Documentation
Rules and scoring
The full rule catalogue, and the arithmetic behind the two scores. Taken from the rule definitions in the source.
Two classes of rule
Every rule belongs to one of two classes, because they land on different calendars and only one of them is a defect.
- Weakness rules describe cryptography that is wrong today, on a classical computer, with no quantum computer involved. Each carries a CWE. This is ordinary security work.
- Inventory rules describe cryptography that is correct today but sits on a migration clock. Under NIST IR 8547, RSA and elliptic-curve cryptography are deprecated in 2030 and disallowed in 2035. Each carries a migration priority instead of a CWE.
Weakness rules
Nine rules. These feed the Weakness Score and can fail a build.
| Rule | Severity | CWE | Detects |
|---|---|---|---|
CRYPTO-HASH-BROKEN-001 | High | CWE-328 | MD5, SHA-1. Chosen-prefix collisions against both are practical on commodity hardware. |
CRYPTO-CIPHER-BROKEN-001 | High | CWE-327 | DES, 3DES, RC4, Blowfish. |
CRYPTO-MODE-ECB-001 | High | CWE-327 | ECB block-cipher mode, which leaks plaintext structure. |
CRYPTO-RNG-INSECURE-001 | Critical | CWE-338 | Non-cryptographic randomness used in a security context: keys, nonces, tokens, salts. |
CRYPTO-IV-STATIC-001 | High | CWE-329 | Hardcoded or all-zero initialisation vectors. |
CRYPTO-TLS-VERIFY-OFF-001 | Critical | CWE-295 | Disabled certificate or hostname verification. |
CRYPTO-KDF-WEAK-001 | High | CWE-916 | Weak or unsalted password hashing. |
CRYPTO-KEYSIZE-WEAK-001 | High | CWE-326 | Undersized RSA, DH or EC parameters. |
SEC-SECRET-001 | Critical | CWE-798 | Hardcoded credentials, API keys and private keys. |
Inventory rules
Ten rules. These build the migration inventory and the CBOM. They never fail a build.
| Rule | Migration priority | Detects |
|---|---|---|
PQC-WALLET-001 | Critical | Private keys, seed phrases, HD wallets, keystores. |
PQC-VALIDATOR-001 | Critical | Validator, governance, bridge, treasury and admin keys. |
PQC-RSA-001 | High | RSA usage. |
PQC-ECC-001 | High | ECDSA, Ed25519, secp256k1, X25519, Schnorr, BLS. |
PQC-SIGN-001 | High | Signing and verification flows. |
PQC-EXCHANGE-001 | High | API credentials, HMAC, withdrawal and custody flows. |
PQC-TLS-001 | Medium | TLS and HTTPS dependencies, the harvest-now-decrypt-later surface. |
PQC-NONCE-001 | Medium | Signature nonces and RFC 6979 handling. |
PQC-HASH-001 | Low | Hash functions. Inventory only: hashes are not quantum-broken. |
PQC-RNG-001 | Low | Randomness sources. |
Only Critical and High priorities count as migration surface. Hash and RNG inventory is recorded but excluded, because replacing SHA-256 is not post-quantum migration work.
How the Weakness Score is computed
Each reportable weakness adds its severity weight, and the total is capped at 100.
| Severity | Weight |
|---|---|
| Critical | 10 |
| High | 7 |
| Medium | 4 |
| Low | 2 |
| Info | 1 |
Baselined findings and low-confidence matches do not count. A match in a comment never moves the score.
| Score | Band |
|---|---|
| 80–100 | Critical |
| 50–79 | High |
| 20–49 | Medium |
| 1–19 | Low |
| 0 | None detected |
How Migration Exposure is computed
Exposure is banded on breadth, not count: one file with 200 ECDSA calls is a smaller migration than 200 files with one call each. The band comes from the percentage of scanned files that contain critical or high-priority inventory findings.
| Files affected | Band |
|---|---|
| 50% or more | Pervasive |
| 20–49% | Extensive |
| 5–19% | Moderate |
| under 5% | Contained |
| no sites | None detected |
Confidence and noise
Every match is graded before it reaches the report.
| Level | Meaning | In the report | In the score |
|---|---|---|---|
| High | A specific pattern in a code context. | Yes | Yes |
| Medium | A real signal that needs manual confirmation. | Yes | Yes |
| Low | A generic term, a comment, or a string sitting alone in a data table. | Likely Noise section only | No |
Low-confidence matches are listed rather than dropped, so the suppression is auditable. If a pattern matters in your repository, you can see it there and promote it to a rule.
What this is not
This is not a formal security audit. It does not prove a project is vulnerable, and it does not prove a project is quantum-safe. Absence of a finding is not absence of the algorithm.
Hash functions and symmetric primitives are not broken by quantum computers. Grover's algorithm gives at most a quadratic speedup on preimage search, which is handled with larger security margins. SHA-256 is fine. Any tool that tells you otherwise is wrong, and the report says so in its own words.