quantakrypto pqc-tools

quantakrypto pqc-tools

Post-quantum readiness for AI coding agents: scans code for quantum-vulnerable cryptography (RSA/ECDH/ECDSA/DH) and returns NIST ML-KEM/ML-DSA/SLH-DSA (and hybrid) migration guidance, with fix verification and dependency checks. Content-based, advisory tools only; runs local (npx @quantakrypto/mcp) or as a hosted OAuth endpoint.

Category
Visit Server

README

quantakrypto-tools

CI License: Apache-2.0 npm @quantakrypto/core npm @quantakrypto/qscan npm @quantakrypto/mcp npm @quantakrypto/sieve npm @quantakrypto/agent Node ≥20 TypeScript strict Runtime deps: 0 NIST FIPS 203/204/205

Open-source post-quantum readiness tooling by quantakrypto. Find quantum-vulnerable cryptography in any codebase, wire post-quantum readiness into your editor and your CI, and conformance-test post-quantum implementations — with zero runtime dependencies (Node built-ins only).

Design goals: simple, clean, reusable code; zero runtime dependencies; everything documented, tested, and example-driven.

What's inside

Tool What it does Get it
qScan (@quantakrypto/qscan) CLI that finds quantum-vulnerable crypto (RSA, (EC)DH, ECDSA, EdDSA, …) across 14 languages (JS/TS, Python, Go, Java/Kotlin/Scala, C#, Rust, Ruby, PHP, Elixir, C/C++, Swift, Objective-C, Dart, Solidity/Move/Cairo) and prints a readiness score. SARIF / JSON / CBOM / evidence (ISO 27001 A.8.24) / OpenVEX output, baselines, incremental & parallel scans. Opt-in --triage (BYOK LLM re-rank/explain) and a qremediate codemod CLI. npx @quantakrypto/qscan ./
MCP (@quantakrypto/mcp) Model Context Protocol server that gives AI coding agents post-quantum readiness tools (scan, inventory, explain, suggest-hybrid, CBOM). Local stdio + hostable HTTP. claude mcp add quantakrypto npx @quantakrypto/mcp
Sieve (@quantakrypto/sieve) Conformance battery for ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) implementations, driven over a JSON stdin/stdout protocol. npx @quantakrypto/sieve --help
Action (@quantakrypto/action) GitHub Action that runs qScan in CI, uploads SARIF, annotates the diff, and fails the build only on new quantum-vulnerable crypto. uses: quantakrypto/pqc-tools/packages/action@v1
agent (@quantakrypto/agent) Optional, zero-dependency BYOK (bring-your-own-key) LLM client (native fetch; Anthropic + OpenAI-compatible adapters) that powers qScan --triage and qremediate --llm. Networked, key-holding — kept isolated (see also qProbe). npm i @quantakrypto/agent
qProbe (@quantakrypto/qprobe) Actively probes live TLS/SSH endpoints you own for post-quantum readiness — PQC-hybrid key exchange (X25519MLKEM768) and classical certificate posture. Gated behind an ownership attestation; reports, never modifies ("engine disposes"). See THREAT-MODEL. npx @quantakrypto/qprobe --i-own-this host

All of qScan, MCP, the Action, agent, and qProbe share the engine in @quantakrypto/core (npm i @quantakrypto/core) — detectors, the vulnerable-dependency DB, the readiness score, SARIF/JSON/CBOM/evidence/OpenVEX reporting, and the offline agent-plane primitives (context redactor, verify_fix gate, codemods, patch policy). Sieve is standalone: it tests other implementations and implements no crypto itself.

Infrastructure coverage. Beyond application source, the shared core engine carries config-scope detectors for Terraform/OpenTofu IaC and cloud KMS, JSON Web Keys, Kubernetes / cert-manager / Istio, CI/CD artifact & code signing (cosign/GPG/jarsigner/codesign/minisign), secrets at rest (SOPS/age, PGP, Sealed Secrets), message brokers (Kafka/MQTT), databases (pgcrypto, libpq sslmode), and JOSE/JWE key management — so qscan, the Action, and MCP flag infrastructure crypto with no extra install. qProbe adds the live-endpoint dimension (see the table above). The narrative anchor for infrastructure is harvest now, decrypt later: data and secrets captured today are decryptable once a CRQC exists.

Quick start

# 1. Scan a codebase for quantum-vulnerable cryptography.
npx @quantakrypto/qscan ./

# 2. Give your AI coding agent post-quantum readiness tools.
claude mcp add quantakrypto npx @quantakrypto/mcp

# 3. Conformance-test a post-quantum implementation (adapter speaks the JSON protocol).
npx @quantakrypto/sieve --impl "node ./my-impl.js" --param ml-kem-768

Add the CI gate by dropping packages/action/examples/quantum-readiness.yml into .github/workflows/, or wire it up directly:

- uses: quantakrypto/pqc-tools/packages/action@v1
  with:
    path: "."
    severity-threshold: "high"

Each package README has the full options reference and more examples: qScan · MCP · Sieve · Action · core · agent.

Using quantakrypto alongside a PQC library (liboqs / OQS)

quantakrypto does not implement post-quantum cryptography, by design — it is the scanner, the CI gate, and the conformance harness you wrap around a real PQC library like liboqs / Open Quantum Safe. They compose: quantakrypto finds and gates classical crypto (qscan, the Action), tells you what to migrate to and in what order (qscan --tier, MCP plan_migration, qremediate), and proves the replacement is correct (sieve conformance-tests any ML-KEM/ML-DSA/SLH-DSA implementation against FIPS 203/204/205). liboqs supplies the primitives.

See the worked end-to-end walkthrough — scan → migrate → verify → gate — in examples/liboqs-migration/.

Workspace layout

quantakrypto-tools/
├── packages/
│   ├── core/     @quantakrypto/core    — shared engine (the contract lives in src/types.ts + src/index.ts)
│   ├── qscan/    @quantakrypto/qscan   — CLI
│   ├── mcp/      @quantakrypto/mcp     — MCP server (stdio now, HTTP scaffold for hosting)
│   ├── action/   @quantakrypto/action — GitHub Action
│   ├── sieve/    @quantakrypto/sieve   — conformance battery + JSON protocol
│   ├── agent/    @quantakrypto/agent   — opt-in BYOK LLM client (triage + remediation)
│   └── qprobe/   @quantakrypto/qprobe  — active TLS/SSH endpoint probing (gated; the only prober)
├── docs/         architecture, hosted-MCP design, improvement roadmap
└── examples/     end-to-end examples

Development

Requires Node ≥ 20.

npm install        # links the workspaces
npm run build      # tsc --build (project references)
npm test           # node:test across all packages

The toolchain is intentionally tiny: TypeScript + tsx (to run node:test on .ts) are the only dev dependencies; there are no runtime dependencies.

Documentation & compliance

Full documentation lives in docs/:

  • Objectives & scope — what the toolchain is for, what each library does, the load-bearing decisions, and the deliberate scope boundaries. Start here.
  • Architecture decisions — the immutable "why" behind each load-bearing choice (zero deps, shared core contract, two-plane agent, …).
  • Standards & compliance — what the tools touch and could align to: NIST FIPS 203/204/205, SP 800-208, CNSA 2.0, SARIF, CWE, ISO/IEC 27001 (A.8.24), Common Criteria, FIPS 140-3, EU DORA/NIS2, US M-23-02 / NSM-10, and OSS assurance (SLSA, OpenSSF Scorecard, SPDX/REUSE).
  • Governance: Contributing · Security · Code of Conduct · Changelog.

License

Apache-2.0. The methodology is open; the audits, certificates, and deliverables are where the quantakrypto practice lives.

Support & training

Questions, commercial support, or post-quantum readiness training for your team — visit quantakrypto.com or email hello@quantakrypto.com.

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured