quantakrypto

SSE

by quantakrypto

21 downloads Not rated yet

About

Post-quantum cryptography readiness: scans code and dependencies for quantum-vulnerable RSA/ECDSA/ECDH, plans migration, and verifies fixes.

Details

Transport
SSE

Explore

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name quantakrypto
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

apply_triage

Deterministically attach your triage verdicts to their findings and re-sort by exposure (highest first). Never suppresses. Pass the same 'findings' array you triaged plus a 'verdicts' array of { fingerprint, exposureScore, priority, rationale }.

apply_verified_patch

Deterministically VERIFY a proposed fix before writing it — runs the same patch-policy + verify_fix + blast-radius gates as `qremediate` (offline, no key, no network). Give the finding, the file's current content, and your proposed FULL corrected content; returns approved:true only if the patch is in-policy, clears the finding, adds no new finding, introduces no network/exec sink, and is bounded in size. This does NOT write the file — you write it, only when approved, and never auto-merge.

check_dependency

Check whether a package is in quantakrypto's known quantum-vulnerable dependency database (the classical crypto it exposes). Provide 'name' and optional 'ecosystem' (default npm).

explain_finding

Explain a quantakrypto finding and its post-quantum remediation. Provide a ruleId (e.g. 'forge-rsa-keygen', 'elliptic-ec', 'node-rsa', 'pem-ec-private-key') and/or an algorithm (e.g. 'RSA', 'ECDSA'). The ruleId is resolved against the core detector set, so library and config rules explain correctly.

get_fix_examples

Return before/after code examples for migrating a classical algorithm to a post-quantum / hybrid replacement. Provide an 'algorithm' (RSA, ECDH, ECDSA, …) or a 'ruleId' from a finding.

list_rules

List the quantakrypto detector catalog: every detector id and what it looks for.

remediate_findings

Produce a deterministic remediation REQUEST bundle (rubric + fix schema + per-finding metadata + fingerprints) for YOU (the host agent) to fix. This tool calls no model and needs no key. For each finding, propose the corrected FULL file content, then VERIFY with verify_fix and keep only fixes that clear the finding. Never touch files with secrets; never auto-merge. Pass 'findings' from scan_path --format json.

score_delta

Compute the readiness-score and HNDL change between two finding sets (e.g. before and after a migration). Pass 'before' and 'after' as arrays of findings from scan_path --format json.

suggest_hybrid

Recommend a post-quantum / hybrid migration. Provide an 'algorithm' (e.g. RSA, ECDH, ECDSA) or free-text 'context' describing the usage. Set 'tier' to 'category-5' for CNSA 2.0 / national-security systems.

triage_findings

Produce a deterministic triage REQUEST bundle (rubric + verdict schema + per-finding metadata) for YOU (the host agent) to reason over. This tool does NOT call any model and needs no API key. Assess each finding's real-world exposure, then call apply_triage with your verdicts. Pass 'findings' as an array from scan_path --format json.

verify_fix

Run the quantakrypto detectors over a code snippet (NOT the filesystem) and report any classical crypto that remains. Use this to confirm an edit actually removed the quantum-vulnerable usage. Provide 'code' plus a 'language' or 'filename'.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "quantakrypto": {
            "server": {
                "command": "npx",
                "args": [
                    "-y",
                    "@quantakrypto/mcp"
                ]
            }
        }
    }
}

McpServers

{
    "server": {
        "command": "npx",
        "args": [
            "-y",
            "@quantakrypto/mcp"
        ]
    }
}

Transport

"stdio"

Package

"@quantakrypto/mcp"

Registry

"npm"

Using quantakrypto alongside a PQC library (liboqs / OQS)

quantakryptodoes not implement post-quantum cryptography, by design— it is the scanner, the CI gate, and the conformance harness you wrap around a real PQC library like](https://github.com/quantakrypto/pqc-tools/blob/HEAD/packages/agent/README.md)liboqs / Open Quantum Safe. They compose: quantakryptofinds and gatesclassical crypto (qscan, the Action), tells youwhat to migrate to and in what order(qscan --tier, MCPplan_migration,qremediate), andconformance-tests the replacement(sieveruns any ML-KEM/ML-DSA/SLH-DSA implementation against FIPS 203/204/205, with exact-value KATs when you supply official NIST ACVP vectors). liboqs supplies the primitives.

See the worked end-to-end walkthrough — scan → migrate → verify → gate — inexamples/liboqs-migration/.

quantakrypto-tools/ ├── packages/ │ ├── core/ @quantakrypto/core — shared engine (the contract lives in src/types.ts + src/index.ts) │ ├── qscan/ @quantakrypto/qscan — CLI │ ├── mcp/ @quantakrypto/mcp — MCP server (stdio now, HTTP scaffold for hosting) │ ├── action/ @quantakrypto/action — GitHub Action │ ├── sieve/ @quantakrypto/sieve — conformance battery + JSON protocol │ ├── agent/ @quantakrypto/agent — opt-in BYOK LLM client (triage + remediation) │ └── qprobe/ @quantakrypto/qprobe — active TLS/SSH endpoint probing (gated; the only prober) ├── docs/ architecture, hosted-MCP design, improvement roadmap └── examples/ end-to-end examples
npm install # links the workspaces npm run build # tsc --build (project references) npm test # node:test across all packages

The toolchain is intentionally tiny: TypeScript +tsx(to runnode:teston.ts) are the only dev dependencies; there areno runtime dependencies.

- Objectives & scope— what the toolchain is for, what each library does, the load-bearing decisions, and the deliberate scope boundaries. Start here.
-
Architecture decisions— the immutable "why" behind each load-bearing choice (zero deps, shared core contract, two-plane agent, …).
-
Standards & compliance— what the tools touch and could align to: NIST FIPS 203/204/205, SP 800-208, CNSA 2.0, SARIF, CWE, ISO/IEC 27001 (A.8.24), Common Criteria, FIPS 140-3, EU DORA/NIS2, US M-23-02 / NSM-10, and OSS assurance (SLSA, OpenSSF Scorecard, SPDX/REUSE).
- Governance:
Contributing·Security·Code of Conduct·Changelog.

Apache-2.0. The methodology is open; the assessments, attestation reports, and deliverables are where thequantakryptopractice lives.

Questions, commercial support, or post-quantum readiness training for your team — visitquantakrypto.comor email[email protected].

This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.

Create crafted UI components inspired by the best 21st.dev design engineers.

Bring agent evaluations, observability, and synthetic test set generation directly into your IDE for free with Galileo's new MCP server

An MCP server to help AI assistants to answer questions and generate AccelByte Extend SDK code more effectively .

MCP server for AI Diagram Maker — generate beautiful software engineering diagrams directly inside Cursor, Claude Desktop, Claude Code, or any MCP-compatible AI agent

ALAPI MCP Tools,Call hundreds of API interfaces via MCP

AI-powered SVG animation generator that transforms static files into animated SVG components using the Allyson platform

MCP server that gives AI assistants on-demand access to 1,500+ amCharts docs, ~300 code examples, and 1000+ class API references.

APIMatic MCP Server is used to validate OpenAPI specifications using APIMatic. The server processes OpenAPI files and returns validation summaries by leveraging APIMatic’s API.

One shared context layer for AI agents and humans — live API specs, DB schemas, and versioned contracts across repos so every agent and teammate works from the same source of truth.

Build and deploy full-stack Next.js apps with 98 tools for React, AWS, and MongoDB

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.