🛡️ Modern Python code obfuscator - Enterprise-grade protection at 50% lower cost than PyArmor
- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
claude mcp add pyobfus -- uvx pyobfus-mcp{
"mcpServers": {
"pyobfus": {
"command": "uvx",
"args": ["pyobfus-mcp"]
}
}
}MCP Servers overview
# pyobfus — the Python obfuscator <p align="center"> <img src="https://raw.githubusercontent.com/zhurong2020/pyobfus/main/docs/assets/logo.jpeg" alt="pyobfus Logo" width="200"> </p> **pyobfus** (pronounced as "Python obfuscator") is a modern, AST-based **python-obfuscator / code-obfuscator** with framework-aware presets, reverse stack-trace mapping for AI-assisted debugging, and a machine-readable JSON CLI designed for [Claude Code](https://claude.com/claude-code), [Cursor](https://cursor.com/), [Codex](https://openai.com/codex/), and MCP agents. A transparent, open-source alternative to PyArmor. [](https://pypi.org/project/pyobfus/) [](https://pypi.org/project/pyobfus/) [](https://pyobfus.readthedocs.io/en/latest/) [-blue.svg)](LICENSE) [](https://www.python.org/downloads/) [](https://www.bestpractices.dev/projects/12788) [](https://doi.org/10.5281/zenodo.20846053) [](https://glama.ai/mcp/servers/zhurong2020/pyobfus) [](https://github.com/psf/black) A Python code obfuscator built with AST-based transformations. **Supports Python 3.9 through 3.14**. Provides reliable name mangling, string encoding, control-flow flattening, AES-256 string encryption, and — unique to pyobfus — a reverse-mapping workflow that lets you (or your AI coding assistant) debug obfuscated stack traces without giving up the protection. > **🔒 Pro Edition available** — 6 patent-targeted protection mechanisms (Selective Opacity, forensic watermarking, Runtime String Vault, and more) layered on top of the free AST obfuscator, $45 one-time, no subscription. See [Pro Edition](#-pro-edition) below. > **🔧 What's new in v0.5.7** — Pro builds now support `--import-obfuscation`, rewriting top-level imports to runtime `importlib` / `__import__` calls and encrypting the import strings. The comparison guide also now states the honest AST-vs-bytecode tradeoff for PyArmor alternatives. Full details in the [CHANGELOG](CHANGELOG.md); see [Pro Edition](#-pro-edition) below. ## 🔌 Companion MCP server: [`pyobfus-mcp`](pyobfus_mcp/) This repository ships **two installable packages**: | Package | What it is | Install | |---|---|---| | [`pyobfus`](https://pypi.org/project/pyobfus/) | The Python obfuscator (CLI + library). | `pip install pyobfus` | | [`pyobfus-mcp`](https://pypi.org/project/pyobfus-mcp/) | A **Model Context Protocol (MCP) server** that exposes pyobfus's tools to AI coding agents. | `uvx pyobfus-mcp` (zero-install) or `pip install pyobfus-mcp` | The MCP server lives in [`pyobfus_mcp/`](pyobfus_mcp/) and is built on the official [Model Context Protocol Python SDK](https://github.com/modelcontextprotocol/python-sdk) (FastMCP). It registers eight MCP tools so **Claude Desktop, Claude Code, Cursor, Windsurf, Zed, and Codex** can call pyobfus directly from agent conversations — no shelling out: | MCP tool | Implementation | Purpose | |---|---|---| | `protect_project` | [`pyobfus_mcp/tools.py`](pyobfus_mcp/pyobfus_mcp/tools.py) | **One-call, self-verifying pipeline**: scan → preset → obfuscate → byte-compile + import-smoke-test the output → return `verified: true/false`. The agent reports a green check instead of hoping the transform didn't break anything | | `check_obfuscation_risks` | [`pyobfus_mcp/tools.py`](pyobfus_mcp/pyobfus_mcp/tools.py) | Pre-flight risk scan (eval/exec, dynamic attribute, framework reflection) | | `generate_pyobfus_config` | [`pyobfus_mcp/tools.py`](pyobfus_mcp/pyobfus_mcp/tools.py) | Auto-detect framework → write a working `pyobfus.yaml` | | `unmap_stack_trace` | [`pyobfus_mcp/tools.py`](pyobfus_mcp/pyobfus_mcp/tools.py) | Reverse obfuscated identifiers in a production stack trace | | `list_presets` | [`pyobfus_mcp/tools.py`](pyobfus_mcp/pyobfus_mcp/tools.py) | Enumerate community / framework / Pro presets | | `explain_preset` | [`pyobfus_mcp/tools.py`](pyobfus_mcp/pyobfus_mcp/tools.py) | Describe what a named preset changes | | `recommend_tier` | [`pyobfus_mcp/tools.py`](pyobfus_mcp/pyobfus_mcp/tools.py) | Analyze a project and recommend community vs Pro tier, with reasoning | | `start_pro_trial` | [`pyobfus_mcp/tools.py`](pyobfus_mcp/pyobfus_mcp/tools.py) | Return structured guidance for starting the 5-day Pro trial | The server is registered in the **official [MCP Registry](https://registry.modelcontextprotocol.io/)** under `io.github.zhurong2020/pyobfus-mcp`. The transport is stdio. See [`pyobfus_mcp/README.md`](pyobfus_mcp/README.md) for per-client configuration snippets. ### 🧩 Claude Code skill / plugin This repo is also a **Claude Code plugin marketplace**. The `pyobfus-protect` skill teaches an agent the full "protect Python before shipping — obfuscate **and** verify it still runs" workflow (MCP-first, CLI fallback): ``` /plugin marketplace add zhurong2020/pyobfus /plugin install pyobfus@pyobfus ``` See [`skills/`](skills/) for the skill and install details. (This is distinct from [`templates/ai-integration/`](templates/ai-integration/), which are copy-in rule files for *your* project.) ### 🤖 AI-native features - **`pyobfus --check src/`** — pre-flight risk scan: detects `eval`/`exec`, dynamic attribute access, and framework reflection points before you obfuscate. JSON output with an `ai_hint` telling your AI assistant what to run next. - **`pyobfus --init src/`** — zero-config onboarding: scans the project, detects FastAPI/Django/Pydantic/Click/SQLAlchemy, and writes a ready-to-use `pyobfus.yaml`. - **`pyobfus --unmap --trace error.log --mapping mapping.json`** — reverse obfuscated identifiers in a production stack trace so you can debug (or hand the trace to an AI assistant) without reversing the obfuscation itself. - **`pyobfus … --save-mapping mapping.json --trace-marker`** — stamp each obfuscated file with a `# pyobfus:obfuscated` header (id + mapping filename + the exact `--unmap` command) so an AI agent that lands in an obfuscated file from a traceback immediately knows it's pyobfus output and how to reverse the names. - **`pyobfus … --provenance-manifest provenance.json`** — write a local JSON manifest (obfuscated files, config hash, pyobfus version, mapping digest, and a self-consistency integrity digest — not a cryptographic signature) for offline build provenance. - **Framework-aware presets** — `--preset fastapi | django | flask | pydantic | click | sqlalchemy | ml` with built-in exclusions for dispatch methods, decorators, ORM fields, migrations, model-serving wrappers, and dependency-injection parameters. - **Global `--json`** — every CLI mode (`obfuscate`, `--check`, `--unmap`, `--init`) emits the same structured schema with an `ai_hint` field, ready for Claude Code, Cursor, Windsurf, and MCP servers to consume. ## Features ### ✅ Free Edition The following features are **fully implemented and available** in the current version: - **Cross-File Obfuscation**: Consistent name obfuscation across multiple files - Automatic import statement rewriting - `__all__` list updates with obfuscated names - Global symbol table with collision detection - Two-phase obfuscation pipeline (Scan → Transform) - Preview mode with `--dry-run` flag - **Name Mangling**: Rename variables, functions, classes, and class attributes to obfuscated names (I0, I1, I2...) - **Comment Removal**: Strip comments and docstrings - **String Encoding**: Base64 encoding for string literals with automatic decoder injection - **Parameter Preservation**: Preserve function parameter names for keyword argument compatibility (`--preserve-param-names`) - **Multi-file Support**: Obfuscate entire projects with preserved import relationships - **File Filtering**: Exclude files using glob patterns (test files, config files, etc.) - **Configuration Files**: YAML-based configuration for repeatable builds - **Selective Obfuscation**: Preserve specific names (builtins, magic methods, custom exclusions) - **Configuration Presets**: `--preset safe | balanced | aggressive` for quick obfuscation-strength tradeoffs, plus **framework-aware presets** — `--preset fastapi | django | flask | pydantic | click | sqlalchemy | ml` — with built-in exclusions for dispatch methods, decorators, ORM fields, migrations, and dependency-injection parameters. `--list-presets` shows them all - **Pre-flight Risk Scanning** (`--check`): detects `eval`/`exec`, dynamic attribute access, and framework reflection points before you obfuscate - **Reverse Stack-Trace Mapping** (`--unmap`): reverse obfuscated identifiers in a production stack trace, so you (or an AI coding assistant) can debug without un-obfuscating the shipped code - **Build Provenance** (`--provenance-manifest`, v0.5.5): local JSON manifest of an obfuscation run — output file hashes, config hash, pyobfus version, mapping digest — for offline build provenance, no network calls ### 🔒 Pro Edition The following advanced features are available with a Pro license: - **String Encryption** - AES-256 encryption for strings - Runtime decryption with injected decoder - Automatic key generation - **Anti-Debugging** - Debugger detection checks injected into functions - Multiple detection methods (sys.gettrace, sys.settrace) - Configurable behavior - **Control Flow Flattening** - State machine transformation for if/else/elif - For/while loop flattening - Nested structure support - CLI: `--control-flow` - **Dead Code
What people ask about pyobfus
What is zhurong2020/pyobfus?
+
zhurong2020/pyobfus is mcp servers for the Claude AI ecosystem. 🛡️ Modern Python code obfuscator - Enterprise-grade protection at 50% lower cost than PyArmor It has 3 GitHub stars and was last updated today.
How do I install pyobfus?
+
You can install pyobfus by cloning the repository (https://github.com/zhurong2020/pyobfus) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is zhurong2020/pyobfus safe to use?
+
Our security agent has analyzed zhurong2020/pyobfus and assigned a Trust Score of 87/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains zhurong2020/pyobfus?
+
zhurong2020/pyobfus is maintained by zhurong2020. The last recorded GitHub activity is from today, with 0 open issues.
Are there alternatives to pyobfus?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy pyobfus to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/zhurong2020-pyobfus)<a href="https://claudewave.com/repo/zhurong2020-pyobfus"><img src="https://claudewave.com/api/badge/zhurong2020-pyobfus" alt="Featured on ClaudeWave: zhurong2020/pyobfus" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
The fastest path to AI-powered full stack observability, even for lean teams.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!