Documentation

Rules and scoring

The full rule catalogue, and the arithmetic behind the two scores. Taken from the rule definitions in the source.

Two classes of rule

Every rule belongs to one of two classes, because they land on different calendars and only one of them is a defect.

  • Weakness rules describe cryptography that is wrong today, on a classical computer, with no quantum computer involved. Each carries a CWE. This is ordinary security work.
  • Inventory rules describe cryptography that is correct today but sits on a migration clock. Under NIST IR 8547, RSA and elliptic-curve cryptography are deprecated in 2030 and disallowed in 2035. Each carries a migration priority instead of a CWE.

Weakness rules

Nine rules. These feed the Weakness Score and can fail a build.

RuleSeverityCWEDetects
CRYPTO-HASH-BROKEN-001HighCWE-328MD5, SHA-1. Chosen-prefix collisions against both are practical on commodity hardware.
CRYPTO-CIPHER-BROKEN-001HighCWE-327DES, 3DES, RC4, Blowfish.
CRYPTO-MODE-ECB-001HighCWE-327ECB block-cipher mode, which leaks plaintext structure.
CRYPTO-RNG-INSECURE-001CriticalCWE-338Non-cryptographic randomness used in a security context: keys, nonces, tokens, salts.
CRYPTO-IV-STATIC-001HighCWE-329Hardcoded or all-zero initialisation vectors.
CRYPTO-TLS-VERIFY-OFF-001CriticalCWE-295Disabled certificate or hostname verification.
CRYPTO-KDF-WEAK-001HighCWE-916Weak or unsalted password hashing.
CRYPTO-KEYSIZE-WEAK-001HighCWE-326Undersized RSA, DH or EC parameters.
SEC-SECRET-001CriticalCWE-798Hardcoded credentials, API keys and private keys.

Inventory rules

Ten rules. These build the migration inventory and the CBOM. They never fail a build.

RuleMigration priorityDetects
PQC-WALLET-001CriticalPrivate keys, seed phrases, HD wallets, keystores.
PQC-VALIDATOR-001CriticalValidator, governance, bridge, treasury and admin keys.
PQC-RSA-001HighRSA usage.
PQC-ECC-001HighECDSA, Ed25519, secp256k1, X25519, Schnorr, BLS.
PQC-SIGN-001HighSigning and verification flows.
PQC-EXCHANGE-001HighAPI credentials, HMAC, withdrawal and custody flows.
PQC-TLS-001MediumTLS and HTTPS dependencies, the harvest-now-decrypt-later surface.
PQC-NONCE-001MediumSignature nonces and RFC 6979 handling.
PQC-HASH-001LowHash functions. Inventory only: hashes are not quantum-broken.
PQC-RNG-001LowRandomness sources.

Only Critical and High priorities count as migration surface. Hash and RNG inventory is recorded but excluded, because replacing SHA-256 is not post-quantum migration work.

How the Weakness Score is computed

Each reportable weakness adds its severity weight, and the total is capped at 100.

SeverityWeight
Critical10
High7
Medium4
Low2
Info1

Baselined findings and low-confidence matches do not count. A match in a comment never moves the score.

ScoreBand
80–100Critical
50–79High
20–49Medium
1–19Low
0None detected

How Migration Exposure is computed

Exposure is banded on breadth, not count: one file with 200 ECDSA calls is a smaller migration than 200 files with one call each. The band comes from the percentage of scanned files that contain critical or high-priority inventory findings.

Files affectedBand
50% or morePervasive
20–49%Extensive
5–19%Moderate
under 5%Contained
no sitesNone detected

Confidence and noise

Every match is graded before it reaches the report.

LevelMeaningIn the reportIn the score
HighA specific pattern in a code context.YesYes
MediumA real signal that needs manual confirmation.YesYes
LowA generic term, a comment, or a string sitting alone in a data table.Likely Noise section onlyNo

Low-confidence matches are listed rather than dropped, so the suppression is auditable. If a pattern matters in your repository, you can see it there and promote it to a rule.

What this is not

This is not a formal security audit. It does not prove a project is vulnerable, and it does not prove a project is quantum-safe. Absence of a finding is not absence of the algorithm.

Hash functions and symmetric primitives are not broken by quantum computers. Grover's algorithm gives at most a quadratic speedup on preimage search, which is handled with larger security margins. SHA-256 is fine. Any tool that tells you otherwise is wrong, and the report says so in its own words.