This is a security risk: http://security.stackexchange.com/questions/73718/how-zip-symlink-works We should check and by default raise an error for links that target files outside the archive