Python code protection

Skjol

Raises the cost of reverse engineering Python, and measures it honestly.

A code protection framework for proprietary Python applications and algorithms. It combines AST transformation, authenticated encryption, runtime protection, instruction-level virtualization, white-box cryptography and control-flow flattening. These layers raise the cost of analysis; the project is explicit that they cannot make recoverable Python impossible to reverse engineer.

  • Python 3.10+
  • AST transformation
  • AES-256-GCM
  • Cython
  • Rust (PyO3, experimental)
License: MIT
PowerShell
# Default: AST obfuscation + AES-256-GCM runtime encryption
python -m skjol obfuscate -i .\my_app -o .\dist

# Hardened profile
python -m skjol obfuscate -i .\secret.py -o .\protected.py `
    --code-virtualization --whitebox --control-flow-flatten

What it does

01

Instruction-level virtualization

Compiles sensitive logic into a proprietary bytecode run by a randomised, stack-based virtual machine.

02

White-box cryptography

The key is baked into randomised lookup tables, so no contiguous secret sits in memory.

03

Control-flow flattening

Rebuilds functions as state-machine dispatchers, removing the original sequential structure.

04

Polymorphic strings

Structurally different inline decoders with per-session keys.

05

Native compilation

Critical protection layers can be compiled to native code through Cython, or an experimental Rust runtime.

06

Anti-analysis

Detection layers for debuggers, virtual machines and sandboxes, memory dumpers and function hooking.

How it's built

A hexagonal architecture composes the protection layers:

  1. Transform

    AST obfuscation, control-flow flattening and polymorphic string encoding.

  2. Protect

    Authenticated encryption, white-box cryptography and code virtualization.

  3. Runtime

    A per-build runtime module in Python, or an opt-in Rust (PyO3) extension.

  4. Evaluate

    A black-box harness that protects programs through the CLI and attacks the results.

Engineering highlights

  • Security claims come from a reproducible evaluation: 18 protected artifacts, static and dynamic extraction attacks.
  • Results are published as they are: no static recoveries, but runtime extraction succeeded 18/18, recorded as an open limitation.
  • An earlier unvalidated "0.87 resistance score" was withdrawn in favour of reproducible benchmarks.
  • The experimental Rust runtime blocked Python-level eval, exec and marshal hooks in a focused native trial.

Quick start

Terminal
pip install git+https://github.com/esgaltur/skjol.git
python -m skjol obfuscate -i .\app.py -o .\dist\app.py

The full documentation is in the repository on GitHub.

More projects