$npx skillfedfor your agent

shellescape

Shell escape a string to safely use it as a token in a shell command (backport of cPython shlex.quote for Python versions 2.x & < 3.3)

With conditionsPyPI UtilitiesReleased Jan 20201.4M downloads / moMIT licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — shellescape-3.8.1-py2.py3-none-any.whl
v3.8.1 · released 2020-01-25

Yes, if you are maintaining Python 2 or Python 3 < 3.3 code that needs to safely escape shell arguments. For modern projects targeting Python 3.3 and later, use the built-in `shlex.quote()` instead. The package is stable and has no known vulnerabilities, but its abandonment means it will not receive updates if shell-escaping semantics change.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Low friction: pure Python wheel with no runtime dependencies.
  • Maintenance is abandoned—last release was 2020-01-25 and no commits since 2021-04-29—but marked Production/Stable with no known vulnerabilities.

License · maintenance · safety

MIT license (permissive) — MIT license (permissive). No restrictions on commercial or private use; you may modify and distribute freely under the same license terms.

last release 2020-01-25 (2393 days) · last repo commit 2021-04-29 · 16 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,420,056 downloads/mo, #3,926 on PyPI

Verify before relying

from shellescape import quote

filename = "somefile; rm -rf ~"
escaped = quote(filename)
command = 'ls -l {}'.format(escaped)
print(command)  # ls -l 'somefile; rm -rf ~'
  • Whether the backport remains necessary now that Python 2 is end-of-life and Python versions < 3.3 are rarely deployed
  • Whether abandonment affects security posture if shell-escaping semantics change in future Python versions
  • Current compatibility and testing status across modern Python releases
Same gist for agents: .md · .json

What it is and what it does

shellescape is a single-function library that wraps Python strings in shell-safe quoting so they can be safely embedded in shell command lines. It backports `shlex.quote()` to Python 2.x and Python versions before 3.3, making it accessible to projects that need to support those legacy runtimes. The function prevents shell injection attacks by properly escaping metacharacters—turning a dangerous string like `somefile; rm -rf ~` into a quoted token that a shell will treat as literal text rather than as multiple commands.

The package has zero runtime dependencies and installs as a pure Python wheel. It is marked Production/Stable but has been abandoned since 2020; the last commit was in 2021-04-29. No known security vulnerabilities have been reported. With monthly downloads in the top tier, it remains widely used, though most modern projects should consider whether they still need to support the Python versions this backport targets.

Use it for

  • Building shell commands dynamically from untrusted or user-supplied filenames or arguments in Python 2 or early Python 3 codebases.
  • Preventing shell injection when passing arguments to subprocess calls that invoke a shell.
  • Safely constructing remote SSH commands by quoting local arguments before embedding them in the remote command string.
  • Escaping special characters in filenames or paths before passing them to shell utilities via Python scripts on legacy Python versions.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are maintaining Python 2 or Python 3 < 3.3 code that needs to safely escape shell arguments.

For modern projects targeting Python 3.3 and later, use the built-in `shlex.quote()` instead. The package is stable and has no known vulnerabilities, but its abandonment means it will not receive updates if shell-escaping semantics change.

Install

shellescape on PyPI

Before you install

Low friction: pure Python wheel with no runtime dependencies. Maintenance is abandoned—last release was 2020-01-25 and no commits since 2021-04-29—but marked Production/Stable with no known vulnerabilities.

License in practice

MIT license (permissive). No restrictions on commercial or private use; you may modify and distribute freely under the same license terms.

Quickstart

from shellescape import quote

filename = "somefile; rm -rf ~"
escaped = quote(filename)
command = 'ls -l {}'.format(escaped)
print(command)  # ls -l 'somefile; rm -rf ~'

Verify before relying

  • Whether the backport remains necessary now that Python 2 is end-of-life and Python versions < 3.3 are rarely deployed
  • Whether abandonment affects security posture if shell-escaping semantics change in future Python versions
  • Current compatibility and testing status across modern Python releases

Package facts

LicenseMIT license permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceAbandoned 2,393 days since the last release
Last repo commit
First released
Downloads1,420,056 / month, #3,926 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: POSIXOperating System :: UnixProgramming Language :: PythonProgramming Language :: Python :: 2Programming Language :: Python :: 3

Evidence: shellescape-3.8.1-py2.py3-none-any.whl

Tags

Capabilities
shell escape string safelyshell quote command argumentprevent shell injectionshlex quote backportescape shell metacharacterssafe subprocess command buildingshell command injection prevention
Topics
shell-safetylegacy-python
PyPI keywords
shellquoteescapebackportcommand linecommandsubprocess

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “shell escape string safely”

  • shellescapeProvides a `quote()` function that shell-escapes Python strings to…
  • MarkupSafeMarkupSafe provides a text object that escapes special characters so…
  • oslexProvides a unified API for shell argument quoting and parsing that…

Give your agent the search over MCP, or paste the wish link into any chat.

More Utilities packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
charset-normalizer Worth it
PyPI · Utilities · released Aug 2026

Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.

permissive licensepure Python · 3.7+
1.7Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
Pygments Worth it
PyPI · Utilities · released Mar 2026

Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.

Install it if you need to display or transform source code.

BSD-2-Clausepure Python · 3.9+
1.3Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo

See also oslex · bashlex · MarkupSafe · subprocess.run · mslex · subprocrunner · bash · pygnuutils · plumbum · future-fstrings