trackmcp
Back to directory

Open-source post-quantum readiness tooling by quantakrypto

10 stars TypeScriptOthers Updated Aug 17, 2026
crypto-agilitycryptographyharvest-now-decrypt-laterinfosecpost-quantumpqcpqc-migrationpqc-readinesspqcryptoq-dayquantumquantum-readinesssecurity-trainingencryption-strategypqc-certificationcbommcppost-quantum-cryptographysbomnist

Documentation

quantakrypto-tools

CI
License: Apache-2.0
OpenSSF Best Practices
npm @quantakrypto/core
npm @quantakrypto/qscan
npm @quantakrypto/mcp
npm @quantakrypto/sieve
npm @quantakrypto/agent
npm @quantakrypto/qprobe
Node ≥20
TypeScript strict
Runtime deps: 0
PQC targets: FIPS 203/204/205

Open-source post-quantum readiness tooling by quantakrypto.

Find quantum-vulnerable cryptography in any codebase, wire post-quantum readiness

into your editor and your CI, and conformance-test post-quantum implementations —

with zero runtime dependencies (Node built-ins only).

> Design goals: simple, clean, reusable code; zero runtime dependencies;

> everything documented, tested, and example-driven.

What's inside

ToolWhat it doesGet it
**qScan** (`@quantakrypto/qscan`)CLI that finds quantum-vulnerable crypto (RSA, (EC)DH, ECDSA, EdDSA, …) across 14 languages (JS/TS, Python, Go, Java/Kotlin/Scala, C#, Rust, Ruby, PHP, Elixir, C/C++, Swift, Objective-C, Dart, Solidity/Move/Cairo) and prints a readiness score. SARIF / JSON / CBOM / evidence (ISO 27001 A.8.24) / OpenVEX output, baselines, incremental & parallel scans. Compliance mandate gate: `--mandate cnsa-2.0` / `nist-ir-8547` reports each prohibited finding with its dated clause and fails the build on the mandate's deadlines (`--lead-months`, `--fail-now`). Opt-in `--triage` (BYOK LLM re-rank/explain) and a `qremediate` codemod CLI.`npx @quantakrypto/qscan ./`
**MCP** (`@quantakrypto/mcp`)Model Context Protocol server that gives AI coding agents post-quantum readiness tools (16 tools — scan, inventory, explain, suggest-hybrid, CBOM, plan-migration, triage, remediate, probe-endpoint, …). Local stdio + hostable HTTP.`claude mcp add quantakrypto npx @quantakrypto/mcp`
**Sieve** (`@quantakrypto/sieve`)Conformance battery for ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) implementations, driven over a JSON stdin/stdout protocol.`npx @quantakrypto/sieve --help`
**Action** (`@quantakrypto/action`)GitHub Action that runs the qScan/Sieve/qProbe checks in CI, writes SARIF for code-scanning upload, annotates the diff, and fails the build only on new quantum-vulnerable crypto.`uses: quantakrypto/pqc-tools/packages/action@v1`
**agent** (`@quantakrypto/agent`)Optional, zero-dependency BYOK (bring-your-own-key) LLM client (native `fetch`; Anthropic + OpenAI-compatible adapters) that powers qScan `--triage` and `qremediate --llm`. Networked, key-holding — kept isolated (see also qProbe).`npm i @quantakrypto/agent`
**qProbe** (`@quantakrypto/qprobe`)Actively probes live TLS/SSH endpoints you own for post-quantum readiness — PQC-hybrid key exchange (X25519MLKEM768) and classical certificate posture. Gated behind an ownership attestation; reports, never modifies ("engine disposes"). See THREAT-MODEL.`npx @quantakrypto/qprobe --i-own-this host`

All of qScan, MCP, the Action, agent, and qProbe share the engine in

**`@quantakrypto/core`** (`npm i @quantakrypto/core`) — detectors,

the vulnerable-dependency DB, the readiness score, SARIF/JSON/CBOM/evidence/OpenVEX

reporting, and the

offline agent-plane primitives (context redactor, `verify_fix` gate, codemods, patch

policy). Sieve is standalone: it tests *other* implementations and implements no

crypto itself.

Infrastructure coverage. Beyond application source, the shared `core` engine

carries config-scope detectors for Terraform/OpenTofu IaC and cloud KMS, JSON

Web Keys, Kubernetes / cert-manager / Istio, CI/CD artifact & code signing

(cosign/GPG/jarsigner/codesign/minisign), secrets at rest (SOPS/age, PGP, Sealed

Secrets), message brokers (Kafka/MQTT), databases (pgcrypto, libpq `sslmode`), and

JOSE/JWE key management — so `qscan`, the Action, and MCP flag infrastructure

crypto with no extra install. qProbe adds the live-endpoint dimension (see the

table above). The narrative anchor for infrastructure is *harvest now, decrypt

later*: data and secrets captured today are decryptable once a CRQC exists.

Quick start

bash
# 1. Scan a codebase for quantum-vulnerable cryptography.
npx @quantakrypto/qscan ./

# 2. Give your AI coding agent post-quantum readiness tools.
claude mcp add quantakrypto npx @quantakrypto/mcp

# 3. Conformance-test a post-quantum implementation (adapter speaks the JSON protocol).
npx @quantakrypto/sieve --impl "node ./my-impl.js" --param ml-kem-768

# 4. Gate against a compliance mandate's dated deadlines (CNSA 2.0 / NIST IR 8547).
#    Verdicts also ride in --format json/sarif/evidence; --policy lets an org
#    acknowledge families it is knowingly migrating (exempt from early gating).
npx @quantakrypto/qscan ./ --mandate cnsa-2.0 [--policy .quantakrypto/crypto-policy.json]

Add the CI gate by dropping

`packages/action/examples/quantum-readiness.yml`

into `.github/workflows/`, or wire it up directly:

yaml
- uses: quantakrypto/pqc-tools/packages/action@v1
  with:
    path: "."
    severity-threshold: "high"

Each package README has the full options reference and more examples:

qScan ·

MCP ·

Sieve ·

Action ·

core ·

agent.

Using quantakrypto alongside a PQC library (liboqs / OQS)

quantakrypto does not implement post-quantum cryptography, by design — it is

the scanner, the CI gate, and the conformance harness you wrap around a real PQC

library like liboqs / Open Quantum Safe. They

compose: quantakrypto finds and gates classical crypto (`qscan`, the Action),

tells you what to migrate to and in what order (`qscan --tier`, MCP

`plan_migration`, `qremediate`), and conformance-tests the replacement

(`sieve` runs any ML-KEM/ML-DSA/SLH-DSA implementation against FIPS 203/204/205,

with exact-value KATs when you supply official NIST ACVP vectors). liboqs

supplies the primitives.

See the worked end-to-end walkthrough — scan → migrate → verify → gate — in

**`examples/liboqs-migration/`**.

Workspace layout

code
quantakrypto-tools/
├── packages/
│   ├── core/     @quantakrypto/core    — shared engine (the contract lives in src/types.ts + src/index.ts)
│   ├── qscan/    @quantakrypto/qscan   — CLI
│   ├── mcp/      @quantakrypto/mcp     — MCP server (stdio now, HTTP scaffold for hosting)
│   ├── action/   @quantakrypto/action — GitHub Action
│   ├── sieve/    @quantakrypto/sieve   — conformance battery + JSON protocol
│   ├── agent/    @quantakrypto/agent   — opt-in BYOK LLM client (triage + remediation)
│   └── qprobe/   @quantakrypto/qprobe  — active TLS/SSH endpoint probing (gated; the only prober)
├── docs/         architecture, hosted-MCP design, improvement roadmap
└── examples/     end-to-end examples

Development

Requires Node ≥ 20.

bash
npm install        # links the workspaces
npm run build      # tsc --build (project references)
npm test           # node:test across all packages

The toolchain is intentionally tiny: TypeScript + `tsx` (to run `node:test` on

`.ts`) are the only dev dependencies; there are no runtime dependencies.

Documentation & compliance

Full documentation lives in **`docs/`**:

each library does, the load-bearing decisions, and the deliberate scope

boundaries. Start here.

each load-bearing choice (zero deps, shared core contract, two-plane agent, …).

could align to: NIST FIPS 203/204/205, SP 800-208, CNSA 2.0, SARIF, CWE,

ISO/IEC 27001 (A.8.24), Common Criteria, FIPS 140-3, EU DORA/NIS2, US

M-23-02 / NSM-10, and OSS assurance (SLSA, OpenSSF Scorecard, SPDX/REUSE).

Code of Conduct · Changelog.

License

Apache-2.0. The methodology is open; the assessments, attestation

reports, and deliverables are where the quantakrypto

practice lives.

Support & training

Questions, commercial support, or post-quantum readiness training for your team —

visit **quantakrypto.com** or email

**hello@quantakrypto.com**.

Frequently asked questions

What is pqc-tools?

pqc-tools is Open-source post-quantum readiness tooling by quantakrypto

How do I install pqc-tools?

Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.

Is pqc-tools open source?

Yes — it is hosted on GitHub at https://github.com/quantakrypto/pqc-tools and has 10 stars.

Related MCP tools

Run your own MCP server? See who uses it and what to fix.

Measure it with TrackMCP