You can clone with
HTTPS or Subversion.
It would be nice to have the name of the DNSSEC algorithm, not just the number.
Two possible strategies: hardcode by hand the most common, or retrieve http://www.iana.org/assignments/dns-sec-alg-numbers/dns-sec-alg-numbers.xml (it's in XML) and parse it.
And the meaning of the flags, too :
algorithm RSASHA-1(5), length 4096 bits, flags ZONE+SEP(257)