$npx skillfedfor your agent

cart

CaRT Neutering format

With conditionsPyPI LibrariesReleased Feb 2025360.9K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — cart-1.2.3-py2.py3-none-any.whl
v1.2.3 · released 2025-02-10 · Python >=3.6 · 1 runtime deps: pycryptodome

Yes, if you work in malware analysis, threat intelligence, or security research and need a standardized format for safe malware storage and transfer with embedded metadata. The low install friction, permissive license, and lack of known vulnerabilities make it a safe choice. However, note that maintenance is dormant and RC4 is cryptographically weak by modern standards—verify that RC4 meets your security requirements before adopting for new systems rather than legacy workflows.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires pycryptodome for RC4 encryption; Python 3.6 or later.
  • Low install friction with a single runtime dependency (pycryptodome).
  • Maintenance is dormant—last commit was 2025-02-10 but no releases for 550 days prior, suggesting the package is stable but not actively developed.

License · maintenance · safety

MIT (permissive) — MIT license (permissive) places no restrictions on use, modification, or redistribution in proprietary or open-source contexts.

last release 2025-02-10 (550 days) · last repo commit 2025-02-10 · 53 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 360,936 downloads/mo, #7,241 on PyPI

Verify before relying

pip install cart

from cart import CaRT

# Encode a file with optional metadata
cart = CaRT()
cart.encode('malware.exe', 'malware.exe.cartmeta')

# Decode a CaRT file
cart.decode('malware.exe.cart')
  • Whether RC4 encryption meets current security standards for new deployments versus legacy/archival use only
  • Performance characteristics and streaming efficiency claims relative to standard compression tools
  • Compatibility with STIX v2 implementations beyond the JSON embedding example shown
Same gist for agents: .md · .json

What it is and what it does

CaRT is a specialized file format designed to safely store and transfer malware samples by compressing them with zlib, encrypting them with RC4, and embedding associated metadata—including optional STIX v2 threat intelligence reports—all within a single .cart file. The format includes a mandatory header and footer structure that allows metadata and hash information to be read without decompressing the entire payload, and it uses a default RC4 key (first 8 digits of pi, twice) unless overridden with a custom key.

The package provides both a Python library for programmatic access and a command-line interface that automatically detects whether to encode or decode a file. It reads optional metadata from .cartmeta files with matching prefixes and supports configuration via ~/.cart/cart.cfg. The primary use case is in malware analysis and threat intelligence workflows where samples must be safely archived and shared without triggering antivirus detection or accidental execution.

Use it for

  • Archive malware samples for security research with embedded STIX v2 threat reports without triggering antivirus alerts
  • Transfer suspected malware between security teams with metadata and hash verification built into the file structure
  • Store malware collections with streaming compression to reduce storage footprint while preserving metadata accessibility
  • Integrate threat intelligence reports directly into malware samples for downstream analysis tools via STIX v2 JSON embedding
  • Read file hashes and metadata from archived samples without decompressing the full payload for rapid triage

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you work in malware analysis, threat intelligence, or security research and need a standardized format for safe malware storage and transfer with embedded metadata.

The low install friction, permissive license, and lack of known vulnerabilities make it a safe choice. However, note that maintenance is dormant and RC4 is cryptographically weak by modern standards—verify that RC4 meets your security requirements before adopting for new systems rather than legacy workflows.

Install

cart on PyPI

Before you install

Low install friction with a single runtime dependency (pycryptodome). Maintenance is dormant—last commit was 2025-02-10 but no releases for 550 days prior, suggesting the package is stable but not actively developed.

Requires pycryptodome for RC4 encryption; Python 3.6 or later.

License in practice

MIT license (permissive) places no restrictions on use, modification, or redistribution in proprietary or open-source contexts.

Quickstart

pip install cart

from cart import CaRT

# Encode a file with optional metadata
cart = CaRT()
cart.encode('malware.exe', 'malware.exe.cartmeta')

# Decode a CaRT file
cart.decode('malware.exe.cart')

Verify before relying

  • Whether RC4 encryption meets current security standards for new deployments versus legacy/archival use only
  • Performance characteristics and streaming efficiency claims relative to standard compression tools
  • Compatibility with STIX v2 implementations beyond the JSON embedding example shown

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.6
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
pycryptodome
MaintenanceDormant 550 days since the last release
Last repo commit
First released
Downloads360,936 / month, #7,241 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Software Development :: Libraries

Evidence: cart-1.2.3-py2.py3-none-any.whl

Tags

Capabilities
malware storage formatencrypted file compressionRC4 zlib transportmalware metadata embeddingSTIX report packagingsecure file neuteringcryptographic file archive
Topics
malware-analysisthreat-intelligencestix-integration
PyPI keywords
neuteringformatmalwarecartstixdevelopmentgccanadacse-cstcsecstcccscyber

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “malware storage format”

  • cartCaRT is a file format and Python library for compressing, encrypting,…
  • olefileolefile parses, reads, and writes Microsoft OLE2 compound files…
  • ppdeepppdeep computes fuzzy hashes (CTPH/ssdeep) to measure similarity…

Give your agent the search over MCP, or paste the wish link into any chat.

More Libraries packages

urllib3 Worth it
PyPI · Libraries · released May 2026

urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.

MITpure Python · 3.10+
1.8Bdownloads / mo
requests Worth it
PyPI · Libraries · released May 2026

Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.

Apache-2.0pure Python · 3.10+
1.8Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
python-dateutil Worth it
PyPI · Libraries · released Mar 2024

Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.

Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.

Apache-2.0pure Python
1.2Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo
pytest Worth it
PyPI · Libraries · released Jun 2026

pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.

MITpure Python · 3.10+
1.1Bdownloads / mo

See also Flask-Compress · stix2 · clamd · clamav-client · mixbox · pyminizip · cmeel-zlib · malduck · pylzss · pyClamd