pqc-tools
Open-source post-quantum readiness tooling by quantakrypto
Documentation
quantakrypto-tools
Open-source post-quantum readiness tooling by quantakrypto.
Find quantum-vulnerable cryptography in any codebase, wire post-quantum readiness
into your editor and your CI, and conformance-test post-quantum implementations —
with zero runtime dependencies (Node built-ins only).
> Design goals: simple, clean, reusable code; zero runtime dependencies;
> everything documented, tested, and example-driven.
What's inside
| Tool | What it does | Get it |
|---|---|---|
| **qScan** (`@quantakrypto/qscan`) | CLI that finds quantum-vulnerable crypto (RSA, (EC)DH, ECDSA, EdDSA, …) across 14 languages (JS/TS, Python, Go, Java/Kotlin/Scala, C#, Rust, Ruby, PHP, Elixir, C/C++, Swift, Objective-C, Dart, Solidity/Move/Cairo) and prints a readiness score. SARIF / JSON / CBOM / evidence (ISO 27001 A.8.24) / OpenVEX output, baselines, incremental & parallel scans. Compliance mandate gate: `--mandate cnsa-2.0` / `nist-ir-8547` reports each prohibited finding with its dated clause and fails the build on the mandate's deadlines (`--lead-months`, `--fail-now`). Opt-in `--triage` (BYOK LLM re-rank/explain) and a `qremediate` codemod CLI. | `npx @quantakrypto/qscan ./` |
| **MCP** (`@quantakrypto/mcp`) | Model Context Protocol server that gives AI coding agents post-quantum readiness tools (16 tools — scan, inventory, explain, suggest-hybrid, CBOM, plan-migration, triage, remediate, probe-endpoint, …). Local stdio + hostable HTTP. | `claude mcp add quantakrypto npx @quantakrypto/mcp` |
| **Sieve** (`@quantakrypto/sieve`) | Conformance battery for ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) implementations, driven over a JSON stdin/stdout protocol. | `npx @quantakrypto/sieve --help` |
| **Action** (`@quantakrypto/action`) | GitHub Action that runs the qScan/Sieve/qProbe checks in CI, writes SARIF for code-scanning upload, annotates the diff, and fails the build only on new quantum-vulnerable crypto. | `uses: quantakrypto/pqc-tools/packages/action@v1` |
| **agent** (`@quantakrypto/agent`) | Optional, zero-dependency BYOK (bring-your-own-key) LLM client (native `fetch`; Anthropic + OpenAI-compatible adapters) that powers qScan `--triage` and `qremediate --llm`. Networked, key-holding — kept isolated (see also qProbe). | `npm i @quantakrypto/agent` |
| **qProbe** (`@quantakrypto/qprobe`) | Actively probes live TLS/SSH endpoints you own for post-quantum readiness — PQC-hybrid key exchange (X25519MLKEM768) and classical certificate posture. Gated behind an ownership attestation; reports, never modifies ("engine disposes"). See THREAT-MODEL. | `npx @quantakrypto/qprobe --i-own-this host` |
All of qScan, MCP, the Action, agent, and qProbe share the engine in
**`@quantakrypto/core`** (`npm i @quantakrypto/core`) — detectors,
the vulnerable-dependency DB, the readiness score, SARIF/JSON/CBOM/evidence/OpenVEX
reporting, and the
offline agent-plane primitives (context redactor, `verify_fix` gate, codemods, patch
policy). Sieve is standalone: it tests *other* implementations and implements no
crypto itself.
Infrastructure coverage. Beyond application source, the shared `core` engine
carries config-scope detectors for Terraform/OpenTofu IaC and cloud KMS, JSON
Web Keys, Kubernetes / cert-manager / Istio, CI/CD artifact & code signing
(cosign/GPG/jarsigner/codesign/minisign), secrets at rest (SOPS/age, PGP, Sealed
Secrets), message brokers (Kafka/MQTT), databases (pgcrypto, libpq `sslmode`), and
JOSE/JWE key management — so `qscan`, the Action, and MCP flag infrastructure
crypto with no extra install. qProbe adds the live-endpoint dimension (see the
table above). The narrative anchor for infrastructure is *harvest now, decrypt
later*: data and secrets captured today are decryptable once a CRQC exists.
Quick start
# 1. Scan a codebase for quantum-vulnerable cryptography.
npx @quantakrypto/qscan ./
# 2. Give your AI coding agent post-quantum readiness tools.
claude mcp add quantakrypto npx @quantakrypto/mcp
# 3. Conformance-test a post-quantum implementation (adapter speaks the JSON protocol).
npx @quantakrypto/sieve --impl "node ./my-impl.js" --param ml-kem-768
# 4. Gate against a compliance mandate's dated deadlines (CNSA 2.0 / NIST IR 8547).
# Verdicts also ride in --format json/sarif/evidence; --policy lets an org
# acknowledge families it is knowingly migrating (exempt from early gating).
npx @quantakrypto/qscan ./ --mandate cnsa-2.0 [--policy .quantakrypto/crypto-policy.json]Add the CI gate by dropping
`packages/action/examples/quantum-readiness.yml`
into `.github/workflows/`, or wire it up directly:
- uses: quantakrypto/pqc-tools/packages/action@v1
with:
path: "."
severity-threshold: "high"Each package README has the full options reference and more examples:
qScan ·
MCP ·
Sieve ·
Action ·
core ·
Using quantakrypto alongside a PQC library (liboqs / OQS)
quantakrypto does not implement post-quantum cryptography, by design — it is
the scanner, the CI gate, and the conformance harness you wrap around a real PQC
library like liboqs / Open Quantum Safe. They
compose: quantakrypto finds and gates classical crypto (`qscan`, the Action),
tells you what to migrate to and in what order (`qscan --tier`, MCP
`plan_migration`, `qremediate`), and conformance-tests the replacement
(`sieve` runs any ML-KEM/ML-DSA/SLH-DSA implementation against FIPS 203/204/205,
with exact-value KATs when you supply official NIST ACVP vectors). liboqs
supplies the primitives.
See the worked end-to-end walkthrough — scan → migrate → verify → gate — in
**`examples/liboqs-migration/`**.
Workspace layout
quantakrypto-tools/
├── packages/
│ ├── core/ @quantakrypto/core — shared engine (the contract lives in src/types.ts + src/index.ts)
│ ├── qscan/ @quantakrypto/qscan — CLI
│ ├── mcp/ @quantakrypto/mcp — MCP server (stdio now, HTTP scaffold for hosting)
│ ├── action/ @quantakrypto/action — GitHub Action
│ ├── sieve/ @quantakrypto/sieve — conformance battery + JSON protocol
│ ├── agent/ @quantakrypto/agent — opt-in BYOK LLM client (triage + remediation)
│ └── qprobe/ @quantakrypto/qprobe — active TLS/SSH endpoint probing (gated; the only prober)
├── docs/ architecture, hosted-MCP design, improvement roadmap
└── examples/ end-to-end examplesDevelopment
Requires Node ≥ 20.
npm install # links the workspaces
npm run build # tsc --build (project references)
npm test # node:test across all packagesThe toolchain is intentionally tiny: TypeScript + `tsx` (to run `node:test` on
`.ts`) are the only dev dependencies; there are no runtime dependencies.
Documentation & compliance
Full documentation lives in **`docs/`**:
- **Objectives & scope** — what the toolchain is for, what
each library does, the load-bearing decisions, and the deliberate scope
boundaries. Start here.
- **Architecture decisions** — the immutable "why" behind
each load-bearing choice (zero deps, shared core contract, two-plane agent, …).
- **Standards & compliance** — what the tools touch and
could align to: NIST FIPS 203/204/205, SP 800-208, CNSA 2.0, SARIF, CWE,
ISO/IEC 27001 (A.8.24), Common Criteria, FIPS 140-3, EU DORA/NIS2, US
M-23-02 / NSM-10, and OSS assurance (SLSA, OpenSSF Scorecard, SPDX/REUSE).
- Governance: Contributing · Security ·
License
Apache-2.0. The methodology is open; the assessments, attestation
reports, and deliverables are where the quantakrypto
practice lives.
Support & training
Questions, commercial support, or post-quantum readiness training for your team —
visit **quantakrypto.com** or email
Frequently asked questions
What is pqc-tools?
pqc-tools is Open-source post-quantum readiness tooling by quantakrypto
How do I install pqc-tools?
Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.
Is pqc-tools open source?
Yes — it is hosted on GitHub at https://github.com/quantakrypto/pqc-tools and has 10 stars.
Related MCP tools
The Open-Source Multimodal AI Agent Stack: Connecting Cutting-Edge AI Models and Agent Infra
A MCP for Claude Desktop / Claude Code / Windsurf / Cursor to build n8n workflows for you
MCP server to provide Figma layout information to AI coding agents like Cursor
This is MCP server for Claude that gives it terminal control, file system search and diff file editing capabilities
Browser MCP is a Model Context Provider (MCP) server that allows AI applications to control your browser
A Model Context Protocol (MCP) server and CLI that provides tools for agent use when working on iOS and macOS projects.
Run your own MCP server? See who uses it and what to fix.
Measure it with TrackMCP