fickling
A static analyzer and interpreter for Python pickle data
Decision gist · record as of 2026-08-14
Yes. Fickling is actively maintained, has no runtime dependencies, supports current Python versions, and fills a genuine security gap in ML workflows where pickle deserialization is a known attack vector. The LGPLv3+ license is permissive for most use cases. Install it if you load pickle or PyTorch files from any untrusted source.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- PyTorch support requires the optional torch dependency.
- Installation is straightforward with no runtime dependencies; the package is actively maintained with a recent release and supports Python 3.10 through 3.14.
License · maintenance · safety
copyleft license (copyleft) — Fickling is licensed under GNU LGPLv3+, a copyleft license. You may use it in proprietary applications if you link dynamically and provide users with the ability to relink against modified versions, but derivative works of fickling itself must remain open source.
last release 2026-06-26 (49 days) · last repo commit 2026-08-13 · 662 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 993,426 downloads/mo, #4,556 on PyPI
Alternatives
Verify before relying
import fickling
# Enable safety checks for all pickle loads
fickling.always_check_safety()
# Or check a single file
try:
fickling.load("file.pkl")
except fickling.UnsafeFileError as e:
print(f"Unsafe: {e.info}")- Whether the allowlist of safe ML library imports is kept current with new library releases
- Performance characteristics when analyzing large pickle files or many files in sequence
What it is and what it does
Fickling provides tools to inspect and validate Python pickle files for malicious content before they are deserialized. It works by hooking into Python's pickle module to intercept and analyze bytecode execution, checking imports against an allowlist of known-safe ML library imports. The package can be used as a library with context managers or global hooks, or as a command-line tool for batch analysis.
The core use case is securing AI/ML environments where untrusted pickle files (including PyTorch model files) may be loaded. Fickling can also decompile pickle bytecode to an AST for manual inspection, trace pickle execution without running malicious code, inject code into pickle files, and identify polyglot files that masquerade as multiple formats. It supports PyTorch formats from v0.1.1 through v1.3 and TorchScript formats v1.0 through v1.4.
Use it for
- Scan downloaded PyTorch models or pickle files for malicious imports before loading them in production
- Automatically block unsafe pickle deserialization in ML pipelines using global hooks or context managers
- Analyze suspicious pickle files by decompiling them to Python AST for manual code review
- Detect polyglot files that exploit multiple PyTorch or TorchScript format specifications
- Trace pickle bytecode execution without executing embedded malicious code for forensic analysis
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Fickling is actively maintained, has no runtime dependencies, supports current Python versions, and fills a genuine security gap in ML workflows where pickle deserialization is a known attack vector. The LGPLv3+ license is permissive for most use cases. Install it if you load pickle or PyTorch files from any untrusted source.
Install
fickling on PyPI
Before you install
Installation is straightforward with no runtime dependencies; the package is actively maintained with a recent release and supports Python 3.10 through 3.14. PyTorch support is optional.
Requires Python 3.10 or later. PyTorch support requires the optional torch dependency.
License in practice
Fickling is licensed under GNU LGPLv3+, a copyleft license. You may use it in proprietary applications if you link dynamically and provide users with the ability to relink against modified versions, but derivative works of fickling itself must remain open source.
Quickstart
import fickling
# Enable safety checks for all pickle loads
fickling.always_check_safety()
# Or check a single file
try:
fickling.load("file.pkl")
except fickling.UnsafeFileError as e:
print(f"Unsafe: {e.info}")
Verify before relying
- Whether the allowlist of safe ML library imports is kept current with new library releases
- Performance characteristics when analyzing large pickle files or many files in sequence
Package facts
| License | copyleft license copyleft |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 49 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 993,426 / month, #4,556 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaEnvironment :: ConsoleIntended Audience :: Science/ResearchLicense :: OSI Approved :: GNU Lesser General Public License v3 or later (LGPLv3+)Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: SecurityTopic :: Software Development :: TestingTopic :: Utilities |
Evidence: fickling-0.1.12-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “pickle security analysis”
- ficklingFickling is a decompiler, static analyzer, and bytecode rewriter for…
- picklescanScans Python Pickle files and related serialized model formats to…
- pypicklepypickle wraps Python's pickle module to save and load serialized…
Give your agent the search over MCP, or paste the wish link into any chat.
More Utilities packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.
Install it if you need to display or transform source code.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
See also picklescan · pyarrow-hotfix · pypickle · cloudpickle · dill · compress-pickle · django-picklefield · uncompyle6 · decompyle3 · depyf