Nightmare Obfuscator is a defensive IP-protection tool for controlled collaboration, built and maintained by CDLI.ai. It creates a working obfuscated copy of a Rust project while the owner keeps the original source. Each output includes a locked metadata vault with checksums, configuration metadata, owner/project metadata, and an integrity signature.
V1 is intentionally narrow:
- Rust source support only.
- Python, JavaScript, TypeScript, Go, C, C++, and Java are roadmap-only.
- One-way obfuscation; the original repo remains the source of truth.
- No runtime key requirement for collaborators.
- No deobfuscation or encrypted original-source recovery promise.
- String encryption is disabled by default and must be enabled explicitly after fixture/build-parity checks.
Install the latest main build from source:
cargo install --git https://github.com/cdliai/nightmare-obfuscatorOr download a packaged binary and its .sha256 from a tagged
GitHub Release.
For local development from a checkout:
cargo install --path .
# or build a release binary without installing
cargo build --releaseCreate a reusable run contract:
nightmare init \
--source ./my-rust-project \
--output ./partner-drop \
--owner CDLI \
--project my-rust-project \
--yesRun the contract and emit machine-readable stage results:
nightmare run ./nightmare.toml --jsonVerify an obfuscated output:
nightmare verify ./partner-dropOpen the CDLI.ai terminal shell when attached to a terminal:
nightmare
# or render the entry screen without interaction
nightmare tui --previewThe shell starts with a CDLI-branded entry screen for Public Login and Account
Login. Public Login opens the local obfuscation shell backed by the same
nightmare.toml run contract. Account Login accepts an account name and
password surface for the future hosted plan, but rejects locally until the
backend is connected.
Use nightmare init --instant for the reduced-motion terminal banner. Running
nightmare init --config ./nightmare.toml against an existing config edits only
the values supplied by flags and keeps the rest of the run contract intact.
Use nightmare init --run to save the config and immediately run obfuscation
through the same staged contract.
Use an owner-controlled Ed25519 signing seed when provenance identity matters:
nightmare signing public-key --signing-key ./nightmare-signing.key
nightmare verify ./partner-drop --trusted-public-key <base64-public-key>The signing key file contains a base64-encoded 32-byte seed. The manifest stores only the public verification key.
Legacy scriptable commands remain supported:
nightmare obfuscate ./my-rust-project --select src/critical
nightmare vault ./my-rust-project-obfsExperimental agent planning is available as a thin surface over the same run contract:
nightmare gate github \
--repo https://github.com/owner/repo \
--ref <40-character-commit-sha> \
--config ./nightmare.toml \
--jsonBy default, Nightmare copies the entire input project so build files, assets, and
configuration remain present. If no --select values are provided, all supported
Rust source files are obfuscated. If --select is provided, only matching files
or directories are obfuscated and unselected files are copied byte-for-byte.
The canonical run contract is documented in
docs/run-contract.md. It wraps source/output paths,
owner/project metadata, selected paths, ignores, profile/intensity, feature
toggles, metadata verification, and build/smoke policy. nightmare run --json
separates obfuscation, metadata verification, and build/smoke checks so CI and
agents do not overclaim safety.
Language policy is documented in
docs/language-support.md. Non-Rust files are
copied as opaque assets in V1.
The default ignore set excludes .git, target, dependency/vendor folders, and
.nightmare. Additional --ignore <pattern> values are matched against relative
paths.
The output metadata lives at:
.nightmare/manifest.json
.nightmare/signature
cargo fmt --check
cargo clippy --workspace --all-targets -- -D warnings
cargo test --workspaceFixture acceptance tests are under fixtures/ and tests/acceptance.rs.
This open-source core covers protecting a single Rust drop locally. Rolling controlled source-sharing out across an organization — hosted accounts, policy and governance, coverage beyond Rust, and integration with the toolchains and agent harnesses you already run — is what CDLI delivers on the commercial side. Independent of the languages and tools in your stack, reach us at CDLI.ai.
main is the stable/release branch and dev is the active integration branch.
CDLI.ai maintainers own repository governance through CODEOWNERS, security
reporting, and review gates.
Licensed under either MIT or Apache-2.0, at your option.