scan_repo
Inventory cryptography in a local directory tree to locate quantum-vulnerable algorithms and post-quantum schemes, reporting each with file, line, and coverage count.
Instructions
Inventory the cryptography inside one local directory tree, file by file.
Reads source, configuration (nginx.conf, sshd_config, .ini, .toml), CI pipelines,
Terraform and Kubernetes manifests under path. Returns each algorithm found with
its file and line, the mathematical family and standing of every post-quantum
scheme, and a coverage count.
Use this to answer what a specific project on this machine actually uses. Do not
use it to ask whether this server knows a given algorithm, or to explain how one is
classified without scanning anything -- list_algorithms answers that from the same
table and reads no files. It is also the wrong tool for a network endpoint, a
running host or a certificate store: it opens files on disk and nothing else.
Coverage is reported as a fraction with a base. files_scanned + unreadable_files + files_skipped_by_type == files_present. A file that could not be opened is listed,
never counted as scanned, because no findings in a file nobody read is not the same
as a file that is clean. Files skipped because this tool does not claim their type
are counted by extension, so the reader can judge the boundary rather than assume
past it.
Cost scales with the size of the tree, so a large monorepo takes proportionally longer; there is no cache and no partial mode.
Quoted lines are masked by default. Reading happens on this machine, but this
result does not stay on it: it is returned to a model, which is a place the
scanned line has not been before. A secret sharing a line with a finding -- a
token in the call that names the cipher -- would travel with it. Masking keeps
what a reader needs (the algorithm, the file, the line number, the shape of the
call) and removes what nobody asked for. Pass level="full" when the line
itself is the thing being examined.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | Directory to scan, absolute or relative to the working directory: a checked-out repository, a service directory, a config tree. Vendored and build directories (.git, node_modules, vendor, dist, build, target) are excluded and do not count toward files_present. | |
| level | No | How much of each matched line to return. `masked` (the default) keeps the characters that spell the algorithm and stars every other letter and digit; `full` returns the line as written; `trimmed` returns no line at all. File and line number are the same at every level. | masked |
| profile | No | Whose rules each `replacement` follows. `nist` (the default) is FIPS 203/204/205. The others read one national document each and say whom it addresses: us-cnsa2 (NSA, US National Security Systems), uk-ncsc, au-ism, ca-cccs, de-bsi, fr-anssi, nl-ncsc, eu-eccg (EU product certification), bg (no Bulgarian guidance found; EU roadmap dates). Detection is identical under every profile. | nist |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||