quantakrypto pqc-tools

Scan code for quantum-vulnerable cryptography and get NIST post-quantum migration guidance.

Should I use this

Quality & Safety

A
Description quality
96%
Schema completeness
91%
Naming quality
87%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~2,603Tokens (tool definitions)
~2.0 KBTypical response size
Significant attention impact (2.03% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "pqc-tools": {
      "command": "npx",
      "args": [
        "@quantakrypto/mcp"
      ]
    }
  }
}

Runnable packages

npm@quantakrypto/mcp0.5.2stdio

Remote endpoints

https://mcp.quantakrypto.com/mcpstreamable-http

What it can do

Tool inventory

Tools (11)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
⚪apply_triage(findings, verdicts)

Deterministically attach your triage verdicts to their findings and re-sort by exposure (highest first). Never suppresses. Pass the same 'findings' array you triaged plus a 'verdicts' array of { fingerprint, exposureScore, priority, rationale }.

Input Schema

{
  "type": "object",
  "properties": {
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "description": "A single finding from `scan_path --format json`.",
        "properties": {
          "ruleId": {
            "type": "string",
            "description": "Stable rule id, e.g. \"rsa-keygen\"."
          },
          "title": {
            "type": "string"
          },
          "category": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "description": "critical | high | medium | low | info."
          },
          "confidence": {
            "type": "string"
          },
          "algorithm": {
            "type": "string",
            "description": "Classical algorithm family, when applicable."
          },
          "hndl": {
            "type": "boolean",
            "description": "Exposed to harvest-now-decrypt-later."
          },
          "message": {
            "type": "string"
          },
          "remediation": {
            "type": "string"
          },
          "cwe": {
            "type": "string",
            "description": "e.g. \"CWE-327\"."
          },
          "location": {
            "type": "object",
            "description": "Where the finding is.",
            "properties": {
              "file": {
                "type": "string"
              },
              "line": {
                "type": "number"
              }
            },
            "required": [
              "file"
            ]
          }
        },
        "required": [
          "ruleId",
          "location"
        ]
      },
      "description": "The findings that were triaged."
    },
    "verdicts": {
      "type": "array",
      "items": {
        "type": "object",
        "description": "A triage verdict for one finding.",
        "properties": {
          "fingerprint": {
            "type": "string",
            "description": "Fingerprint of the finding this verdict applies to."
          },
          "exposureScore": {
            "type": "number",
            "description": "Real-world exposure (higher = more exposed)."
          },
          "priority": {
            "type": "string",
            "enum": [
              "now",
              "soon",
              "later"
            ]
          },
          "rationale": {
            "type": "string",
            "description": "Why this exposure score / priority."
          }
        },
        "required": [
          "fingerprint",
          "exposureScore",
          "priority",
          "rationale"
        ]
      },
      "description": "One verdict per finding, keyed by fingerprint."
    }
  },
  "required": [
    "findings",
    "verdicts"
  ],
  "additionalProperties": false
}
🟡apply_verified_patch(finding, originalContent, newContent)

Deterministically VERIFY a proposed fix before writing it — runs the same patch-policy + verify_fix + blast-radius gates as `qremediate` (offline, no key, no network). Give the finding, the file's current content, and your proposed FULL corrected content; returns approved:true only if the patch is in-policy, clears the finding, adds no new finding, introduces no network/exec sink, and is bounded in size. This does NOT write the file — you write it, only when approved, and never auto-merge.

Input Schema

{
  "type": "object",
  "properties": {
    "finding": {
      "type": "object",
      "description": "The scan finding being fixed (needs a string ruleId and location.file)."
    },
    "originalContent": {
      "type": "string",
      "description": "The file's current full content."
    },
    "newContent": {
      "type": "string",
      "description": "Your proposed full corrected file content."
    }
  },
  "required": [
    "finding",
    "originalContent",
    "newContent"
  ],
  "additionalProperties": false
}
🟢check_dependency(name, ecosystem)

Check whether a package is in quantakrypto's known quantum-vulnerable dependency database (the classical crypto it exposes). Provide 'name' and optional 'ecosystem' (default npm).

Input Schema

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "description": "Package name to look up (e.g. 'node-forge', 'jsonwebtoken')."
    },
    "ecosystem": {
      "type": "string",
      "description": "Package ecosystem. Default: npm."
    }
  },
  "required": [
    "name"
  ],
  "additionalProperties": false
}
🟡explain_finding(ruleId, algorithm)

Explain a quantakrypto finding and its post-quantum remediation. Provide a ruleId (e.g. 'forge-rsa-keygen', 'elliptic-ec', 'node-rsa', 'pem-ec-private-key') and/or an algorithm (e.g. 'RSA', 'ECDSA'). The ruleId is resolved against the core detector set, so library and config rules explain correctly.

Input Schema

{
  "type": "object",
  "properties": {
    "ruleId": {
      "type": "string",
      "description": "The finding's rule id, matching a detector id prefix."
    },
    "algorithm": {
      "type": "string",
      "description": "The classical algorithm family involved (e.g. RSA, ECDH, ECDSA)."
    }
  },
  "additionalProperties": false
}
🟡get_fix_examples(algorithm, ruleId)

Return before/after code examples for migrating a classical algorithm to a post-quantum / hybrid replacement. Provide an 'algorithm' (RSA, ECDH, ECDSA, …) or a 'ruleId' from a finding.

Input Schema

{
  "type": "object",
  "properties": {
    "algorithm": {
      "type": "string",
      "description": "Classical algorithm family to migrate away from."
    },
    "ruleId": {
      "type": "string",
      "description": "A finding's ruleId (resolved to its algorithm)."
    }
  },
  "additionalProperties": false
}
🟢list_rules

List the quantakrypto detector catalog: every detector id and what it looks for.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🔴remediate_findings(findings)

Produce a deterministic remediation REQUEST bundle (rubric + fix schema + per-finding metadata + fingerprints) for YOU (the host agent) to fix. This tool calls no model and needs no key. For each finding, propose the corrected FULL file content, then VERIFY with verify_fix and keep only fixes that clear the finding. Never touch files with secrets; never auto-merge. Pass 'findings' from scan_path --format json.

Input Schema

{
  "type": "object",
  "properties": {
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "description": "A single finding from `scan_path --format json`.",
        "properties": {
          "ruleId": {
            "type": "string",
            "description": "Stable rule id, e.g. \"rsa-keygen\"."
          },
          "title": {
            "type": "string"
          },
          "category": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "description": "critical | high | medium | low | info."
          },
          "confidence": {
            "type": "string"
          },
          "algorithm": {
            "type": "string",
            "description": "Classical algorithm family, when applicable."
          },
          "hndl": {
            "type": "boolean",
            "description": "Exposed to harvest-now-decrypt-later."
          },
          "message": {
            "type": "string"
          },
          "remediation": {
            "type": "string"
          },
          "cwe": {
            "type": "string",
            "description": "e.g. \"CWE-327\"."
          },
          "location": {
            "type": "object",
            "description": "Where the finding is.",
            "properties": {
              "file": {
                "type": "string"
              },
              "line": {
                "type": "number"
              }
            },
            "required": [
              "file"
            ]
          }
        },
        "required": [
          "ruleId",
          "location"
        ]
      },
      "description": "Findings from a scan's JSON output."
    }
  },
  "required": [
    "findings"
  ],
  "additionalProperties": false
}
🟡score_delta(before, after)

Compute the readiness-score and HNDL change between two finding sets (e.g. before and after a migration). Pass 'before' and 'after' as arrays of findings from scan_path --format json.

Input Schema

{
  "type": "object",
  "properties": {
    "before": {
      "type": "array",
      "items": {
        "type": "object",
        "description": "A single finding from `scan_path --format json`.",
        "properties": {
          "ruleId": {
            "type": "string",
            "description": "Stable rule id, e.g. \"rsa-keygen\"."
          },
          "title": {
            "type": "string"
          },
          "category": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "description": "critical | high | medium | low | info."
          },
          "confidence": {
            "type": "string"
          },
          "algorithm": {
            "type": "string",
            "description": "Classical algorithm family, when applicable."
          },
          "hndl": {
            "type": "boolean",
            "description": "Exposed to harvest-now-decrypt-later."
          },
          "message": {
            "type": "string"
          },
          "remediation": {
            "type": "string"
          },
          "cwe": {
            "type": "string",
            "description": "e.g. \"CWE-327\"."
          },
          "location": {
            "type": "object",
            "description": "Where the finding is.",
            "properties": {
              "file": {
                "type": "string"
              },
              "line": {
                "type": "number"
              }
            },
            "required": [
              "file"
            ]
          }
        },
        "required": [
          "ruleId",
          "location"
        ]
      },
      "description": "Findings before the change (from a scan's JSON findings)."
    },
    "after": {
      "type": "array",
      "items": {
        "type": "object",
        "description": "A single finding from `scan_path --format json`.",
        "properties": {
          "ruleId": {
            "type": "string",
            "description": "Stable rule id, e.g. \"rsa-keygen\"."
          },
          "title": {
            "type": "string"
          },
          "category": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "description": "critical | high | medium | low | info."
          },
          "confidence": {
            "type": "string"
          },
          "algorithm": {
            "type": "string",
            "description": "Classical algorithm family, when applicable."
          },
          "hndl": {
            "type": "boolean",
            "description": "Exposed to harvest-now-decrypt-later."
          },
          "message": {
            "type": "string"
          },
          "remediation": {
            "type": "string"
          },
          "cwe": {
            "type": "string",
            "description": "e.g. \"CWE-327\"."
          },
          "location": {
            "type": "object",
            "description": "Where the finding is.",
            "properties": {
              "file": {
                "type": "string"
              },
              "line": {
                "type": "number"
              }
            },
            "required": [
              "file"
            ]
          }
        },
        "required": [
          "ruleId",
          "location"
        ]
      },
      "description": "Findings after the change."
    }
  },
  "required": [
    "before",
    "after"
  ],
  "additionalProperties": false
}
🟡suggest_hybrid(algorithm, context, tier)

Recommend a post-quantum / hybrid migration. Provide an 'algorithm' (e.g. RSA, ECDH, ECDSA) or free-text 'context' describing the usage. Set 'tier' to 'category-5' for CNSA 2.0 / national-security systems.

Input Schema

{
  "type": "object",
  "properties": {
    "algorithm": {
      "type": "string",
      "description": "Classical algorithm family to migrate away from."
    },
    "context": {
      "type": "string",
      "description": "Free-text description of the cryptographic usage (used when no algorithm is given)."
    },
    "tier": {
      "type": "string",
      "enum": [
        "category-3",
        "category-5"
      ],
      "description": "Security tier: 'category-3' (default, commercial — ML-KEM-768 / ML-DSA-65) or 'category-5' (CNSA 2.0 / NSS, long-lived secrets — ML-KEM-1024 / ML-DSA-87)."
    }
  },
  "additionalProperties": false
}
⚪triage_findings(findings)

Produce a deterministic triage REQUEST bundle (rubric + verdict schema + per-finding metadata) for YOU (the host agent) to reason over. This tool does NOT call any model and needs no API key. Assess each finding's real-world exposure, then call apply_triage with your verdicts. Pass 'findings' as an array from scan_path --format json.

Input Schema

{
  "type": "object",
  "properties": {
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "description": "A single finding from `scan_path --format json`.",
        "properties": {
          "ruleId": {
            "type": "string",
            "description": "Stable rule id, e.g. \"rsa-keygen\"."
          },
          "title": {
            "type": "string"
          },
          "category": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "description": "critical | high | medium | low | info."
          },
          "confidence": {
            "type": "string"
          },
          "algorithm": {
            "type": "string",
            "description": "Classical algorithm family, when applicable."
          },
          "hndl": {
            "type": "boolean",
            "description": "Exposed to harvest-now-decrypt-later."
          },
          "message": {
            "type": "string"
          },
          "remediation": {
            "type": "string"
          },
          "cwe": {
            "type": "string",
            "description": "e.g. \"CWE-327\"."
          },
          "location": {
            "type": "object",
            "description": "Where the finding is.",
            "properties": {
              "file": {
                "type": "string"
              },
              "line": {
                "type": "number"
              }
            },
            "required": [
              "file"
            ]
          }
        },
        "required": [
          "ruleId",
          "location"
        ]
      },
      "description": "Findings from a scan's JSON output."
    }
  },
  "required": [
    "findings"
  ],
  "additionalProperties": false
}
🟡verify_fix(code, language, filename)

Run the quantakrypto detectors over a code snippet (NOT the filesystem) and report any classical crypto that remains. Use this to confirm an edit actually removed the quantum-vulnerable usage. Provide 'code' plus a 'language' or 'filename'.

Input Schema

{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "The source code to check."
    },
    "language": {
      "type": "string",
      "description": "Language of the code (js, ts, python, go, java, csharp, rust, ruby, c, …)."
    },
    "filename": {
      "type": "string",
      "description": "Optional filename; its extension selects the detectors (overrides 'language')."
    }
  },
  "required": [
    "code"
  ],
  "additionalProperties": false
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded11 tools
verifiedversion not recorded11 tools