I'm not clear on why scandir is useful given it is only able to see into the initial package/zip bundle. If you're running that sort of thing, won't be hard-pathed anyways? It's not like you'll be scanning that kind of user data out of it?
cc @creationix