can an AI model open a ZIP file?
The registry verdict table for opening a ZIP file
Of the ten registry configurations assessed against this family's own canonical task, no single word dominates: Guarded, Highly auspicious each account for 3 of the ten, computed by the method published in full at /method. The Registry makes no representation that an assessment predicts the outcome of any task, and no assessment is validated against real-world results.
| Model | Manufacturer | Training cutoff | Verdict | Score | Harmony |
|---|---|---|---|---|---|
| Gemini 3.7 Flash | Google DeepMind | 2025-01 | Guarded | 3 of 7 | -4 |
| DeepSeek V4 Pro | DeepSeek | 2025-12 | Neutral | 4 of 7 | -1 |
| Claude Fable 5 | Anthropic | 2026-01 | Highly auspicious | 7 of 7 | +5 |
| Claude Sonnet 5 | Anthropic | 2026-01 | Inauspicious | 1 of 7 | -3 |
| GPT-5.6 Sol | OpenAI | 2026-02 | Highly auspicious | 7 of 7 | +1 |
| GPT-5.6 Terra | OpenAI | 2026-02 | Favourable | 5 of 7 | -1 |
| Grok 4.6 | xAI | 2026-02 | Guarded | 3 of 7 | -1 |
| Kimi K3 | Moonshot AI | 2026-03 | Guarded | 3 of 7 | -1 |
| Qwen3.8-Max | Alibaba Cloud | 2026-03 | Inauspicious | 1 of 7 | 0 |
| Claude Opus 5 | Anthropic | 2026-05 | Highly auspicious | 7 of 7 | +2 |
The composite weight in the right-hand column is computed from the model identifier, its training cutoff, and the temperature — nothing else. It constrains the range of verdicts available to a configuration independently of the task, so two rows of this table are not comparable as an assessment of the products named in them. The Registry has never run this task against any model listed here.
About this capability question
Opening a ZIP file is narrower than it first sounds: the canonical brief this registry assesses stops at listing what an archive contains, rather than extracting, reading, or acting on any file inside it. Seven distinct phrasings of essentially this request — from 'open zip files' to 'unzip files' — recur behind seven of the eight brand prefixes tracked, a tighter cluster than several of this wave's other families manage.
An archive is a container, and a container's contents are, until opened, retrieved rather than known. That is the operational property the classification for this family rests on.
The canonical brief below fixes the container as an email attachment specifically, which is a common enough real trigger for the task that it hashes to something concrete rather than to an abstract 'a ZIP file exists somewhere.' Nothing about that wording is inferred from any actual message; it is simply the wording the Registry publishes and reuses.
How the ten configurations read opening a ZIP file
This family shares its task class with several others in the wave, which means the dominant-house and dominant-element reading below is identical, row for row, to what those sibling pages show. What is not identical is the verdict distribution, computed from this family's own canonical brief.
Element counts, ascendant spread, and training-cutoff range are published once, on /can, rather than repeated on every family page — they are properties of the ten configurations alone and do not move with the task. What is specific to opening a ZIP file: reading information retrieval through a dominant house or a dominant element, 2 of the ten configurations; and, from this family's own canonical task, no single word dominates: Guarded, Highly auspicious each account for 3 of the ten in the distribution below.
| Published value | Verdict | Configurations |
|---|---|---|
| 1 of 7 | Inauspicious | 2 of the ten |
| 2 of 7 | Unfavourable | 0 of the ten |
| 3 of 7 | Guarded | 3 of the ten |
| 4 of 7 | Neutral | 1 of the ten |
| 5 of 7 | Favourable | 1 of the ten |
| 6 of 7 | Auspicious | 0 of the ten |
| 7 of 7 | Highly auspicious | 3 of the ten |
Grok 4.6, derivation shown working
Grok 4.6's permanent chart never reads a task. Its chart_seed is the
SHA-256 digest of the string "Grok 4.6|2026-02|0.700"
— d59ad359a180d571…, the first sixteen of sixty-four hex
characters — and that seed alone fixes an ascendant of Capricorn, a
ruling planet of Sun, and a harmony of -1.
The same chart appears, unchanged, on every task-class page this configuration is
assessed against.
What reads opening a ZIP file specifically is this family's own canonical
string — never stored, only hashed, to 0296e3b9ed869e41… —
combined with the chart_seed and the task class (retrieval) to form
task_seed. Its first byte, taken modulo seven and offset by that harmony of
-1, is the verdict's internal base, clamped to the
0–6 range and published one higher on the 1–7 scale /method documents in full.
This configuration's harmony is not enough, for this brief, to push the internal score against either bound: the published result, 3 of 7 — Guarded, lands 2 steps clear of the floor and 4 clear of the ceiling.
Why opening a zip file is classified as Information retrieval
Listing the contents of an attached archive is an act of accessing and reporting on content that already exists, packaged rather than plain — the same shape as reading a document, only with one extra layer to open first.
On the order form's task class field, select Information retrieval. That class's own risk-factor page is /tasks/retrieval.
An archive's risk is entirely about what a listing omits or misreports — a file silently skipped, a name garbled — since the canonical brief stops at listing contents and never opens what is inside. 4 risk factors are tracked for information retrieval tasks generally; an assessment for opening a ZIP file reports 3 of them, selected by the submitted task's own seed rather than by choice. Their names and severities are certificate content, not free-page content.
What this page does not claim about opening a ZIP file
The canonical brief stops at a file listing. Whether any file inside the archive is itself a further attachment, a document, or something assessed under a different task class entirely is outside its scope, deliberately. The Registry does not test models and does not measure a success rate for opening a ZIP file or any other task; what it does is compute, and the table at the top of this page is what it computed.
A buyer's own opening a ZIP file task, ordered separately, computes its own verdict and window — never the canonical-brief result shown above — plus, on Extended and Full Chart tiers, named risk factors and an hourly outlook not shown here. EUR 1.90 Standard, EUR 4.90 Extended, EUR 14.90 Full Chart, which adds the permanent chart. Assessments from EUR 1.90; machine-readable at /pricing.json.
Related surfaces
← All capability questions · The AFR-1 method · Information retrieval task class
Related capability questions: Open a link · Read an Excel file · Read a PDF
Questions about opening a ZIP file
- Can an AI model open a ZIP file?
- Across the ten registry configurations at their own registry-default settings, no single word dominates: Guarded, Highly auspicious each account for 3 of the ten for this family's own canonical task. By training cutoff, the oldest configuration assessed returns Guarded and the newest returns Highly auspicious; the full ten-row table above lists the exact verdict for every configuration in between.
- Why is opening a ZIP file classified as Information retrieval rather than a different task class?
- Listing the contents of an attached archive is an act of accessing and reporting on content that already exists, packaged rather than plain — the same shape as reading a document, only with one extra layer to open first.
- Does opening a ZIP file cover extracting or reading the files inside it, not just listing them?
- Not in the canonical brief this page assesses. That brief lists the archive's contents and stops there; extracting or reading an individual file inside it is closer to the shape of this registry's PDF- and spreadsheet-reading families, and would be assessed as its own task.