
loremfile
io.github.kumarprabhashanandv0.2.0Updated Oct 8, 2026
CC0 sample files and test fixtures: find one, get its URL and SHA-256, check a copy on disk.
Overview
Lets an assistant find CC0 sample files and test fixtures, get their URLs and SHA-256 hashes, and verify a local copy.
- What it does
- Provides access to a catalog of free, CC0 sample files covering many formats, including PDFs, images, audio, video, office documents, data files, archives, fonts, text encodings, raw byte blobs, and deliberately malformed edge cases. The assistant can look up a fixture, retrieve its URL and SHA-256 hash, and check a copy already on disk against the published hash. The catalog is machine-readable and includes per-format indexes and checksum listings.
- When to use it
- Useful when you need placeholder or test files for development, CI pipelines, or demos and want stable, hash-verifiable downloads without accounts or attribution. Also helpful for testing how software handles malformed or truncated files.
- Requirements
- Runs as a local stdio process, installed via npm with npx or via PyPI with uvx. No accounts, API keys, or environment variables are declared. Network access to the canonical host is needed to download fixtures.
Installation
In SourceWeft
- Open loremfile in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
loremfile
Free, CC0, hotlink-friendly sample files for every file type. Lorem Picsum, but for PDFs, images, audio, video, office documents, data files, archives, fonts, text encodings, raw byte blobs and deliberately malformed edge cases.
No ads, no accounts, no rate-limit surprises, no attribution required. Open CORS, byte-range
support, one-year immutable caching, and a machine-readable
manifest.json with SHA-256 hashes for every file.
228 files across 78 formats plus the edge/ set are live, at catalog version 1.2.0. The
specification lives in docs/.
Canonical host
The canonical host is https://loremfile.dev.
This README is the out-of-band pointer: if loremfile.dev is ever unavailable or moves, the
current canonical host is stated here first. Do not rely on any other mirror.
What you can rely on
- The bytes at a published path do not change. Hash, byte count and MIME type stay as
they are; a fix is a new path, and the old entry records
supersededBy. A file may be withdrawn for legal reasons, and the manifest then keeps a tombstone for it. There is no promise of availability — see the terms. - Hotlinking is welcome. That is what this is for. Please keep automated traffic under 30 requests per second per client (the edge rate-limits at 300 requests / 10 s per IP).
- No tracking cookies, no analytics scripts, no accounts.
For agents and CI
/llms.txt— what this service is, in one file./manifest.json— every fixture with path, bytes,sha256, MIME type, tags and format-specific properties./sha256sums.txt— verify downloads withsha256sum -c./{format}/index.json— one format at a time.
GitHub Action
Pull fixtures into a workflow and check each one against its sha256 in the manifest:
It writes to loremfile-fixtures/ and outputs dir and count. A file whose bytes do not
match the manifest fails the step and names the file. catalog-version: "1.2.0" refuses to
run if loremfile.dev has moved on.
The action is shell only and talks to nothing but loremfile.dev. It downloads one file at a
time with a pause between them and backs off on a 429, because the published rate limit
applies to it like any other client. Linux and macOS runners only — it needs sha256sum
or shasum, and Windows is not supported rather than half-supported.
action-v1 is a major tag that moves as the action changes; it is deliberately not a v*
release tag, because those name a catalog version and are frozen once pushed. Pinning a
commit SHA works too and is the strictest option.
Licences
Third-party tools used to generate the files are listed in THIRD_PARTY.md.
No third-party media is redistributed — everything is generated.
Repository
Contributing
Fixture requests and bug reports go in Issues; see
CONTRIBUTING.md for the naming grammar and what makes a good fixture.
Security reports: SECURITY.md.
By opening a pull request you agree that generator code is MIT and any resulting fixtures are CC0.
Source: README.md at commit 684a053
Tools
0Version history
1- v0.2.0LatestOct 8, 2026


