pqc-migration-mcp
pqc-migration-mcp
让你的 AI 智能体获得它一直在猜测的后量子迁移事实。
通过 MCP 提供六个工具:凭据大小、分片数量、重组窗口、39 个失败族分类以及基准评分。问 Claude “我们的 ML-KEM-768 握手能否放进 BLE MTU?”,它会计算出答案,而不是估算一个。
📖 完整文档、教程和概念指南:https://nickharris808.github.io/pqc-toolkit/
为什么存在这个项目
智能体越来越多地参与 PQC 迁移工作,而它们恰恰在关键问题上自信地犯错:凭据实际有多大、会分成多少分片、在你的并发下是否存在安全的重组上限。这些是算术问题,不是判断问题——所以把算术交给智能体。
这里的协议层是零依赖的。MCP 是基于换行分隔 stdio 的 JSON-RPC 2.0,小到可以直接实现,并且让安装变得非常简单。
Related MCP server: attestix
安装
pip install git+https://github.com/nickharris808/pqc-migration-mcp这也会从其仓库拉取 pqc-sizes 和 pqc-mfb。目前它们还未发布到 PyPI,所以 pip install pqc-migration-mcp 目前无法使用。
30 秒快速上手
# talk to it directly -- it is line-delimited JSON-RPC on stdio
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | pqc-migration-mcpClaude Desktop
添加到 claude_desktop_config.json:
{
"mcpServers": {
"pqc-migration": {
"command": "pqc-migration-mcp"
}
}
}重启 Claude Desktop。六个工具会出现在连接器下。
工具
工具 | 回答的问题 |
| KEM+签名凭据有多少字节,逐组件计算? |
| 在此传输上有多少分片——分片现在是否强制? |
| 是否存在安全容量上限?如果不存在,什么并发 可以 工作? |
| 全部 39 个失败族,包含案例数和已发表的类似物 |
| 该族中什么会失效、在哪些设计中、每个设计做了什么? |
| 对 PQC-MFB 提交进行评分:覆盖率、回归、零覆盖族 |
工作示例——实际输出
传输是换行分隔的 JSON——每行一个完整对象。请将请求保持在一行;跨两行的请求会到达为两个不完整的请求,并返回两个 -32700 解析错误。
$ echo '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"reassembly_window","arguments":{"largest_legitimate_object":12000,"memory_budget":32768,"concurrency":3}}}' | pqc-migration-mcp服务器每行回复一个 JSON 对象。经过美化打印后,该回复的 content 负载是:
{
"budget": 32768,
"ceiling": 10922,
"concurrency": 3,
"explanation": "EMPTY WINDOW: floor 12,000 B > ceiling 10,922 B (short by 1,078 B). No capacity cap is both feasible and safe. Raise the budget to at least 36,000 B, reduce concurrency to at most 2, or choose a smaller credential.",
"floor": 12000,
"is_empty": true,
"max_safe_concurrency": 2,
"recommended_cap": null
}智能体得到判定以及能修复它的数字,因此它可以提出具体更改,而不是报告问题。
此服务器不会告诉你什么
它暴露检测。它不暴露修复。
智能体可以了解到某个设计在 krack_retransmission 上失败,以及未修复的设计具体做了什么。它无法获得关闭该问题的机制。这个边界是刻意的:一个返回修复方案的 MCP 工具会让任何用户在一个下午内枚举出整个封闭集合。
有一个测试会对全部 39 个族调用 describe_family,再加上所有其他工具,将响应拼接起来,如果输出中任何地方出现 repair_mechanism、repaired_detail 或 repaired_held,测试就会失败。
错误语义
领域错误——未知算法、未知族——会作为工具结果返回,带有 isError: true 和一条列出有效选项的消息,以便智能体自行纠正。只有协议故障才会变成 JSON-RPC 错误(-32601 未知方法/工具、-32602 参数错误、-32700 无法解析的行)。
格式错误的行不会终止循环;服务器会回复解析错误并继续服务。
测试
pip install -e ".[dev]" && pytest # 57 passed测试覆盖协议、每个工具、护城河边界,以及作为子进程驱动的真实 stdio 传输——包括检查stderr 保持为空,因为 MCP 客户端将 stdout 读作协议,杂散警告会混淆它们。
范围
算术、分类查找和评分。没有密码学、没有网络、没有遥测。它不检查你的实现。一个干净的答案意味着你的配置是合理的,而不是你的代码强制执行了它。
相关
pqc-sizes · pqc-mfb ·
pqc-guard-action · pqc-dos-embedded
关闭 39 个族是封闭核心所做的事情。相关主题已由已提交的临时专利申请覆盖。如需商业使用完整包络,请打开 GitHub Discussion 或在此仓库上提交 issue。
诚实的范围
这证明了什么。 智能体推理所用的算术和分类是正确的:真实的凭据大小、真实的分片数量、真实的窗口判定,以及真实的失败分类。
它不证明什么。
不证明智能体使用了答案。 这提供事实;它不监督这些事实被如何使用。
不检查你的代码。 这里没有工具读取你的实现。
不是修复通道。 每个工具只暴露检测。一个测试会对全部 39 个族调用
describe_family,再加上所有其他工具,如果输出中任何地方出现修复字段,测试就会失败。
错误。 领域问题会作为工具结果返回,带有 isError: true 和一条列出有效选项的消息,以便智能体自我纠正。只有协议故障才会变成 JSON-RPC 错误。
PQC 迁移工具包
为团队将认证密钥交换迁移到后量子而准备的十一个免费工具。它们发现和测量;它们不修复。
工具 | 作用 | 位置 |
大小、分片数量,以及双向重组窗口 | 源码 | |
适用于 Node 和浏览器的相同算术 | 源码 | |
当窗口为空时使构建失败 | GitHub Action | |
169 行 C 代码:在真实 64 KB 设备上的失败 | 源码 | |
在设备上重新验证边界,无需 SMT 求解器 | 源码 | |
用 Lean 4 证明的相同边界——0 个 | 源码 | |
可综合 RTL 中的门,5 个 Yosys 证明 | 源码 | |
pqc-migration-mcp ← 你在这里 | 面向 AI 智能体的六个 MCP 工具 | 源码 |
322 个案例 · 39 个失败族 · 评分器 | 源码 | |
作为数据集的基准 | HF | |
122 个命名形式化结果,6 个证明器 | HF | |
在浏览器中试用,无需安装 | HF Space |
刚接触? 端到端教程 用大约十分钟带你完成一个真实迁移,涵盖所有工具:大小 -> 窗口 -> CI 门 -> 基准。
赶时间? pqc-sizes 在五秒内告诉你凭据是否分片以及是否存在安全上限。pqc-explorer 在浏览器中做同样的事情,无需安装。
封闭核心
关闭 39 个失败族——降级绑定、重传安全安装、分片转录、漫游前向保密、多链路密钥分离、准入控制、组密钥绑定——是一个独立的专有代码库。相关主题已由已提交的临时专利申请覆盖。
这种划分是经过测量的,而非断言:在复制噪声控制下,32 个修复机制中只有 4 个在外部可区分,因此发布这些检测器不会泄露修复方案。
如需商业许可,请打开 GitHub Discussion 或在任何这些仓库上提交 issue。
许可证
Apache-2.0。参见 LICENSE 和 CONTRIBUTING.md。
Available Tools
6 toolscredential_sizeC
Total on-wire bytes for a KEM + signature credential, with a per-component breakdown.
| Name | Required | Description | Default |
|---|---|---|---|
| kem | No | KEM name, e.g. ML-KEM-768 | ML-KEM-768 |
| sig | No | Signature name, e.g. ML-DSA-65 | ML-DSA-65 |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the burden. It mentions a 'per-component breakdown' but does not specify the output format, side effects, or constraints like required permissions. Minimal disclosure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single sentence that efficiently conveys the core function. However, front-loading could be improved by adding an explicit verb. Still well-structured.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Adequate for a simple tool with two optional parameters, but lacks details on the return value format (e.g., boolean? object?). Without an output schema, more context would help.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with descriptions for both parameters. The description repeats the concept but adds no new meaning beyond what the schema provides. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool computes on-wire bytes for a credential with a breakdown, which distinguishes it from sibling tools like list_failure_families. However, the verb is implied rather than explicit (e.g., 'calculate').
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance on when to use this tool, when not to, or alternatives. The sibling tools are unrelated, but the description does not help the agent decide context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
describe_familyA
Detail for one failure family: the invariants it breaks, the unrepaired designs that fail it, and what each did. Does not return repairs.
| Name | Required | Description | Default |
|---|---|---|---|
| family | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations exist. Description mentions what is returned and what is not (repairs), but lacks information on side effects, permissions, or whether it is a read-only operation. Basic disclosure but not comprehensive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Single sentence, efficient and front-loaded with purpose. No redundant words, but a structured list of what is included might improve clarity without expanding length significantly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Describes output content (invariants, designs) but not structure or format. No output schema. Lacks guidance on the parameter value. Adequate for narrow use but insufficient for full autonomy.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0% for the only parameter 'family'. Description does not explain what the parameter value should be (e.g., family ID or name) or provide format examples. Fails to add meaning beyond the schema's type and required status.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states the tool provides detailed information for one failure family, including invariants and unrepaired designs, and explicitly excludes repairs. This distinguishes it from sibling tool list_failure_families, which likely lists all families.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Implies use when details on a specific family are needed, but does not explicitly state when to use versus siblings like list_failure_families or other tools. No alternatives or exclusions provided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
fragmentsB
How many fragments an object becomes on a transport, and whether fragmentation is therefore mandatory.
| Name | Required | Description | Default |
|---|---|---|---|
| object_bytes | Yes | ||
| frame_payload | Yes | usable payload bytes per frame |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must carry the full burden of behavioral disclosure. It indicates the tool calculates fragment count and mandatory status, but it does not disclose side effects, authorization needs, error conditions, or whether the operation is read-only. For a computation tool, the lack of safety information is a gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, concise sentence that immediately conveys the tool's purpose with no extraneous words. It is well-structured and front-loaded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple 2-parameter tool, the description tells what the tool computes, but it lacks information about the return format (the output schema is absent). The agent must infer whether the result is a number, boolean, or structured object. This is a moderate completeness gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is only 50% (frame_payload has a description). The tool description adds context by relating the parameters to object transport, but it does not explain what object_bytes is or provide details beyond the schema. It fails to compensate for the missing schema description of object_bytes.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states that the tool computes 'how many fragments an object becomes on a transport' and determines if fragmentation is mandatory. This is a specific verb+resource that distinguishes it from sibling tools like list_failure_families and reassembly_window.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is given on when to use this tool versus alternatives. The description does not mention prerequisites, exclusions, or comparisons with sibling tools. The agent must guess the appropriate context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_failure_familiesA
All 39 post-quantum migration failure families, with case counts and published prior-art analogues.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries full burden. It mentions output content but doesn't disclose behavioral traits such as read-only nature, permissions needed, rate limits, or any side effects. For a tool with no annotations, this is insufficient.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single, clear sentence with no extraneous information. Every word adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description provides reasonable context about return values (case counts, analogues). However, it lacks details like ordering, filtering, or any prerequisites. With no annotations, additional behavioral context would improve completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There are 0 parameters, so the schema provides no information. The description adds meaning by explaining what the tool returns, which is the full list. Baseline for 0 params is 4.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly specifies the verb 'list' and resource 'failure families', explicitly states 'All 39', and includes details on return content (case counts and prior-art analogues). This distinguishes it from sibling tools like 'describe_family' which likely focuses on one family.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies use case: get a comprehensive list of all failure families. It doesn't explicitly state when not to use or name alternatives, but the contrast with 'describe_family' is clear. No explicit exclusions or when-not guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
reassembly_windowC
The two-sided reassembly-capacity window. Returns is_empty=true when NO capacity cap is both feasible and safe, plus the maximum concurrency that would be safe.
| Name | Required | Description | Default |
|---|---|---|---|
| concurrency | Yes | ||
| memory_budget | Yes | ||
| largest_legitimate_object | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, and the description does not fully disclose behavior. It lacks information on side effects, authentication, safety, or what 'feasible and safe' means. The description is insufficient for an agent to understand the tool's full behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is brief with one sentence, but it could be more structured. It front-loads jargon and then specifies returns. No superfluous words, but clarity is sacrificed for brevity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description only partially describes the return value (is_empty and max concurrency). It does not cover error conditions, edge cases, or other potential return fields. The description is incomplete for effective use.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has no descriptions, and the tool's description does not explain the meaning of each parameter ('largest_legitimate_object', 'memory_budget', 'concurrency'). Minimal context is provided, leaving the agent guessing.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description gives a basic idea of the tool's purpose (computing a capacity window), but uses jargon ('two-sided reassembly-capacity window') and doesn't clearly state the action (e.g., 'compute' or 'get'). The return values are specified, providing some clarity.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance on when to use this tool versus its siblings. The description does not mention context, prerequisites, or alternatives.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
score_submissionB
Score a PQC-MFB submission ({case_id: bool}). Returns coverage, regressions, and which families have zero coverage.
| Name | Required | Description | Default |
|---|---|---|---|
| submission | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses return values (coverage, regressions, zero-coverage families) but does not mention side effects, required authentication, or whether the operation is read-only. Since no annotations are provided, the description bears full burden, and the lack of side-effect clarity is a gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single concise sentence that front-loads the verb and resource. However, the notation '{case_id: bool}' is somewhat cryptic and could be integrated into the schema or clarified.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the lack of output schema and detailed input schema, the description should provide more context on the input object structure and the exact format of the return values. It covers outputs but omits input details, making it incomplete for proper use.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 0% description coverage, and the description only hints at a 'case_id' field via '{case_id: bool}', which is not defined in the schema. The structure of the required 'submission' object is left entirely unexplained, so the description adds minimal value beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action (score) and the specific resource (PQC-MFB submission), and lists the outputs (coverage, regressions, zero-coverage families). This distinguishes it from sibling tools like list_failure_families or describe_family, which serve different purposes.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies the tool is used when you need to evaluate a submission, but it does not provide explicit guidance on when to use it vs. siblings, nor does it mention prerequisites or avoidance scenarios.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
6 tool updates
v0.1.0- First observed
credential_size - First observed
describe_family - First observed
fragments - First observed
list_failure_families - First observed
reassembly_window - First observed
score_submission
TDQS
Scored across 6 tools
Each tool targets a distinct aspect of PQC migration analysis: failure families, reassembly capacity, submission scoring, credential size, family details, and fragmentation. No overlaps in functionality.
Most tools follow a verb_noun pattern with underscores (list_failure_families, score_submission, describe_family). 'credential_size' and 'reassembly_window' are noun-like but still clear; 'fragments' is a single noun, slightly deviating.
The set includes 6 tools, which is well within the ideal 3-15 range. Each tool addresses a specific need without redundancy, making the scope manageable and focused.
The tools cover querying failure families and scoring submissions, but lack submission management, repair retrieval (noted in describe_family), and listing submissions. Some gaps exist for a full workflow.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Production-grade cryptography toolkit with 31 MCP tools for classical, PQC, and KMS workflows.
QuantumOracle — 18 post-quantum crypto tools: Kyber, Dilithium, hybrid schemes, migration.
AI-security knowledge as MCP: standards-mapped tools (OWASP, NIST, MITRE) for AI agents.
Tamper-evident proof creation and verification for AI agents via MCP, A2A, and REST.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables AI assistants to perform quantum-resistant cryptographic operations using NIST-standardized algorithms including ML-KEM, ML-DSA, and SPHINCS+. Supports key generation, encryption, digital signatures, and security analysis for post-quantum cryptography research and development.1MIT
- AlicenseNot gradedqualityBmaintenanceMCP server for compliance automation of AI agents, enabling EU AI Act compliance, verifiable credentials, and decentralized identity management with 47 tools across 9 modules.17Apache 2.0
- AlicenseBqualityDmaintenanceDefense-grade cryptographic compliance and analysis tools for MCP, including FIPS 140-3 validation, CNSA 2.0 analysis, post-quantum readiness assessment, and classical cipher utilities.181MIT
- AlicenseBqualityAmaintenanceEnables AI assistants to execute 463 CyberChef data manipulation operations—including encryption, encoding, and forensic analysis—as MCP tools.421,63819GPL 3.0