Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,544Letters: 14Defects: 1,324counted 3 min ago
teppi

Server definition

Hash
sha256:d626c8ef2e2e00a61d5cccfcd40974e7690d435371b8d369f427ab78c39c2015
What it is
What a remote MCP server returned when asked what it offers: 11 tools

The blob, as servednamed by its sha256

{ "instructions": "quantakrypto checks code for quantum-vulnerable cryptography and recommends post-quantum (NIST PQC) migrations. Use scan_path / inventory_crypto to assess a path, list_rules to see detectors, and explain_finding / suggest_hybrid for remediation guidance.", "tools": [ { "description": "Deterministically attach your triage verdicts to their findings and re-sort by exposure (highest first). Never suppresses. Pass the same 'findings' array you triaged plus a 'verdicts' array of { fingerprint, exposureScore, priority, rationale }.", "inputSchema": { "additionalProperties": false, "properties": { "findings": { "description": "The findings that were triaged.", "items": { "description": "A single finding from `scan_path --format json`.", "properties": { "algorithm": { "description": "Classical algorithm family, when applicable.", "type": "string" }, "category": { "type": "string" }, "confidence": { "type": "string" }, "cwe": { "description": "e.g. \"CWE-327\".", "type": "string" }, "hndl": { "description": "Exposed to harvest-now-decrypt-later.", "type": "boolean" }, "location": { "description": "Where the finding is.", "properties": { "file": { "type": "string" }, "line": { "type": "number" } }, "required": [ "file" ], "type": "object" }, "message": { "type": "string" }, "remediation": { "type": "string" }, "ruleId": { "description": "Stable rule id, e.g. \"rsa-keygen\".", "type": "string" }, "severity": { "description": "critical | high | medium | low | info.", "type": "string" }, "title": { "type": "string" } }, "required": [ "ruleId", "location" ], "type": "object" }, "type": "array" }, "verdicts": { "description": "One verdict per finding, keyed by fingerprint.", "items": { "description": "A triage verdict for one finding.", "properties": { "exposureScore": { "description": "Real-world exposure (higher = more exposed).", "type": "number" }, "fingerprint": { "description": "Fingerprint of the finding this verdict applies to.", "type": "string" }, "priority": { "enum": [ "now", "soon", "later" ], "type": "string" }, "rationale": { "description": "Why this exposure score / priority.", "type": "string" } }, "required": [ "fingerprint", "exposureScore", "priority", "rationale" ], "type": "object" }, "type": "array" } }, "required": [ "findings", "verdicts" ], "type": "object" }, "name": "apply_triage", "outputSchema": null }, { "description": "Deterministically VERIFY a proposed fix before writing it — runs the same patch-policy + verify_fix + blast-radius gates as `qremediate` (offline, no key, no network). Give the finding, the file's current content, and your proposed FULL corrected content; returns approved:true only if the patch is in-policy, clears the finding, adds no new finding, introduces no network/exec sink, and is bounded in size. This does NOT write the file — you write it, only when approved, and never auto-merge.", "inputSchema": { "additionalProperties": false, "properties": { "finding": { "description": "The scan finding being fixed (needs a string ruleId and location.file).", "type": "object" }, "newContent": { "description": "Your proposed full corrected file content.", "type": "string" }, "originalContent": { "description": "The file's current full content.", "type": "string" } }, "required": [ "finding", "originalContent", "newContent" ], "type": "object" }, "name": "apply_verified_patch", "outputSchema": null }, { "description": "Check whether a package is in quantakrypto's known quantum-vulnerable dependency database (the classical crypto it exposes). Provide 'name' and optional 'ecosystem' (default npm).", "inputSchema": { "additionalProperties": false, "properties": { "ecosystem": { "description": "Package ecosystem. Default: npm.", "type": "string" }, "name": { "description": "Package name to look up (e.g. 'node-forge', 'jsonwebtoken').", "type": "string" } }, "required": [ "name" ], "type": "object" }, "name": "check_dependency", "outputSchema": null }, { "description": "Explain a quantakrypto finding and its post-quantum remediation. Provide a ruleId (e.g. 'forge-rsa-keygen', 'elliptic-ec', 'node-rsa', 'pem-ec-private-key') and/or an algorithm (e.g. 'RSA', 'ECDSA'). The ruleId is resolved against the core detector set, so library and config rules explain correctly.", "inputSchema": { "additionalProperties": false, "properties": { "algorithm": { "description": "The classical algorithm family involved (e.g. RSA, ECDH, ECDSA).", "type": "string" }, "ruleId": { "description": "The finding's rule id, matching a detector id prefix.", "type": "string" } }, "type": "object" }, "name": "explain_finding", "outputSchema": null }, { "description": "Return before/after code examples for migrating a classical algorithm to a post-quantum / hybrid replacement. Provide an 'algorithm' (RSA, ECDH, ECDSA, …) or a 'ruleId' from a finding.", "inputSchema": { "additionalProperties": false, "properties": { "algorithm": { "description": "Classical algorithm family to migrate away from.", "type": "string" }, "ruleId": { "description": "A finding's ruleId (resolved to its algorithm).", "type": "string" } }, "type": "object" }, "name": "get_fix_examples", "outputSchema": null }, { "description": "List the quantakrypto detector catalog: every detector id and what it looks for.", "inputSchema": { "additionalProperties": false, "properties": {}, "type": "object" }, "name": "list_rules", "outputSchema": null }, { "description": "Produce a deterministic remediation REQUEST bundle (rubric + fix schema + per-finding metadata + fingerprints) for YOU (the host agent) to fix. This tool calls no model and needs no key. For each finding, propose the corrected FULL file content, then VERIFY with verify_fix and keep only fixes that clear the finding. Never touch files with secrets; never auto-merge. Pass 'findings' from scan_path --format json.", "inputSchema": { "additionalProperties": false, "properties": { "findings": { "description": "Findings from a scan's JSON output.", "items": { "description": "A single finding from `scan_path --format json`.", "properties": { "algorithm": { "description": "Classical algorithm family, when applicable.", "type": "string" }, "category": { "type": "string" }, "confidence": { "type": "string" }, "cwe": { "description": "e.g. \"CWE-327\".", "type": "string" }, "hndl": { "description": "Exposed to harvest-now-decrypt-later.", "type": "boolean" }, "location": { "description": "Where the finding is.", "properties": { "file": { "type": "string" }, "line": { "type": "number" } }, "required": [ "file" ], "type": "object" }, "message": { "type": "string" }, "remediation": { "type": "string" }, "ruleId": { "description": "Stable rule id, e.g. \"rsa-keygen\".", "type": "string" }, "severity": { "description": "critical | high | medium | low | info.", "type": "string" }, "title": { "type": "string" } }, "required": [ "ruleId", "location" ], "type": "object" }, "type": "array" } }, "required": [ "findings" ], "type": "object" }, "name": "remediate_findings", "outputSchema": null }, { "description": "Compute the readiness-score and HNDL change between two finding sets (e.g. before and after a migration). Pass 'before' and 'after' as arrays of findings from scan_path --format json.", "inputSchema": { "additionalProperties": false, "properties": { "after": { "description": "Findings after the change.", "items": { "description": "A single finding from `scan_path --format json`.", "properties": { "algorithm": { "description": "Classical algorithm family, when applicable.", "type": "string" }, "category": { "type": "string" }, "confidence": { "type": "string" }, "cwe": { "description": "e.g. \"CWE-327\".", "type": "string" }, "hndl": { "description": "Exposed to harvest-now-decrypt-later.", "type": "boolean" }, "location": { "description": "Where the finding is.", "properties": { "file": { "type": "string" }, "line": { "type": "number" } }, "required": [ "file" ], "type": "object" }, "message": { "type": "string" }, "remediation": { "type": "string" }, "ruleId": { "description": "Stable rule id, e.g. \"rsa-keygen\".", "type": "string" }, "severity": { "description": "critical | high | medium | low | info.", "type": "string" }, "title": { "type": "string" } }, "required": [ "ruleId", "location" ], "type": "object" }, "type": "array" }, "before": { "description": "Findings before the change (from a scan's JSON findings).", "items": { "description": "A single finding from `scan_path --format json`.", "properties": { "algorithm": { "description": "Classical algorithm family, when applicable.", "type": "string" }, "category": { "type": "string" }, "confidence": { "type": "string" }, "cwe": { "description": "e.g. \"CWE-327\".", "type": "string" }, "hndl": { "description": "Exposed to harvest-now-decrypt-later.", "type": "boolean" }, "location": { "description": "Where the finding is.", "properties": { "file": { "type": "string" }, "line": { "type": "number" } }, "required": [ "file" ], "type": "object" }, "message": { "type": "string" }, "remediation": { "type": "string" }, "ruleId": { "description": "Stable rule id, e.g. \"rsa-keygen\".", "type": "string" }, "severity": { "description": "critical | high | medium | low | info.", "type": "string" }, "title": { "type": "string" } }, "required": [ "ruleId", "location" ], "type": "object" }, "type": "array" } }, "required": [ "before", "after" ], "type": "object" }, "name": "score_delta", "outputSchema": null }, { "description": "Recommend a post-quantum / hybrid migration. Provide an 'algorithm' (e.g. RSA, ECDH, ECDSA) or free-text 'context' describing the usage. Set 'tier' to 'category-5' for CNSA 2.0 / national-security systems.", "inputSchema": { "additionalProperties": false, "properties": { "algorithm": { "description": "Classical algorithm family to migrate away from.", "type": "string" }, "context": { "description": "Free-text description of the cryptographic usage (used when no algorithm is given).", "type": "string" }, "tier": { "description": "Security tier: 'category-3' (default, commercial — ML-KEM-768 / ML-DSA-65) or 'category-5' (CNSA 2.0 / NSS, long-lived secrets — ML-KEM-1024 / ML-DSA-87).", "enum": [ "category-3", "category-5" ], "type": "string" } }, "type": "object" }, "name": "suggest_hybrid", "outputSchema": null }, { "description": "Produce a deterministic triage REQUEST bundle (rubric + verdict schema + per-finding metadata) for YOU (the host agent) to reason over. This tool does NOT call any model and needs no API key. Assess each finding's real-world exposure, then call apply_triage with your verdicts. Pass 'findings' as an array from scan_path --format json.", "inputSchema": { "additionalProperties": false, "properties": { "findings": { "description": "Findings from a scan's JSON output.", "items": { "description": "A single finding from `scan_path --format json`.", "properties": { "algorithm": { "description": "Classical algorithm family, when applicable.", "type": "string" }, "category": { "type": "string" }, "confidence": { "type": "string" }, "cwe": { "description": "e.g. \"CWE-327\".", "type": "string" }, "hndl": { "description": "Exposed to harvest-now-decrypt-later.", "type": "boolean" }, "location": { "description": "Where the finding is.", "properties": { "file": { "type": "string" }, "line": { "type": "number" } }, "required": [ "file" ], "type": "object" }, "message": { "type": "string" }, "remediation": { "type": "string" }, "ruleId": { "description": "Stable rule id, e.g. \"rsa-keygen\".", "type": "string" }, "severity": { "description": "critical | high | medium | low | info.", "type": "string" }, "title": { "type": "string" } }, "required": [ "ruleId", "location" ], "type": "object" }, "type": "array" } }, "required": [ "findings" ], "type": "object" }, "name": "triage_findings", "outputSchema": null }, { "description": "Run the quantakrypto detectors over a code snippet (NOT the filesystem) and report any classical crypto that remains. Use this to confirm an edit actually removed the quantum-vulnerable usage. Provide 'code' plus a 'language' or 'filename'.", "inputSchema": { "additionalProperties": false, "properties": { "code": { "description": "The source code to check.", "type": "string" }, "filename": { "description": "Optional filename; its extension selects the detectors (overrides 'language').", "type": "string" }, "language": { "description": "Language of the code (js, ts, python, go, java, csharp, rust, ruby, c, …).", "type": "string" } }, "required": [ "code" ], "type": "object" }, "name": "verify_fix", "outputSchema": null } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:d626c8ef2e2e00a61d5cccfcd40974e7690d435371b8d369f427ab78c39c2015 | sha256sum