quantakrypto pqc-tools
Scan code for quantum-vulnerable cryptography and get NIST post-quantum migration guidance.
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"pqc-tools": {
"command": "npx",
"args": [
"@quantakrypto/mcp"
]
}
}
}Paquetes ejecutables
0.5.2stdioPuntos de conexión remotos
https://mcp.quantakrypto.com/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (11)
⚪apply_triage(findings, verdicts)
Deterministically attach your triage verdicts to their findings and re-sort by exposure (highest first). Never suppresses. Pass the same 'findings' array you triaged plus a 'verdicts' array of { fingerprint, exposureScore, priority, rationale }.
Esquema de entrada
{
"type": "object",
"properties": {
"findings": {
"type": "array",
"items": {
"type": "object",
"description": "A single finding from `scan_path --format json`.",
"properties": {
"ruleId": {
"type": "string",
"description": "Stable rule id, e.g. \"rsa-keygen\"."
},
"title": {
"type": "string"
},
"category": {
"type": "string"
},
"severity": {
"type": "string",
"description": "critical | high | medium | low | info."
},
"confidence": {
"type": "string"
},
"algorithm": {
"type": "string",
"description": "Classical algorithm family, when applicable."
},
"hndl": {
"type": "boolean",
"description": "Exposed to harvest-now-decrypt-later."
},
"message": {
"type": "string"
},
"remediation": {
"type": "string"
},
"cwe": {
"type": "string",
"description": "e.g. \"CWE-327\"."
},
"location": {
"type": "object",
"description": "Where the finding is.",
"properties": {
"file": {
"type": "string"
},
"line": {
"type": "number"
}
},
"required": [
"file"
]
}
},
"required": [
"ruleId",
"location"
]
},
"description": "The findings that were triaged."
},
"verdicts": {
"type": "array",
"items": {
"type": "object",
"description": "A triage verdict for one finding.",
"properties": {
"fingerprint": {
"type": "string",
"description": "Fingerprint of the finding this verdict applies to."
},
"exposureScore": {
"type": "number",
"description": "Real-world exposure (higher = more exposed)."
},
"priority": {
"type": "string",
"enum": [
"now",
"soon",
"later"
]
},
"rationale": {
"type": "string",
"description": "Why this exposure score / priority."
}
},
"required": [
"fingerprint",
"exposureScore",
"priority",
"rationale"
]
},
"description": "One verdict per finding, keyed by fingerprint."
}
},
"required": [
"findings",
"verdicts"
],
"additionalProperties": false
}🟡apply_verified_patch(finding, originalContent, newContent)
Deterministically VERIFY a proposed fix before writing it — runs the same patch-policy + verify_fix + blast-radius gates as `qremediate` (offline, no key, no network). Give the finding, the file's current content, and your proposed FULL corrected content; returns approved:true only if the patch is in-policy, clears the finding, adds no new finding, introduces no network/exec sink, and is bounded in size. This does NOT write the file — you write it, only when approved, and never auto-merge.
Esquema de entrada
{
"type": "object",
"properties": {
"finding": {
"type": "object",
"description": "The scan finding being fixed (needs a string ruleId and location.file)."
},
"originalContent": {
"type": "string",
"description": "The file's current full content."
},
"newContent": {
"type": "string",
"description": "Your proposed full corrected file content."
}
},
"required": [
"finding",
"originalContent",
"newContent"
],
"additionalProperties": false
}🟢check_dependency(name, ecosystem)
Check whether a package is in quantakrypto's known quantum-vulnerable dependency database (the classical crypto it exposes). Provide 'name' and optional 'ecosystem' (default npm).
Esquema de entrada
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Package name to look up (e.g. 'node-forge', 'jsonwebtoken')."
},
"ecosystem": {
"type": "string",
"description": "Package ecosystem. Default: npm."
}
},
"required": [
"name"
],
"additionalProperties": false
}🟡explain_finding(ruleId, algorithm)
Explain a quantakrypto finding and its post-quantum remediation. Provide a ruleId (e.g. 'forge-rsa-keygen', 'elliptic-ec', 'node-rsa', 'pem-ec-private-key') and/or an algorithm (e.g. 'RSA', 'ECDSA'). The ruleId is resolved against the core detector set, so library and config rules explain correctly.
Esquema de entrada
{
"type": "object",
"properties": {
"ruleId": {
"type": "string",
"description": "The finding's rule id, matching a detector id prefix."
},
"algorithm": {
"type": "string",
"description": "The classical algorithm family involved (e.g. RSA, ECDH, ECDSA)."
}
},
"additionalProperties": false
}🟡get_fix_examples(algorithm, ruleId)
Return before/after code examples for migrating a classical algorithm to a post-quantum / hybrid replacement. Provide an 'algorithm' (RSA, ECDH, ECDSA, …) or a 'ruleId' from a finding.
Esquema de entrada
{
"type": "object",
"properties": {
"algorithm": {
"type": "string",
"description": "Classical algorithm family to migrate away from."
},
"ruleId": {
"type": "string",
"description": "A finding's ruleId (resolved to its algorithm)."
}
},
"additionalProperties": false
}🟢list_rules
List the quantakrypto detector catalog: every detector id and what it looks for.
Esquema de entrada
{
"type": "object",
"properties": {},
"additionalProperties": false
}🔴remediate_findings(findings)
Produce a deterministic remediation REQUEST bundle (rubric + fix schema + per-finding metadata + fingerprints) for YOU (the host agent) to fix. This tool calls no model and needs no key. For each finding, propose the corrected FULL file content, then VERIFY with verify_fix and keep only fixes that clear the finding. Never touch files with secrets; never auto-merge. Pass 'findings' from scan_path --format json.
Esquema de entrada
{
"type": "object",
"properties": {
"findings": {
"type": "array",
"items": {
"type": "object",
"description": "A single finding from `scan_path --format json`.",
"properties": {
"ruleId": {
"type": "string",
"description": "Stable rule id, e.g. \"rsa-keygen\"."
},
"title": {
"type": "string"
},
"category": {
"type": "string"
},
"severity": {
"type": "string",
"description": "critical | high | medium | low | info."
},
"confidence": {
"type": "string"
},
"algorithm": {
"type": "string",
"description": "Classical algorithm family, when applicable."
},
"hndl": {
"type": "boolean",
"description": "Exposed to harvest-now-decrypt-later."
},
"message": {
"type": "string"
},
"remediation": {
"type": "string"
},
"cwe": {
"type": "string",
"description": "e.g. \"CWE-327\"."
},
"location": {
"type": "object",
"description": "Where the finding is.",
"properties": {
"file": {
"type": "string"
},
"line": {
"type": "number"
}
},
"required": [
"file"
]
}
},
"required": [
"ruleId",
"location"
]
},
"description": "Findings from a scan's JSON output."
}
},
"required": [
"findings"
],
"additionalProperties": false
}🟡score_delta(before, after)
Compute the readiness-score and HNDL change between two finding sets (e.g. before and after a migration). Pass 'before' and 'after' as arrays of findings from scan_path --format json.
Esquema de entrada
{
"type": "object",
"properties": {
"before": {
"type": "array",
"items": {
"type": "object",
"description": "A single finding from `scan_path --format json`.",
"properties": {
"ruleId": {
"type": "string",
"description": "Stable rule id, e.g. \"rsa-keygen\"."
},
"title": {
"type": "string"
},
"category": {
"type": "string"
},
"severity": {
"type": "string",
"description": "critical | high | medium | low | info."
},
"confidence": {
"type": "string"
},
"algorithm": {
"type": "string",
"description": "Classical algorithm family, when applicable."
},
"hndl": {
"type": "boolean",
"description": "Exposed to harvest-now-decrypt-later."
},
"message": {
"type": "string"
},
"remediation": {
"type": "string"
},
"cwe": {
"type": "string",
"description": "e.g. \"CWE-327\"."
},
"location": {
"type": "object",
"description": "Where the finding is.",
"properties": {
"file": {
"type": "string"
},
"line": {
"type": "number"
}
},
"required": [
"file"
]
}
},
"required": [
"ruleId",
"location"
]
},
"description": "Findings before the change (from a scan's JSON findings)."
},
"after": {
"type": "array",
"items": {
"type": "object",
"description": "A single finding from `scan_path --format json`.",
"properties": {
"ruleId": {
"type": "string",
"description": "Stable rule id, e.g. \"rsa-keygen\"."
},
"title": {
"type": "string"
},
"category": {
"type": "string"
},
"severity": {
"type": "string",
"description": "critical | high | medium | low | info."
},
"confidence": {
"type": "string"
},
"algorithm": {
"type": "string",
"description": "Classical algorithm family, when applicable."
},
"hndl": {
"type": "boolean",
"description": "Exposed to harvest-now-decrypt-later."
},
"message": {
"type": "string"
},
"remediation": {
"type": "string"
},
"cwe": {
"type": "string",
"description": "e.g. \"CWE-327\"."
},
"location": {
"type": "object",
"description": "Where the finding is.",
"properties": {
"file": {
"type": "string"
},
"line": {
"type": "number"
}
},
"required": [
"file"
]
}
},
"required": [
"ruleId",
"location"
]
},
"description": "Findings after the change."
}
},
"required": [
"before",
"after"
],
"additionalProperties": false
}🟡suggest_hybrid(algorithm, context, tier)
Recommend a post-quantum / hybrid migration. Provide an 'algorithm' (e.g. RSA, ECDH, ECDSA) or free-text 'context' describing the usage. Set 'tier' to 'category-5' for CNSA 2.0 / national-security systems.
Esquema de entrada
{
"type": "object",
"properties": {
"algorithm": {
"type": "string",
"description": "Classical algorithm family to migrate away from."
},
"context": {
"type": "string",
"description": "Free-text description of the cryptographic usage (used when no algorithm is given)."
},
"tier": {
"type": "string",
"enum": [
"category-3",
"category-5"
],
"description": "Security tier: 'category-3' (default, commercial — ML-KEM-768 / ML-DSA-65) or 'category-5' (CNSA 2.0 / NSS, long-lived secrets — ML-KEM-1024 / ML-DSA-87)."
}
},
"additionalProperties": false
}⚪triage_findings(findings)
Produce a deterministic triage REQUEST bundle (rubric + verdict schema + per-finding metadata) for YOU (the host agent) to reason over. This tool does NOT call any model and needs no API key. Assess each finding's real-world exposure, then call apply_triage with your verdicts. Pass 'findings' as an array from scan_path --format json.
Esquema de entrada
{
"type": "object",
"properties": {
"findings": {
"type": "array",
"items": {
"type": "object",
"description": "A single finding from `scan_path --format json`.",
"properties": {
"ruleId": {
"type": "string",
"description": "Stable rule id, e.g. \"rsa-keygen\"."
},
"title": {
"type": "string"
},
"category": {
"type": "string"
},
"severity": {
"type": "string",
"description": "critical | high | medium | low | info."
},
"confidence": {
"type": "string"
},
"algorithm": {
"type": "string",
"description": "Classical algorithm family, when applicable."
},
"hndl": {
"type": "boolean",
"description": "Exposed to harvest-now-decrypt-later."
},
"message": {
"type": "string"
},
"remediation": {
"type": "string"
},
"cwe": {
"type": "string",
"description": "e.g. \"CWE-327\"."
},
"location": {
"type": "object",
"description": "Where the finding is.",
"properties": {
"file": {
"type": "string"
},
"line": {
"type": "number"
}
},
"required": [
"file"
]
}
},
"required": [
"ruleId",
"location"
]
},
"description": "Findings from a scan's JSON output."
}
},
"required": [
"findings"
],
"additionalProperties": false
}🟡verify_fix(code, language, filename)
Run the quantakrypto detectors over a code snippet (NOT the filesystem) and report any classical crypto that remains. Use this to confirm an edit actually removed the quantum-vulnerable usage. Provide 'code' plus a 'language' or 'filename'.
Esquema de entrada
{
"type": "object",
"properties": {
"code": {
"type": "string",
"description": "The source code to check."
},
"language": {
"type": "string",
"description": "Language of the code (js, ts, python, go, java, csharp, rust, ruby, c, …)."
},
"filename": {
"type": "string",
"description": "Optional filename; its extension selects the detectors (overrides 'language')."
}
},
"required": [
"code"
],
"additionalProperties": false
}Comunidad
Evidencia