$npx skillfedfor your agent

miscreant

Misuse-resistant authenticated symmetric encryption

SkipPyPI CryptographyReleased Dec 20171.3M downloads / moMIT licenseSource build

Decision gist · record as of 2026-08-14

sdist only — miscreant-0.3.0.tar.gz · builds from source
v0.3.0 · released 2017-12-25

No. The package is abandoned (last release 2017-12-25, repository archived, no commits since 2019-09-03) and marked Pre-Alpha. While the cryptographic constructions are theoretically sound and no known vulnerabilities exist, the lack of active maintenance means security issues and compatibility problems will not be addressed. Use only if maintaining legacy code already depending on it.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Package is abandoned with no active maintenance; security issues will not be addressed by the original developers.
  • High install friction with no runtime dependencies.
  • The package is abandoned—last commit was 2019-09-03 and latest release was 2017-12-25.

License · maintenance · safety

MIT license (permissive) — MIT license permits commercial and private use with minimal restrictions, though the abandoned status means no ongoing legal or security updates from maintainers.

last release 2017-12-25 (3154 days) · last repo commit 2019-09-03 · 474 stars · archived

0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,278,707 downloads/mo, #4,120 on PyPI

Verify before relying

pip install miscreant

from miscreant import AESSIV

cipher = AESSIV(key)
encrypted = cipher.seal(plaintext, associated_data)
  • Whether the cryptographic constructions (AES-SIV, AES-PMAC-SIV, STREAM) have been independently audited or validated since the last release in 2017-12-25.
  • Current compatibility with modern Python versions and whether the package installs without build errors on current systems.
  • Whether interoperability with other Miscreant implementations (Go, Rust, JavaScript, Ruby, C#) is maintained across versions.
  • Specific key size requirements and parameter constraints for the cipher implementations.
Same gist for agents: .md · .json

What it is and what it does

Miscreant is a Python library implementing misuse-resistant authenticated encryption schemes designed to remain secure even when cryptographic nonces are accidentally reused—a common failure mode in symmetric encryption. It provides three main constructions: AES-SIV (combining AES-CTR with AES-CMAC), AES-PMAC-SIV (a parallelizable variant using AES-PMAC for better performance), and STREAM (for online/streaming encryption that also defends against reordering and truncation attacks). The library is part of a larger cross-language Miscreant project and is intended for developers who need authenticated encryption for individual messages, encryption keys, message streams, or large files.

The package has no runtime dependencies, making installation straightforward, but it is abandoned—the repository is archived, the last commit was 2019-09-03, and the latest release dates to 2017-12-25. The codebase is marked Pre-Alpha, indicating it was never considered production-ready by its authors. No security vulnerabilities are currently recorded, but the lack of active maintenance means any future issues will not be addressed by the original developers.

Use it for

  • Encrypt sensitive configuration files or encryption keys where nonce reuse must not compromise security.
  • Implement streaming encryption for large files or network streams with built-in protection against message reordering.
  • Build cross-language cryptographic systems using the interoperable Miscreant implementations across Go, Rust, JavaScript, Ruby, or C#.
  • Wrap encryption keys in a deterministic, authenticated manner as an alternative to traditional key-wrapping schemes.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No.

The package is abandoned (last release 2017-12-25, repository archived, no commits since 2019-09-03) and marked Pre-Alpha. While the cryptographic constructions are theoretically sound and no known vulnerabilities exist, the lack of active maintenance means security issues and compatibility problems will not be addressed. Use only if maintaining legacy code already depending on it.

Install

miscreant on PyPI

Before you install

High install friction with no runtime dependencies. The package is abandoned—last commit was 2019-09-03 and latest release was 2017-12-25. Repository is archived. Pre-Alpha status signals incomplete development.

Package is abandoned with no active maintenance; security issues will not be addressed by the original developers.

License in practice

MIT license permits commercial and private use with minimal restrictions, though the abandoned status means no ongoing legal or security updates from maintainers.

Quickstart

pip install miscreant

from miscreant import AESSIV

cipher = AESSIV(key)
encrypted = cipher.seal(plaintext, associated_data)

Verify before relying

  • Whether the cryptographic constructions (AES-SIV, AES-PMAC-SIV, STREAM) have been independently audited or validated since the last release in 2017-12-25.
  • Current compatibility with modern Python versions and whether the package installs without build errors on current systems.
  • Whether interoperability with other Miscreant implementations (Go, Rust, JavaScript, Ruby, C#) is maintained across versions.
  • Specific key size requirements and parameter constraints for the cipher implementations.

Package facts

LicenseMIT license permissive
Python supportNot specified
Install frictionHigh. Source build required
Runtime dependenciesNone
MaintenanceAbandoned 3,154 days since the last release
Last repo commit repository archived
First released
Downloads1,278,707 / month, #4,120 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 2 - Pre-AlphaIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: English

Evidence: miscreant-0.3.0.tar.gz

Tags

Capabilities
authenticated encryption libraryAES-SIV implementationnonce reuse resistant encryptionsymmetric encryption misuse resistantAES-PMAC-SIV cipherstreaming authenticated encryptioncryptographic key wrapping
Topics
abandonedcryptographyauthenticated-encryption
PyPI keywords
cryptography

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “authenticated encryption library”

  • miscreantProvides misuse-resistant authenticated encryption using AES-SIV,…
  • fernetA pure Python implementation of the Fernet symmetric encryption…
  • pyhpkePyHPKE implements HPKE (Hybrid Public Key Encryption) as defined in…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also crypto · snitun · tink · py3rijndael · chacha20poly1305-reuseable · pyaes · aes-pkcs5 · ff3 · django-cryptography-django5 · pyAesCrypt