$npx skillfedfor your agent

pypickle

pypickle is a Python library to save and load variables in pickle files.

With conditionsPyPI UtilitiesReleased Aug 202694.3K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pypickle-2.0.2-py3-none-any.whl
v2.0.2 · released 2026-08-13 · Python >=3

Yes, if you load pickle files from any source you don't fully control. The validation layer adds meaningful protection against a real pickle deserialization threat without breaking standard workflows. No security vulnerabilities on record, low friction, and active maintenance. Skip it only if you never deserialize untrusted pickles or have already implemented equivalent validation.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Low install friction with no runtime dependencies.
  • Actively maintained as of 2026-08-13 with recent release history.

License · maintenance · safety

MIT (permissive) — MIT license permits free use, modification, and distribution with minimal restrictions.

last release 2026-08-13 (1 days) · last repo commit 2026-08-13 · 4 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 94,268 downloads/mo, #13,336 on PyPI

Verify before relying

pip install pypickle

import pypickle

# Save data
data = [1, 2, 3, 4, 5]
pypickle.save('test.pkl', data)

# Load data with validation
loaded = pypickle.load('test.pkl')
  • Whether the twenty high-risk modules listed in documentation are sufficient for typical threat models
  • Performance overhead of validation checks compared to standard pickle
  • Compatibility of pickles created by pypickle with standard pickle.load()
Same gist for agents: .md · .json

What it is and what it does

pypickle is a wrapper around Python's pickle module that adds security-first validation before loading serialized data. It classifies modules as high-risk (like `os`, `sys`) and blocks them by default unless explicitly allowed, preventing arbitrary code execution from untrusted pickle files. The library provides `save()` and `load()` functions alongside utility methods to check critical filesystem paths and identify risky modules within a pickle.

The package targets developers who need to persist Python objects—models, session data, configuration—but want protection against pickle deserialization exploits. It requires Python 3+ and has no external dependencies, making it a lightweight drop-in for projects already using pickle.

Use it for

  • Loading pickled machine learning models from untrusted sources while blocking dangerous module imports
  • Saving application state or cached data with filesystem safety checks to prevent overwrites to system paths
  • Validating pickle files before processing in data pipelines to catch potentially malicious payloads
  • Sharing serialized Python objects between services with explicit module whitelisting for security

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you load pickle files from any source you don't fully control.

The validation layer adds meaningful protection against a real pickle deserialization threat without breaking standard workflows. No security vulnerabilities on record, low friction, and active maintenance. Skip it only if you never deserialize untrusted pickles or have already implemented equivalent validation.

Install

pypickle on PyPI

Before you install

Low install friction with no runtime dependencies. Actively maintained as of 2026-08-13 with recent release history.

License in practice

MIT license permits free use, modification, and distribution with minimal restrictions.

Quickstart

pip install pypickle

import pypickle

# Save data
data = [1, 2, 3, 4, 5]
pypickle.save('test.pkl', data)

# Load data with validation
loaded = pypickle.load('test.pkl')

Verify before relying

  • Whether the twenty high-risk modules listed in documentation are sufficient for typical threat models
  • Performance overhead of validation checks compared to standard pickle
  • Compatibility of pickles created by pypickle with standard pickle.load()

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 1 days since the last release
Last repo commit
First released
Downloads94,268 / month, #13,336 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Intended Audience :: EducationIntended Audience :: Science/ResearchOperating System :: MacOSOperating System :: Microsoft :: WindowsOperating System :: OS IndependentOperating System :: UnixProgramming Language :: Python :: 3

Evidence: pypickle-2.0.2-py3-none-any.whl

Tags

Capabilities
pickle serialization with validationsafe pickle loadingpython data persistencesecure pickle wrapperpickle file safety checks
Topics
securityserializationdata-persistence
PyPI keywords
pythonpicklesaveloadserializationdeserializationdatavariables

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “pickle serialization with validation”

  • pypicklepypickle wraps Python's pickle module to save and load serialized…
  • zodbpickleProvides a ZODB-compatible pickle interface that handles…
  • pickle5Backports the pickle 5 protocol (PEP 574) and related pickle module…

Give your agent the search over MCP, or paste the wish link into any chat.

More Utilities packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
charset-normalizer Worth it
PyPI · Utilities · released Aug 2026

Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.

permissive licensepure Python · 3.7+
1.7Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
Pygments Worth it
PyPI · Utilities · released Mar 2026

Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.

Install it if you need to display or transform source code.

BSD-2-Clausepure Python · 3.9+
1.3Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo

See also picklescan · cloudpickle · fickling · django-picklefield · jsonpickle · skops · compress-pickle · colourmap · srsly