$npx skillfedfor your agent

capstone

Capstone disassembly engine

Worth itPyPI SecurityReleased May 20263.6M downloads / mopermissive licensePlatform wheel

Decision gist · record as of 2026-08-14

platform wheels — capstone-5.0.9-py3-none-macosx_10_9_universal2.whl · capstone-5.0.9-py3-none-macosx_10_9_x86_64.whl · capstone-5.0.9-py3-none-macosx_11_0_arm64.whl
v5.0.9 · released 2026-05-28 · Python >=3.8 · 1 runtime deps: importlib-resources

Yes. Capstone is a mature, widely-used disassembly engine with no known vulnerabilities, permissive licensing, and straightforward installation via precompiled wheels. It is the right choice if you need to decode and analyze binary code across multiple architectures.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.8 or later; if building from source on Windows, Visual Studio and the Developer Command Prompt are needed to compile C code.
  • Precompiled wheels are available for most common platforms (macOS, Linux, Windows across multiple architectures), making installation straightforward via pip.
  • A C compilation environment is only needed if building from source; the package has one lightweight runtime dependency.

License · maintenance · safety

permissive license (permissive) — Released under the BSD license, which is permissive and allows commercial use, modification, and redistribution with minimal restrictions—you must include the LICENSE.TXT file with redistributed binaries or source.

last release 2026-05-28 (78 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 3,560,655 downloads/mo, #2,575 on PyPI

Verify before relying

pip install capstone

import capstone

md = capstone.Cs(capstone.CS_ARCH_X86, capstone.CS_MODE_64)
for instr in md.disasm(b'\x00'):
    print(instr.mnemonic)
  • Whether the package provides semantics (implicit register reads/writes) through a straightforward API or requires additional configuration.
  • Performance characteristics when disassembling large binaries or handling complex malware patterns.
  • Thread-safety guarantees and any caveats for concurrent disassembly operations.
Same gist for agents: .md · .json

What it is and what it does

Capstone is a lightweight, architecture-neutral disassembly framework designed for binary analysis and reverse engineering. It decodes machine code into assembly instructions for multiple CPU architectures (ARM, ARM64, MIPS, PPC, Sparc, SystemZ, XCore, X86) and provides semantic details about each instruction, such as implicit register reads and writes. The core is implemented in C with Python bindings, making it suitable for malware analysis and security research.

The package is distributed as precompiled wheels for most platforms, so installation via pip is typically frictionless. If you need to build from source, a C compiler is required. You can optionally point to an existing system-installed libcapstone library via the LIBCAPSTONE_PATH environment variable to skip the build step. The single runtime dependency is importlib-resources.

Use it for

  • Disassemble and analyze malware binaries to understand their behavior and identify obfuscation techniques.
  • Reverse-engineer compiled executables to audit security properties or recover lost source code.
  • Build custom binary analysis tools that need to decode machine code across multiple CPU architectures.
  • Analyze firmware or embedded system binaries where architecture support and lightweight overhead are critical.
  • Implement security research workflows that require extracting and analyzing instruction semantics from compiled code.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Capstone is a mature, widely-used disassembly engine with no known vulnerabilities, permissive licensing, and straightforward installation via precompiled wheels. It is the right choice if you need to decode and analyze binary code across multiple architectures.

Install

capstone on PyPI

Before you install

Precompiled wheels are available for most common platforms (macOS, Linux, Windows across multiple architectures), making installation straightforward via pip. A C compilation environment is only needed if building from source; the package has one lightweight runtime dependency.

Requires Python 3.8 or later; if building from source on Windows, Visual Studio and the Developer Command Prompt are needed to compile C code.

License in practice

Released under the BSD license, which is permissive and allows commercial use, modification, and redistribution with minimal restrictions—you must include the LICENSE.TXT file with redistributed binaries or source.

Quickstart

pip install capstone

import capstone

md = capstone.Cs(capstone.CS_ARCH_X86, capstone.CS_MODE_64)
for instr in md.disasm(b'\x00'):
    print(instr.mnemonic)

Verify before relying

  • Whether the package provides semantics (implicit register reads/writes) through a straightforward API or requires additional configuration.
  • Performance characteristics when disassembling large binaries or handling complex malware patterns.
  • Thread-safety guarantees and any caveats for concurrent disassembly operations.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.8
Install frictionMedium. Platform-specific wheel
Runtime dependencies
1 package
importlib-resources
MaintenanceActively maintained 78 days since the last release
First released
Downloads3,560,655 / month, #2,575 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: BSD LicenseProgramming Language :: Python :: 3

Evidence: capstone-5.0.9-py3-none-macosx_10_9_universal2.whl; capstone-5.0.9-py3-none-macosx_10_9_x86_64.whl; capstone-5.0.9-py3-none-macosx_11_0_arm64.whl; capstone-5.0.9-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; capstone-5.0.9-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; capstone-5.0.9-py3-none-manylinux_2_5_i686.manylinux1_i686.manylinux_2_17_i686.manylinux2014_i686.whl; capstone-5.0.9-py3-none-musllinux_1_2_aarch64.whl; capstone-5.0.9-py3-none-musllinux_1_2_i686.whl; capstone-5.0.9-py3-none-musllinux_1_2_x86_64.whl; capstone-5.0.9-py3-none-win_amd64.whl

Tags

Capabilities
disassembly enginebinary code analysismachine code decoderassembly instruction parsingreverse engineering toolarchitecture-neutral disassemblermalware analysis
Topics
binary-analysisreverse-engineeringdisassembly

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “disassembly engine”

  • capstoneCapstone is a disassembly engine that decodes binary machine code…
  • idaproEnables programmatic binary analysis and reverse engineering by…
  • viv-utilsProvides utility functions and helpers for analyzing and manipulating…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also keystone-engine · py-cpuinfo · pcodedmp · smda · dncil · ethereum-dasm · pypcode · ropper · angr · idapro