Serveur MCP

quantakrypto pqc-tools

io.github.quantakrypto/pqc-tools
Outils développeur Sécurité Public et accessible MCP 2026-07-28

Ce que fait ce MCP

Scans code and dependencies for quantum-vulnerable cryptography and supports deterministic triage, verification, and post-quantum migration guidance.

apply_triage
Deterministically attach your triage verdicts to their findings and re-sort by exposure (highest first). Never suppresses. Pass the same 'findings' array you triaged plus a 'verdicts' array of { fingerprint, exposureScore, priority, rationale }.
Schéma d’entrée
{'type': 'object', 'required': ['findings', 'verdicts'], 'properties': {'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['ruleId', 'location'], 'properties': {'cwe': {'type': 'string', 'description': 'e.g. "CWE-327".'}, 'hndl': {'type': 'boolean', 'description': 'Exposed to harvest-now-decrypt-later.'}, 'title': {'type': 'string'}, 'ruleId': {'type': 'string', 'description': 'Stable rule id, e.g. "rsa-keygen".'}, 'message': {'type': 'string'}, 'category': {'type': 'string'}, 'location': {'type': 'object', 'required': ['file'], 'properties': {'file': {'type': 'string'}, 'line': {'type': 'number'}}, 'description': 'Where the finding is.'}, 'severity': {'type': 'string', 'description': 'critical | high | medium | low | info.'}, 'algorithm': {'type': 'string', 'description': 'Classical algorithm family, when applicable.'}, 'confidence': {'type': 'string'}, 'remediation': {'type': 'string'}}, 'description': 'A single finding from `scan_path --format json`.'}, 'description': 'The findings that were triaged.'}, 'verdicts': {'type': 'array', 'items': {'type': 'object', 'required': ['fingerprint', 'exposureScore', 'priority', 'rationale'], 'properties': {'priority': {'enum': ['now', 'soon', 'later'], 'type': 'string'}, 'rationale': {'type': 'string', 'description': 'Why this exposure score / priority.'}, 'fingerprint': {'type': 'string', 'description': 'Fingerprint of the finding this verdict applies to.'}, 'exposureScore': {'type': 'number', 'description': 'Real-world exposure (higher = more exposed).'}}, 'description': 'A triage verdict for one finding.'}, 'description': 'One verdict per finding, keyed by fingerprint.'}}, 'additionalProperties': False}
apply_verified_patch
Deterministically VERIFY a proposed fix before writing it — runs the same patch-policy + verify_fix + blast-radius gates as `qremediate` (offline, no key, no network). Give the finding, the file's current content, and your proposed FULL corrected content; returns approved:true only if the patch is in-policy, clears the finding, adds no new finding, introduces no network/exec sink, and is bounded in size. This does NOT write the file — you write it, only when approved, and never auto-merge.
Schéma d’entrée
{'type': 'object', 'required': ['finding', 'originalContent', 'newContent'], 'properties': {'finding': {'type': 'object', 'description': 'The scan finding being fixed (needs a string ruleId and location.file).'}, 'newContent': {'type': 'string', 'description': 'Your proposed full corrected file content.'}, 'originalContent': {'type': 'string', 'description': "The file's current full content."}}, 'additionalProperties': False}
check_dependency
Check whether a package is in quantakrypto's known quantum-vulnerable dependency database (the classical crypto it exposes). Provide 'name' and optional 'ecosystem' (default npm).
Schéma d’entrée
{'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': "Package name to look up (e.g. 'node-forge', 'jsonwebtoken')."}, 'ecosystem': {'type': 'string', 'description': 'Package ecosystem. Default: npm.'}}, 'additionalProperties': False}
explain_finding
Explain a quantakrypto finding and its post-quantum remediation. Provide a ruleId (e.g. 'forge-rsa-keygen', 'elliptic-ec', 'node-rsa', 'pem-ec-private-key') and/or an algorithm (e.g. 'RSA', 'ECDSA'). The ruleId is resolved against the core detector set, so library and config rules explain correctly.
Schéma d’entrée
{'type': 'object', 'properties': {'ruleId': {'type': 'string', 'description': "The finding's rule id, matching a detector id prefix."}, 'algorithm': {'type': 'string', 'description': 'The classical algorithm family involved (e.g. RSA, ECDH, ECDSA).'}}, 'additionalProperties': False}
get_fix_examples
Return before/after code examples for migrating a classical algorithm to a post-quantum / hybrid replacement. Provide an 'algorithm' (RSA, ECDH, ECDSA, …) or a 'ruleId' from a finding.
Schéma d’entrée
{'type': 'object', 'properties': {'ruleId': {'type': 'string', 'description': "A finding's ruleId (resolved to its algorithm)."}, 'algorithm': {'type': 'string', 'description': 'Classical algorithm family to migrate away from.'}}, 'additionalProperties': False}
list_rules
List the quantakrypto detector catalog: every detector id and what it looks for.
Schéma d’entrée
{'type': 'object', 'properties': {}, 'additionalProperties': False}
remediate_findings
Produce a deterministic remediation REQUEST bundle (rubric + fix schema + per-finding metadata + fingerprints) for YOU (the host agent) to fix. This tool calls no model and needs no key. For each finding, propose the corrected FULL file content, then VERIFY with verify_fix and keep only fixes that clear the finding. Never touch files with secrets; never auto-merge. Pass 'findings' from scan_path --format json.
Schéma d’entrée
{'type': 'object', 'required': ['findings'], 'properties': {'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['ruleId', 'location'], 'properties': {'cwe': {'type': 'string', 'description': 'e.g. "CWE-327".'}, 'hndl': {'type': 'boolean', 'description': 'Exposed to harvest-now-decrypt-later.'}, 'title': {'type': 'string'}, 'ruleId': {'type': 'string', 'description': 'Stable rule id, e.g. "rsa-keygen".'}, 'message': {'type': 'string'}, 'category': {'type': 'string'}, 'location': {'type': 'object', 'required': ['file'], 'properties': {'file': {'type': 'string'}, 'line': {'type': 'number'}}, 'description': 'Where the finding is.'}, 'severity': {'type': 'string', 'description': 'critical | high | medium | low | info.'}, 'algorithm': {'type': 'string', 'description': 'Classical algorithm family, when applicable.'}, 'confidence': {'type': 'string'}, 'remediation': {'type': 'string'}}, 'description': 'A single finding from `scan_path --format json`.'}, 'description': "Findings from a scan's JSON output."}}, 'additionalProperties': False}
score_delta
Compute the readiness-score and HNDL change between two finding sets (e.g. before and after a migration). Pass 'before' and 'after' as arrays of findings from scan_path --format json.
Schéma d’entrée
{'type': 'object', 'required': ['before', 'after'], 'properties': {'after': {'type': 'array', 'items': {'type': 'object', 'required': ['ruleId', 'location'], 'properties': {'cwe': {'type': 'string', 'description': 'e.g. "CWE-327".'}, 'hndl': {'type': 'boolean', 'description': 'Exposed to harvest-now-decrypt-later.'}, 'title': {'type': 'string'}, 'ruleId': {'type': 'string', 'description': 'Stable rule id, e.g. "rsa-keygen".'}, 'message': {'type': 'string'}, 'category': {'type': 'string'}, 'location': {'type': 'object', 'required': ['file'], 'properties': {'file': {'type': 'string'}, 'line': {'type': 'number'}}, 'description': 'Where the finding is.'}, 'severity': {'type': 'string', 'description': 'critical | high | medium | low | info.'}, 'algorithm': {'type': 'string', 'description': 'Classical algorithm family, when applicable.'}, 'confidence': {'type': 'string'}, 'remediation': {'type': 'string'}}, 'description': 'A single finding from `scan_path --format json`.'}, 'description': 'Findings after the change.'}, 'before': {'type': 'array', 'items': {'type': 'object', 'required': ['ruleId', 'location'], 'properties': {'cwe': {'type': 'string', 'description': 'e.g. "CWE-327".'}, 'hndl': {'type': 'boolean', 'description': 'Exposed to harvest-now-decrypt-later.'}, 'title': {'type': 'string'}, 'ruleId': {'type': 'string', 'description': 'Stable rule id, e.g. "rsa-keygen".'}, 'message': {'type': 'string'}, 'category': {'type': 'string'}, 'location': {'type': 'object', 'required': ['file'], 'properties': {'file': {'type': 'string'}, 'line': {'type': 'number'}}, 'description': 'Where the finding is.'}, 'severity': {'type': 'string', 'description': 'critical | high | medium | low | info.'}, 'algorithm': {'type': 'string', 'description': 'Classical algorithm family, when applicable.'}, 'confidence': {'type': 'string'}, 'remediation': {'type': 'string'}}, 'description': 'A single finding from `scan_path --format json`.'}, 'description': "Findings before the change (from a scan's JSON findings)."}}, 'additionalProperties': False}
suggest_hybrid
Recommend a post-quantum / hybrid migration. Provide an 'algorithm' (e.g. RSA, ECDH, ECDSA) or free-text 'context' describing the usage. Set 'tier' to 'category-5' for CNSA 2.0 / national-security systems.
Schéma d’entrée
{'type': 'object', 'properties': {'tier': {'enum': ['category-3', 'category-5'], 'type': 'string', 'description': "Security tier: 'category-3' (default, commercial — ML-KEM-768 / ML-DSA-65) or 'category-5' (CNSA 2.0 / NSS, long-lived secrets — ML-KEM-1024 / ML-DSA-87)."}, 'context': {'type': 'string', 'description': 'Free-text description of the cryptographic usage (used when no algorithm is given).'}, 'algorithm': {'type': 'string', 'description': 'Classical algorithm family to migrate away from.'}}, 'additionalProperties': False}
triage_findings
Produce a deterministic triage REQUEST bundle (rubric + verdict schema + per-finding metadata) for YOU (the host agent) to reason over. This tool does NOT call any model and needs no API key. Assess each finding's real-world exposure, then call apply_triage with your verdicts. Pass 'findings' as an array from scan_path --format json.
Schéma d’entrée
{'type': 'object', 'required': ['findings'], 'properties': {'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['ruleId', 'location'], 'properties': {'cwe': {'type': 'string', 'description': 'e.g. "CWE-327".'}, 'hndl': {'type': 'boolean', 'description': 'Exposed to harvest-now-decrypt-later.'}, 'title': {'type': 'string'}, 'ruleId': {'type': 'string', 'description': 'Stable rule id, e.g. "rsa-keygen".'}, 'message': {'type': 'string'}, 'category': {'type': 'string'}, 'location': {'type': 'object', 'required': ['file'], 'properties': {'file': {'type': 'string'}, 'line': {'type': 'number'}}, 'description': 'Where the finding is.'}, 'severity': {'type': 'string', 'description': 'critical | high | medium | low | info.'}, 'algorithm': {'type': 'string', 'description': 'Classical algorithm family, when applicable.'}, 'confidence': {'type': 'string'}, 'remediation': {'type': 'string'}}, 'description': 'A single finding from `scan_path --format json`.'}, 'description': "Findings from a scan's JSON output."}}, 'additionalProperties': False}
verify_fix
Run the quantakrypto detectors over a code snippet (NOT the filesystem) and report any classical crypto that remains. Use this to confirm an edit actually removed the quantum-vulnerable usage. Provide 'code' plus a 'language' or 'filename'.
Schéma d’entrée
{'type': 'object', 'required': ['code'], 'properties': {'code': {'type': 'string', 'description': 'The source code to check.'}, 'filename': {'type': 'string', 'description': "Optional filename; its extension selects the detectors (overrides 'language')."}, 'language': {'type': 'string', 'description': 'Language of the code (js, ts, python, go, java, csharp, rust, ruby, c, …).'}}, 'additionalProperties': False}
Ajouté
verify_fix
17 September 2026 12:49
Ajouté
triage_findings
17 September 2026 12:49
Ajouté
suggest_hybrid
17 September 2026 12:49
Ajouté
score_delta
17 September 2026 12:49
Ajouté
remediate_findings
17 September 2026 12:49
Ajouté
list_rules
17 September 2026 12:49
Ajouté
get_fix_examples
17 September 2026 12:49
Ajouté
explain_finding
17 September 2026 12:49
Ajouté
check_dependency
17 September 2026 12:49
Ajouté
apply_verified_patch
17 September 2026 12:49
Ajouté
apply_triage
17 September 2026 12:49

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…