quantakrypto pqc-tools
Scan code for quantum-vulnerable cryptography and get NIST post-quantum migration guidance.
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"pqc-tools": {
"command": "npx",
"args": [
"@quantakrypto/mcp"
]
}
}
}可執行的套件
0.5.2stdio遠端端點
https://mcp.quantakrypto.com/mcpstreamable-http它能做什麼
工具清單
工具(11)
⚪apply_triage(findings, verdicts)
Deterministically attach your triage verdicts to their findings and re-sort by exposure (highest first). Never suppresses. Pass the same 'findings' array you triaged plus a 'verdicts' array of { fingerprint, exposureScore, priority, rationale }.
輸入結構描述
{
"type": "object",
"properties": {
"findings": {
"type": "array",
"items": {
"type": "object",
"description": "A single finding from `scan_path --format json`.",
"properties": {
"ruleId": {
"type": "string",
"description": "Stable rule id, e.g. \"rsa-keygen\"."
},
"title": {
"type": "string"
},
"category": {
"type": "string"
},
"severity": {
"type": "string",
"description": "critical | high | medium | low | info."
},
"confidence": {
"type": "string"
},
"algorithm": {
"type": "string",
"description": "Classical algorithm family, when applicable."
},
"hndl": {
"type": "boolean",
"description": "Exposed to harvest-now-decrypt-later."
},
"message": {
"type": "string"
},
"remediation": {
"type": "string"
},
"cwe": {
"type": "string",
"description": "e.g. \"CWE-327\"."
},
"location": {
"type": "object",
"description": "Where the finding is.",
"properties": {
"file": {
"type": "string"
},
"line": {
"type": "number"
}
},
"required": [
"file"
]
}
},
"required": [
"ruleId",
"location"
]
},
"description": "The findings that were triaged."
},
"verdicts": {
"type": "array",
"items": {
"type": "object",
"description": "A triage verdict for one finding.",
"properties": {
"fingerprint": {
"type": "string",
"description": "Fingerprint of the finding this verdict applies to."
},
"exposureScore": {
"type": "number",
"description": "Real-world exposure (higher = more exposed)."
},
"priority": {
"type": "string",
"enum": [
"now",
"soon",
"later"
]
},
"rationale": {
"type": "string",
"description": "Why this exposure score / priority."
}
},
"required": [
"fingerprint",
"exposureScore",
"priority",
"rationale"
]
},
"description": "One verdict per finding, keyed by fingerprint."
}
},
"required": [
"findings",
"verdicts"
],
"additionalProperties": false
}🟡apply_verified_patch(finding, originalContent, newContent)
Deterministically VERIFY a proposed fix before writing it — runs the same patch-policy + verify_fix + blast-radius gates as `qremediate` (offline, no key, no network). Give the finding, the file's current content, and your proposed FULL corrected content; returns approved:true only if the patch is in-policy, clears the finding, adds no new finding, introduces no network/exec sink, and is bounded in size. This does NOT write the file — you write it, only when approved, and never auto-merge.
輸入結構描述
{
"type": "object",
"properties": {
"finding": {
"type": "object",
"description": "The scan finding being fixed (needs a string ruleId and location.file)."
},
"originalContent": {
"type": "string",
"description": "The file's current full content."
},
"newContent": {
"type": "string",
"description": "Your proposed full corrected file content."
}
},
"required": [
"finding",
"originalContent",
"newContent"
],
"additionalProperties": false
}🟢check_dependency(name, ecosystem)
Check whether a package is in quantakrypto's known quantum-vulnerable dependency database (the classical crypto it exposes). Provide 'name' and optional 'ecosystem' (default npm).
輸入結構描述
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Package name to look up (e.g. 'node-forge', 'jsonwebtoken')."
},
"ecosystem": {
"type": "string",
"description": "Package ecosystem. Default: npm."
}
},
"required": [
"name"
],
"additionalProperties": false
}🟡explain_finding(ruleId, algorithm)
Explain a quantakrypto finding and its post-quantum remediation. Provide a ruleId (e.g. 'forge-rsa-keygen', 'elliptic-ec', 'node-rsa', 'pem-ec-private-key') and/or an algorithm (e.g. 'RSA', 'ECDSA'). The ruleId is resolved against the core detector set, so library and config rules explain correctly.
輸入結構描述
{
"type": "object",
"properties": {
"ruleId": {
"type": "string",
"description": "The finding's rule id, matching a detector id prefix."
},
"algorithm": {
"type": "string",
"description": "The classical algorithm family involved (e.g. RSA, ECDH, ECDSA)."
}
},
"additionalProperties": false
}🟡get_fix_examples(algorithm, ruleId)
Return before/after code examples for migrating a classical algorithm to a post-quantum / hybrid replacement. Provide an 'algorithm' (RSA, ECDH, ECDSA, …) or a 'ruleId' from a finding.
輸入結構描述
{
"type": "object",
"properties": {
"algorithm": {
"type": "string",
"description": "Classical algorithm family to migrate away from."
},
"ruleId": {
"type": "string",
"description": "A finding's ruleId (resolved to its algorithm)."
}
},
"additionalProperties": false
}🟢list_rules
List the quantakrypto detector catalog: every detector id and what it looks for.
輸入結構描述
{
"type": "object",
"properties": {},
"additionalProperties": false
}🔴remediate_findings(findings)
Produce a deterministic remediation REQUEST bundle (rubric + fix schema + per-finding metadata + fingerprints) for YOU (the host agent) to fix. This tool calls no model and needs no key. For each finding, propose the corrected FULL file content, then VERIFY with verify_fix and keep only fixes that clear the finding. Never touch files with secrets; never auto-merge. Pass 'findings' from scan_path --format json.
輸入結構描述
{
"type": "object",
"properties": {
"findings": {
"type": "array",
"items": {
"type": "object",
"description": "A single finding from `scan_path --format json`.",
"properties": {
"ruleId": {
"type": "string",
"description": "Stable rule id, e.g. \"rsa-keygen\"."
},
"title": {
"type": "string"
},
"category": {
"type": "string"
},
"severity": {
"type": "string",
"description": "critical | high | medium | low | info."
},
"confidence": {
"type": "string"
},
"algorithm": {
"type": "string",
"description": "Classical algorithm family, when applicable."
},
"hndl": {
"type": "boolean",
"description": "Exposed to harvest-now-decrypt-later."
},
"message": {
"type": "string"
},
"remediation": {
"type": "string"
},
"cwe": {
"type": "string",
"description": "e.g. \"CWE-327\"."
},
"location": {
"type": "object",
"description": "Where the finding is.",
"properties": {
"file": {
"type": "string"
},
"line": {
"type": "number"
}
},
"required": [
"file"
]
}
},
"required": [
"ruleId",
"location"
]
},
"description": "Findings from a scan's JSON output."
}
},
"required": [
"findings"
],
"additionalProperties": false
}🟡score_delta(before, after)
Compute the readiness-score and HNDL change between two finding sets (e.g. before and after a migration). Pass 'before' and 'after' as arrays of findings from scan_path --format json.
輸入結構描述
{
"type": "object",
"properties": {
"before": {
"type": "array",
"items": {
"type": "object",
"description": "A single finding from `scan_path --format json`.",
"properties": {
"ruleId": {
"type": "string",
"description": "Stable rule id, e.g. \"rsa-keygen\"."
},
"title": {
"type": "string"
},
"category": {
"type": "string"
},
"severity": {
"type": "string",
"description": "critical | high | medium | low | info."
},
"confidence": {
"type": "string"
},
"algorithm": {
"type": "string",
"description": "Classical algorithm family, when applicable."
},
"hndl": {
"type": "boolean",
"description": "Exposed to harvest-now-decrypt-later."
},
"message": {
"type": "string"
},
"remediation": {
"type": "string"
},
"cwe": {
"type": "string",
"description": "e.g. \"CWE-327\"."
},
"location": {
"type": "object",
"description": "Where the finding is.",
"properties": {
"file": {
"type": "string"
},
"line": {
"type": "number"
}
},
"required": [
"file"
]
}
},
"required": [
"ruleId",
"location"
]
},
"description": "Findings before the change (from a scan's JSON findings)."
},
"after": {
"type": "array",
"items": {
"type": "object",
"description": "A single finding from `scan_path --format json`.",
"properties": {
"ruleId": {
"type": "string",
"description": "Stable rule id, e.g. \"rsa-keygen\"."
},
"title": {
"type": "string"
},
"category": {
"type": "string"
},
"severity": {
"type": "string",
"description": "critical | high | medium | low | info."
},
"confidence": {
"type": "string"
},
"algorithm": {
"type": "string",
"description": "Classical algorithm family, when applicable."
},
"hndl": {
"type": "boolean",
"description": "Exposed to harvest-now-decrypt-later."
},
"message": {
"type": "string"
},
"remediation": {
"type": "string"
},
"cwe": {
"type": "string",
"description": "e.g. \"CWE-327\"."
},
"location": {
"type": "object",
"description": "Where the finding is.",
"properties": {
"file": {
"type": "string"
},
"line": {
"type": "number"
}
},
"required": [
"file"
]
}
},
"required": [
"ruleId",
"location"
]
},
"description": "Findings after the change."
}
},
"required": [
"before",
"after"
],
"additionalProperties": false
}🟡suggest_hybrid(algorithm, context, tier)
Recommend a post-quantum / hybrid migration. Provide an 'algorithm' (e.g. RSA, ECDH, ECDSA) or free-text 'context' describing the usage. Set 'tier' to 'category-5' for CNSA 2.0 / national-security systems.
輸入結構描述
{
"type": "object",
"properties": {
"algorithm": {
"type": "string",
"description": "Classical algorithm family to migrate away from."
},
"context": {
"type": "string",
"description": "Free-text description of the cryptographic usage (used when no algorithm is given)."
},
"tier": {
"type": "string",
"enum": [
"category-3",
"category-5"
],
"description": "Security tier: 'category-3' (default, commercial — ML-KEM-768 / ML-DSA-65) or 'category-5' (CNSA 2.0 / NSS, long-lived secrets — ML-KEM-1024 / ML-DSA-87)."
}
},
"additionalProperties": false
}⚪triage_findings(findings)
Produce a deterministic triage REQUEST bundle (rubric + verdict schema + per-finding metadata) for YOU (the host agent) to reason over. This tool does NOT call any model and needs no API key. Assess each finding's real-world exposure, then call apply_triage with your verdicts. Pass 'findings' as an array from scan_path --format json.
輸入結構描述
{
"type": "object",
"properties": {
"findings": {
"type": "array",
"items": {
"type": "object",
"description": "A single finding from `scan_path --format json`.",
"properties": {
"ruleId": {
"type": "string",
"description": "Stable rule id, e.g. \"rsa-keygen\"."
},
"title": {
"type": "string"
},
"category": {
"type": "string"
},
"severity": {
"type": "string",
"description": "critical | high | medium | low | info."
},
"confidence": {
"type": "string"
},
"algorithm": {
"type": "string",
"description": "Classical algorithm family, when applicable."
},
"hndl": {
"type": "boolean",
"description": "Exposed to harvest-now-decrypt-later."
},
"message": {
"type": "string"
},
"remediation": {
"type": "string"
},
"cwe": {
"type": "string",
"description": "e.g. \"CWE-327\"."
},
"location": {
"type": "object",
"description": "Where the finding is.",
"properties": {
"file": {
"type": "string"
},
"line": {
"type": "number"
}
},
"required": [
"file"
]
}
},
"required": [
"ruleId",
"location"
]
},
"description": "Findings from a scan's JSON output."
}
},
"required": [
"findings"
],
"additionalProperties": false
}🟡verify_fix(code, language, filename)
Run the quantakrypto detectors over a code snippet (NOT the filesystem) and report any classical crypto that remains. Use this to confirm an edit actually removed the quantum-vulnerable usage. Provide 'code' plus a 'language' or 'filename'.
輸入結構描述
{
"type": "object",
"properties": {
"code": {
"type": "string",
"description": "The source code to check."
},
"language": {
"type": "string",
"description": "Language of the code (js, ts, python, go, java, csharp, rust, ruby, c, …)."
},
"filename": {
"type": "string",
"description": "Optional filename; its extension selects the detectors (overrides 'language')."
}
},
"required": [
"code"
],
"additionalProperties": false
}社群
證據