loremfile

io.github.kumarprabhashanandv0.2.0Updated Oct 8, 2026

CC0 sample files and test fixtures: find one, get its URL and SHA-256, check a copy on disk.

VerifiedSTDIODesktop onlyDeveloper ToolsFiles & Storage

Overview

AI-generated overview

Lets an assistant find CC0 sample files and test fixtures, get their URLs and SHA-256 hashes, and verify a local copy.

What it does
Provides access to a catalog of free, CC0 sample files covering many formats, including PDFs, images, audio, video, office documents, data files, archives, fonts, text encodings, raw byte blobs, and deliberately malformed edge cases. The assistant can look up a fixture, retrieve its URL and SHA-256 hash, and check a copy already on disk against the published hash. The catalog is machine-readable and includes per-format indexes and checksum listings.
When to use it
Useful when you need placeholder or test files for development, CI pipelines, or demos and want stable, hash-verifiable downloads without accounts or attribution. Also helpful for testing how software handles malformed or truncated files.
Requirements
Runs as a local stdio process, installed via npm with npx or via PyPI with uvx. No accounts, API keys, or environment variables are declared. Network access to the canonical host is needed to download fixtures.
Before you install
The service offers no promise of availability, and files may be withdrawn for legal reasons, leaving only a tombstone in the manifest. Automated traffic should stay under 30 requests per second per client. The GitHub Action is Linux and macOS only and requires sha256sum or shasum.

Installation

In SourceWeft

  1. Open loremfile in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

loremfile

Free, CC0, hotlink-friendly sample files for every file type. Lorem Picsum, but for PDFs, images, audio, video, office documents, data files, archives, fonts, text encodings, raw byte blobs and deliberately malformed edge cases.

https://loremfile.dev/pdf/a4-3pages.pdfhttps://loremfile.dev/bin/10mb.binhttps://loremfile.dev/mp4/720p-5s.mp4https://loremfile.dev/edge/jpg-truncated-50pct.jpg

No ads, no accounts, no rate-limit surprises, no attribution required. Open CORS, byte-range support, one-year immutable caching, and a machine-readable manifest.json with SHA-256 hashes for every file.

228 files across 78 formats plus the edge/ set are live, at catalog version 1.2.0. The specification lives in docs/.

Canonical host

The canonical host is https://loremfile.dev.

This README is the out-of-band pointer: if loremfile.dev is ever unavailable or moves, the current canonical host is stated here first. Do not rely on any other mirror.

What you can rely on

  • The bytes at a published path do not change. Hash, byte count and MIME type stay as they are; a fix is a new path, and the old entry records supersededBy. A file may be withdrawn for legal reasons, and the manifest then keeps a tombstone for it. There is no promise of availability — see the terms.
  • Hotlinking is welcome. That is what this is for. Please keep automated traffic under 30 requests per second per client (the edge rate-limits at 300 requests / 10 s per IP).
  • No tracking cookies, no analytics scripts, no accounts.

For agents and CI

  • /llms.txt — what this service is, in one file.
  • /manifest.json — every fixture with path, bytes, sha256, MIME type, tags and format-specific properties.
  • /sha256sums.txt — verify downloads with sha256sum -c.
  • /{format}/index.json — one format at a time.

GitHub Action

Pull fixtures into a workflow and check each one against its sha256 in the manifest:

yaml
- uses: kumarprabhashanand/loremfile/action@action-v1  with:    paths: pdf/minimal.pdf mp4/720p-5s.mp4    formats: svg

It writes to loremfile-fixtures/ and outputs dir and count. A file whose bytes do not match the manifest fails the step and names the file. catalog-version: "1.2.0" refuses to run if loremfile.dev has moved on.

The action is shell only and talks to nothing but loremfile.dev. It downloads one file at a time with a pause between them and backs off on a 429, because the published rate limit applies to it like any other client. Linux and macOS runners only — it needs sha256sum or shasum, and Windows is not supported rather than half-supported.

action-v1 is a major tag that moves as the action changes; it is deliberately not a v* release tag, because those name a catalog version and are frozen once pushed. Pinning a commit SHA works too and is the strictest option.

Licences

WhatLicence
Every file served under a format path (/pdf/…, /bin/…, /edge/…)CC0 1.0 Universal — public domain, no attribution needed
Generators, site and tooling in this repositoryMIT
Website text and graphicsCC BY 4.0, attribute "loremfile.dev"

Third-party tools used to generate the files are listed in THIRD_PARTY.md. No third-party media is redistributed — everything is generated.

Repository

PathWhat
docs/The full specification, 00–19. Start with docs/README.md.
catalog/Declarative fixture definitions, one YAML per format.
src/loremfile/Generators, validators, site builder, uploader, infrastructure code.
infra/Cloudflare desired state, applied by workflow.
manifest.jsonGenerated lock file — never hand-edited.

Contributing

Fixture requests and bug reports go in Issues; see CONTRIBUTING.md for the naming grammar and what makes a good fixture. Security reports: SECURITY.md.

By opening a pull request you agree that generator code is MIT and any resulting fixtures are CC0.

Source: README.md at commit 684a053

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.2.0LatestOct 8, 2026