Skip to main content
Glama

pqc-migration-mcp

license mcp ci deps

Give your AI agent the post-quantum migration facts it keeps guessing at.

Six tools over MCP: credential sizes, fragment counts, the reassembly window, the 39-family failure taxonomy, and benchmark scoring. Ask Claude "will our ML-KEM-768 handshake fit in a BLE MTU?" and it computes the answer instead of estimating one.

📖 Full documentation, tutorial and conceptual guide: https://nickharris808.github.io/pqc-toolkit/


Why this exists

Agents are increasingly doing PQC migration work, and they are confidently wrong about exactly the things that matter: how big a credential actually is, how many fragments it becomes, and whether a safe reassembly cap exists at your concurrency. Those are arithmetic, not judgement — so hand the agent the arithmetic.

The protocol layer here is dependency-free. MCP is JSON-RPC 2.0 over line-delimited stdio, which is small enough to implement directly and keeps the install trivial.

Related MCP server: attestix

Install

pip install git+https://github.com/nickharris808/pqc-migration-mcp

This pulls pqc-sizes and pqc-mfb from their repositories too. Not on PyPI yet, so pip install pqc-migration-mcp does not work today.

30-second quickstart

# talk to it directly -- it is line-delimited JSON-RPC on stdio
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | pqc-migration-mcp

Claude Desktop

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "pqc-migration": {
      "command": "pqc-migration-mcp"
    }
  }
}

Restart Claude Desktop. The six tools appear under the connector.

Tools

Tool

Answers

credential_size

How many bytes is a KEM+signature credential, component by component?

fragments

How many fragments on this transport — and is fragmentation now mandatory?

reassembly_window

Does a safe capacity cap exist at all? If not, what concurrency would work?

list_failure_families

All 39 failure families, with case counts and published analogues

describe_family

What breaks in this family, in which designs, and what did each do?

score_submission

Score a PQC-MFB submission: coverage, regressions, zero-coverage families

Worked example — actual output

The transport is line-delimited JSON — one complete object per line. Keep the request on a single line; a request wrapped across two lines arrives as two incomplete ones and comes back as two -32700 parse errors.

$ echo '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"reassembly_window","arguments":{"largest_legitimate_object":12000,"memory_budget":32768,"concurrency":3}}}' | pqc-migration-mcp

The server replies with one JSON object per line. Pretty-printed, the content payload of that reply is:

{
  "budget": 32768,
  "ceiling": 10922,
  "concurrency": 3,
  "explanation": "EMPTY WINDOW: floor 12,000 B > ceiling 10,922 B (short by 1,078 B). No capacity cap is both feasible and safe. Raise the budget to at least 36,000 B, reduce concurrency to at most 2, or choose a smaller credential.",
  "floor": 12000,
  "is_empty": true,
  "max_safe_concurrency": 2,
  "recommended_cap": null
}

The agent gets a verdict and the number that would fix it, so it can propose a concrete change rather than reporting a problem.

What this server will not tell you

It exposes detection. It does not expose repairs.

An agent can learn that a design fails krack_retransmission and exactly what the unrepaired design did. It cannot obtain the mechanism that closes it. That boundary is deliberate: an MCP tool returning repairs would let any user enumerate the entire closed set in an afternoon.

There is a test that calls describe_family for all 39 families plus every other tool, concatenates the responses, and fails if repair_mechanism, repaired_detail or repaired_held appears anywhere in the output.

Error semantics

Domain errors — an unknown algorithm, an unknown family — come back as a tool result with isError: true and a message naming the valid options, so the agent can correct itself. Only protocol faults become JSON-RPC errors (-32601 unknown method/tool, -32602 bad arguments, -32700 unparseable line).

A malformed line does not kill the loop; the server replies with a parse error and keeps serving.

Tests

pip install -e ".[dev]" && pytest      # 57 passed

Tests cover the protocol, every tool, the moat boundary, and the real stdio transport driven as a subprocess — including a check that stderr stays empty, since MCP clients read stdout as protocol and stray warnings confuse them.

Scope

Arithmetic, taxonomy lookup and scoring. No cryptography, no network, no telemetry. It does not inspect your implementation. A clean answer means your configuration is sound, not that your code enforces it.

pqc-sizes · pqc-mfb · pqc-guard-action · pqc-dos-embedded

Closing the 39 families is what the closed core does. Relevant subject matter is covered by a filed provisional patent application. For commercial use of the full envelope, open a GitHub Discussion or an issue on this repository.

Honest scope

What this proves. That the arithmetic and taxonomy an agent is reasoning with are correct: real credential sizes, real fragment counts, a real window verdict, and the real failure taxonomy.

What it does NOT prove.

  • Not that the agent used the answer. This supplies facts; it does not supervise what is done with them.

  • Not an inspection of your code. No tool here reads your implementation.

  • Not a repair channel. Every tool exposes detection only. A test calls describe_family for all 39 families plus every other tool and fails if a repair field appears anywhere in the output.

Errors. Domain problems come back as tool results with isError: true and a message naming valid options, so an agent can self-correct. Only protocol faults become JSON-RPC errors.


The PQC migration toolkit

Eleven free tools for teams moving authenticated key exchange to post-quantum. They find and measure; they do not repair.

Tool

What it does

Where

pqc-sizes

Sizes, fragment counts, and the two-sided reassembly window

source

pqc-sizes-js

The same arithmetic for Node and the browser

source

pqc-guard-action

Fail the build when the window is empty

GitHub Action

pqc-dos-embedded

169 lines of C: the failure on a real 64 KB device

source

farkas-check

Re-verify the bound on-device, no SMT solver

source

pqc-bounds-lean

The same bound in Lean 4 — 0 sorry, 0 imports

source

pqc-dos-gate-rtl

The gate in synthesizable RTL, 5 Yosys proofs

source

pqc-migration-mcp ← you are here

Six MCP tools for AI agents

source

pqc-mfb

322 cases · 39 failure families · scorer

source

pqc-mfb (data)

The benchmark as a dataset

HF

pqc-formal-corpus

122 named formal results, 6 provers

HF

pqc-explorer

Try it in your browser, no install

HF Space

New here? The end-to-end tutorial walks one realistic migration through all of them in about ten minutes: sizes -> window -> CI gate -> benchmark.

In a hurry? pqc-sizes tells you in five seconds whether your credential fragments and whether a safe cap exists. pqc-explorer does the same in a browser, with no install.

The closed core

Closing the 39 failure families — downgrade binding, retransmission-safe installation, fragmentation transcripts, roaming forward secrecy, multi-link key separation, admission control, group-key binding — is a separate proprietary codebase. Relevant subject matter is covered by a filed provisional patent application.

That split is measured, not asserted: under a replicate noise control only 4 of 32 repair mechanisms are externally distinguishable, so publishing these detectors does not disclose the repairs.

For commercial licensing, open a GitHub Discussion or an issue on any of these repos.

License

Apache-2.0. See LICENSE and CONTRIBUTING.md.

Available Tools

6 tools
credential_sizeC

Total on-wire bytes for a KEM + signature credential, with a per-component breakdown.

ParametersJSON Schema
NameRequiredDescriptionDefault
kemNoKEM name, e.g. ML-KEM-768ML-KEM-768
sigNoSignature name, e.g. ML-DSA-65ML-DSA-65

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the burden. It mentions a 'per-component breakdown' but does not specify the output format, side effects, or constraints like required permissions. Minimal disclosure.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single sentence that efficiently conveys the core function. However, front-loading could be improved by adding an explicit verb. Still well-structured.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Adequate for a simple tool with two optional parameters, but lacks details on the return value format (e.g., boolean? object?). Without an output schema, more context would help.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with descriptions for both parameters. The description repeats the concept but adds no new meaning beyond what the schema provides. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool computes on-wire bytes for a credential with a breakdown, which distinguishes it from sibling tools like list_failure_families. However, the verb is implied rather than explicit (e.g., 'calculate').

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance on when to use this tool, when not to, or alternatives. The sibling tools are unrelated, but the description does not help the agent decide context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

describe_familyA

Detail for one failure family: the invariants it breaks, the unrepaired designs that fail it, and what each did. Does not return repairs.

ParametersJSON Schema
NameRequiredDescriptionDefault
familyYes

TDQS

A3.5/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations exist. Description mentions what is returned and what is not (repairs), but lacks information on side effects, permissions, or whether it is a read-only operation. Basic disclosure but not comprehensive.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Single sentence, efficient and front-loaded with purpose. No redundant words, but a structured list of what is included might improve clarity without expanding length significantly.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Describes output content (invariants, designs) but not structure or format. No output schema. Lacks guidance on the parameter value. Adequate for narrow use but insufficient for full autonomy.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0% for the only parameter 'family'. Description does not explain what the parameter value should be (e.g., family ID or name) or provide format examples. Fails to add meaning beyond the schema's type and required status.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states the tool provides detailed information for one failure family, including invariants and unrepaired designs, and explicitly excludes repairs. This distinguishes it from sibling tool list_failure_families, which likely lists all families.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Implies use when details on a specific family are needed, but does not explicitly state when to use versus siblings like list_failure_families or other tools. No alternatives or exclusions provided.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

fragmentsB

How many fragments an object becomes on a transport, and whether fragmentation is therefore mandatory.

ParametersJSON Schema
NameRequiredDescriptionDefault
object_bytesYes
frame_payloadYesusable payload bytes per frame

TDQS

B3.2/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must carry the full burden of behavioral disclosure. It indicates the tool calculates fragment count and mandatory status, but it does not disclose side effects, authorization needs, error conditions, or whether the operation is read-only. For a computation tool, the lack of safety information is a gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, concise sentence that immediately conveys the tool's purpose with no extraneous words. It is well-structured and front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple 2-parameter tool, the description tells what the tool computes, but it lacks information about the return format (the output schema is absent). The agent must infer whether the result is a number, boolean, or structured object. This is a moderate completeness gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is only 50% (frame_payload has a description). The tool description adds context by relating the parameters to object transport, but it does not explain what object_bytes is or provide details beyond the schema. It fails to compensate for the missing schema description of object_bytes.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states that the tool computes 'how many fragments an object becomes on a transport' and determines if fragmentation is mandatory. This is a specific verb+resource that distinguishes it from sibling tools like list_failure_families and reassembly_window.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance is given on when to use this tool versus alternatives. The description does not mention prerequisites, exclusions, or comparisons with sibling tools. The agent must guess the appropriate context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_failure_familiesA

All 39 post-quantum migration failure families, with case counts and published prior-art analogues.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A3.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden. It mentions output content but doesn't disclose behavioral traits such as read-only nature, permissions needed, rate limits, or any side effects. For a tool with no annotations, this is insufficient.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single, clear sentence with no extraneous information. Every word adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no output schema, the description provides reasonable context about return values (case counts, analogues). However, it lacks details like ordering, filtering, or any prerequisites. With no annotations, additional behavioral context would improve completeness.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

There are 0 parameters, so the schema provides no information. The description adds meaning by explaining what the tool returns, which is the full list. Baseline for 0 params is 4.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly specifies the verb 'list' and resource 'failure families', explicitly states 'All 39', and includes details on return content (case counts and prior-art analogues). This distinguishes it from sibling tools like 'describe_family' which likely focuses on one family.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies use case: get a comprehensive list of all failure families. It doesn't explicitly state when not to use or name alternatives, but the contrast with 'describe_family' is clear. No explicit exclusions or when-not guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

reassembly_windowC

The two-sided reassembly-capacity window. Returns is_empty=true when NO capacity cap is both feasible and safe, plus the maximum concurrency that would be safe.

ParametersJSON Schema
NameRequiredDescriptionDefault
concurrencyYes
memory_budgetYes
largest_legitimate_objectYes

TDQS

C2.4/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, and the description does not fully disclose behavior. It lacks information on side effects, authentication, safety, or what 'feasible and safe' means. The description is insufficient for an agent to understand the tool's full behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is brief with one sentence, but it could be more structured. It front-loads jargon and then specifies returns. No superfluous words, but clarity is sacrificed for brevity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description only partially describes the return value (is_empty and max concurrency). It does not cover error conditions, edge cases, or other potential return fields. The description is incomplete for effective use.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has no descriptions, and the tool's description does not explain the meaning of each parameter ('largest_legitimate_object', 'memory_budget', 'concurrency'). Minimal context is provided, leaving the agent guessing.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose3/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description gives a basic idea of the tool's purpose (computing a capacity window), but uses jargon ('two-sided reassembly-capacity window') and doesn't clearly state the action (e.g., 'compute' or 'get'). The return values are specified, providing some clarity.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance on when to use this tool versus its siblings. The description does not mention context, prerequisites, or alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

score_submissionB

Score a PQC-MFB submission ({case_id: bool}). Returns coverage, regressions, and which families have zero coverage.

ParametersJSON Schema
NameRequiredDescriptionDefault
submissionYes

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses return values (coverage, regressions, zero-coverage families) but does not mention side effects, required authentication, or whether the operation is read-only. Since no annotations are provided, the description bears full burden, and the lack of side-effect clarity is a gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single concise sentence that front-loads the verb and resource. However, the notation '{case_id: bool}' is somewhat cryptic and could be integrated into the schema or clarified.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the lack of output schema and detailed input schema, the description should provide more context on the input object structure and the exact format of the return values. It covers outputs but omits input details, making it incomplete for proper use.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 0% description coverage, and the description only hints at a 'case_id' field via '{case_id: bool}', which is not defined in the schema. The structure of the required 'submission' object is left entirely unexplained, so the description adds minimal value beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the action (score) and the specific resource (PQC-MFB submission), and lists the outputs (coverage, regressions, zero-coverage families). This distinguishes it from sibling tools like list_failure_families or describe_family, which serve different purposes.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies the tool is used when you need to evaluate a submission, but it does not provide explicit guidance on when to use it vs. siblings, nor does it mention prerequisites or avoidance scenarios.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 6 tool updatesv0.1.0
    • First observedcredential_size
    • First observeddescribe_family
    • First observedfragments
    • First observedlist_failure_families
    • First observedreassembly_window
    • First observedscore_submission

TDQS

B3.3/5.0

Scored across 6 tools

Disambiguation5/5

Each tool targets a distinct aspect of PQC migration analysis: failure families, reassembly capacity, submission scoring, credential size, family details, and fragmentation. No overlaps in functionality.

Naming Consistency4/5

Most tools follow a verb_noun pattern with underscores (list_failure_families, score_submission, describe_family). 'credential_size' and 'reassembly_window' are noun-like but still clear; 'fragments' is a single noun, slightly deviating.

Tool Count5/5

The set includes 6 tools, which is well within the ideal 3-15 range. Each tool addresses a specific need without redundancy, making the scope manageable and focused.

Completeness3/5

The tools cover querying failure families and scoring submissions, but lack submission management, repair retrieval (noted in describe_family), and listing submissions. Some gaps exist for a full workflow.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI assistants to perform quantum-resistant cryptographic operations using NIST-standardized algorithms including ML-KEM, ML-DSA, and SPHINCS+. Supports key generation, encryption, digital signatures, and security analysis for post-quantum cryptography research and development.
    1
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    MCP server for compliance automation of AI agents, enabling EU AI Act compliance, verifiable credentials, and decentralized identity management with 47 tools across 9 modules.
    17
    Apache 2.0
  • A
    license
    B
    quality
    D
    maintenance
    Defense-grade cryptographic compliance and analysis tools for MCP, including FIPS 140-3 validation, CNSA 2.0 analysis, post-quantum readiness assessment, and classical cipher utilities.
    18
    1
    MIT
  • A
    license
    B
    quality
    A
    maintenance
    Enables AI assistants to execute 463 CyberChef data manipulation operations—including encryption, encoding, and forensic analysis—as MCP tools.
    42
    1,638
    19
    GPL 3.0