Instruction-level virtualization
Compiles sensitive logic into a proprietary bytecode run by a randomised, stack-based virtual machine.
Python code protection
Raises the cost of reverse engineering Python, and measures it honestly.
A code protection framework for proprietary Python applications and algorithms. It combines AST transformation, authenticated encryption, runtime protection, instruction-level virtualization, white-box cryptography and control-flow flattening. These layers raise the cost of analysis; the project is explicit that they cannot make recoverable Python impossible to reverse engineer.
# Default: AST obfuscation + AES-256-GCM runtime encryption
python -m skjol obfuscate -i .\my_app -o .\dist
# Hardened profile
python -m skjol obfuscate -i .\secret.py -o .\protected.py `
--code-virtualization --whitebox --control-flow-flatten
Compiles sensitive logic into a proprietary bytecode run by a randomised, stack-based virtual machine.
The key is baked into randomised lookup tables, so no contiguous secret sits in memory.
Rebuilds functions as state-machine dispatchers, removing the original sequential structure.
Structurally different inline decoders with per-session keys.
Critical protection layers can be compiled to native code through Cython, or an experimental Rust runtime.
Detection layers for debuggers, virtual machines and sandboxes, memory dumpers and function hooking.
A hexagonal architecture composes the protection layers:
AST obfuscation, control-flow flattening and polymorphic string encoding.
Authenticated encryption, white-box cryptography and code virtualization.
A per-build runtime module in Python, or an opt-in Rust (PyO3) extension.
A black-box harness that protects programs through the CLI and attacks the results.
pip install git+https://github.com/esgaltur/skjol.git
python -m skjol obfuscate -i .\app.py -o .\dist\app.py
The full documentation is in the repository on GitHub.