$npx skillfedfor your agent

abi3audit

Scans Python wheels for abi3 violations and inconsistencies

With conditionsPyPI SecurityReleased Jan 2026445.1K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — abi3audit-0.0.26-py3-none-any.whl
v0.0.26 · released 2026-01-23 · Python >=3.10 · 8 runtime deps: abi3info, kaitaistruct, packaging, pefile, pyelftools, requests, requests-cache, rich

Yes, if you build or maintain Python C extensions with abi3 tags. The tool addresses a real gap in the Python packaging ecosystem—there is no built-in enforcement of abi3 compliance, and incorrect tagging can cause runtime crashes or security issues. For extension developers, this is a straightforward audit step. For users of abi3 packages, it is less directly applicable unless you are vetting third-party wheels. No known vulnerabilities and active maintenance.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Low friction: pure Python wheel with eight runtime dependencies (abi3info, kaitaistruct, packaging, pefile, pyelftools, requests, requests-cache, rich).
  • Active maintenance with recent commits and no known vulnerabilities.

License · maintenance · safety

MIT (permissive) — MIT license (permissive): you can use, modify, and distribute abi3audit freely in commercial and private projects with minimal restrictions.

last release 2026-01-23 (203 days) · last repo commit 2026-08-10 · 123 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 445,138 downloads/mo, #6,617 on PyPI

Verify before relying

pip install abi3audit

abi3audit procmaps
abi3audit procmaps-0.5.0-cp36-abi3-manylinux2010_x86_64.whl
abi3audit procmaps.abi3.so
  • Whether the tool can audit wheels or shared objects from non-Linux platforms (Mach-O, Windows PE formats are mentioned in description but platform coverage is unclear).
  • Performance characteristics when scanning large package version histories or many wheels in batch.
Same gist for agents: .md · .json

What it is and what it does

abi3audit is a command-line auditor for Python C extensions that claim to use the stable ABI (abi3). The stable ABI is a CPython feature that allows extensions built once to work across multiple Python minor versions, but there is no enforcement mechanism—a wheel can be incorrectly tagged as abi3 or compiled against the wrong version without detection. abi3audit fills that gap by scanning wheels, individual shared objects, or entire PyPI package histories to find mismatches between the declared abi3 version tag and the actual symbols the extension uses.

The tool works by parsing binary formats (ELF, PE, Mach-O) and examining symbol tables to determine which CPython ABI version each symbol requires, then comparing that to the wheel's tag or a user-specified baseline. It reports version mismatches, non-abi3 symbols, and can output results as human-readable tables or JSON. It is maintained as an active project by Trail of Bits and depends on standard binary analysis libraries (pyelftools, pefile) plus packaging utilities.

Use it for

  • Validate that a locally-built abi3 wheel is correctly compiled and tagged before publishing to PyPI.
  • Audit an entire package's release history on PyPI to find past versions with abi3 violations.
  • Check a bare shared object file to confirm it uses only stable ABI symbols for a given Python version.
  • Generate a JSON report of abi3 compliance across multiple wheels for integration into CI/CD pipelines.
  • Investigate crashes or unexpected behavior in abi3 extensions by confirming symbol compatibility.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you build or maintain Python C extensions with abi3 tags.

The tool addresses a real gap in the Python packaging ecosystem—there is no built-in enforcement of abi3 compliance, and incorrect tagging can cause runtime crashes or security issues. For extension developers, this is a straightforward audit step. For users of abi3 packages, it is less directly applicable unless you are vetting third-party wheels. No known vulnerabilities and active maintenance.

Install

abi3audit on PyPI

Before you install

Low friction: pure Python wheel with eight runtime dependencies (abi3info, kaitaistruct, packaging, pefile, pyelftools, requests, requests-cache, rich). Active maintenance with recent commits and no known vulnerabilities.

Requires Python 3.10 or later.

License in practice

MIT license (permissive): you can use, modify, and distribute abi3audit freely in commercial and private projects with minimal restrictions.

Quickstart

pip install abi3audit

abi3audit procmaps
abi3audit procmaps-0.5.0-cp36-abi3-manylinux2010_x86_64.whl
abi3audit procmaps.abi3.so

Verify before relying

  • Whether the tool can audit wheels or shared objects from non-Linux platforms (Mach-O, Windows PE formats are mentioned in description but platform coverage is unclear).
  • Performance characteristics when scanning large package version histories or many wheels in batch.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
8 packages
abi3infokaitaistructpackagingpefilepyelftoolsrequestsrequests-cacherich
MaintenanceActively maintained 203 days since the last release
Last repo commit
First released
Downloads445,138 / month, #6,617 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyTopic :: Security

Evidence: abi3audit-0.0.26-py3-none-any.whl

Tags

Capabilities
abi3 wheel validationpython extension abi compliancestable abi violationswheel abi3 auditcpython abi checkerpython extension scannerabi3 compatibility check
Topics
binary-analysisc-extensionspackaging-tools

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “abi3 wheel validation”

  • abi3auditabi3audit scans Python extension wheels and shared objects for…
  • abi3infoabi3info exposes CPython's limited API and stable ABI (abi3) metadata…
  • sqlfluffrsSQLFluff-rs is a Rust-based optional component that integrates with a…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also abi3info · auditwheel · pip-audit · alibabacloud-actiontrail20200706 · trufflehog3 · cdk-nag · flawfinder · axe-playwright-python · aa-memberaudit · cxxfilt