Claude Code skills · updated 2026-10-03

Post-quantum crypto skill for Claude Code — RSA/ECC deadlines and ML-KEM fixes

15 crypto findings in one sample, each with file:line, deadline and the fix

post-quantum-crypto-audit - findings on the bundled example

On the bundled sample: 15 findings (4 errors, 11 warnings) in 1 file from 19 rules, including RSA under 2048 bits, PKCS1v15 padding, an ssh_host_dsa_key and a TLS group list with no hybrid.

Get it on Whop - $12 onceGet it on Gumroad

What it printed on the bundled example

== PQC Deprecation Lint — 15 findings (4 errors, 11 warnings) in 1 file · 19 rules
  WARN  deprecation-sample.py:1  [pqc.no_migration_plan]
        This file leans on quantum-vulnerable public-key crypto and names no post-quantum replacement anywhere — nothing in it is on a migration path. FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) were published on 2024-08-13. The replacements exist; name the one you intend to use, in this file, next to the algorithm it replaces. [FIPS 203 · FIPS 204 · FIPS 205]
  WARN  deprecation-sample.py:7  [pqc.rsa_keygen]
        RSA key generation — deprecated after 2030-12-31 — 1551 days from 2026-10-02 (NIST IR 8547). Shor's algorithm breaks RSA outright. Replace key transport with ML-KEM (FIPS 203) and signatures with ML-DSA (FIPS 204), or run a hybrid until the peer catches up. [NIST IR 8547 · FIPS 203 · FIPS 204]
  WARN  deprecation-sample.py:8  [pqc.rsa_keygen]
        RSA key generation — deprecated after 2030-12-31 — 1551 days from 2026-10-02 (NIST IR 8547). Shor's algorithm breaks RSA outright. Replace key transport with ML-KEM (FIPS 203) and signatures with ML-DSA (FIPS 204), or run a hybrid until the peer catches up. [NIST IR 8547 · FIPS 203 · FIPS 204]
  ERROR deprecation-sample.py:8  [pqc.rsa_key_size_legacy]
        RSA under 2048 bits is already disallowed — this is not a 2030 problem, it is a today problem. Nothing below RSA-2048 has been acceptable since 2013. Go straight to ML-KEM / ML-DSA rather than re-keying to RSA-2048, which is itself deprecated after 2030-12-31. [NIST SP 800-131A Rev. 2]

What you get

Install

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "Are we ready for post-quantum crypto? Find every RSA, ECDSA and weak hash in this repo and tell me what replaces each. Don't edit anything yet.". Needs Node 16+.

unzip post-quantum-crypto-audit.zip -d ~/.claude/skills/

Ask Claude

“Are we ready for post-quantum crypto? Find every RSA, ECDSA and weak hash in this repo and tell me what replaces each. Don't edit anything yet.”

What it does not do

It does not connect to servers, read certificates or binaries, or see library-default crypto; no network calls, no edits without your OK.

FAQ

What is a Claude Code skill?

A folder with a SKILL.md and scripts that Claude Code loads when your request matches it. You ask in plain words and Claude runs the scanner the skill carries.

How is this different from asking Claude without the skill?

The skill carries a dated rule table and a scanner that reads every file, so Claude quotes the exact date and line instead of answering from memory.

Does it send my code anywhere?

It does not connect to servers, read certificates or binaries, or see library-default crypto; no network calls, no edits without your OK.

How do I install it?

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "Are we ready for post-quantum crypto? Find every RSA, ECDSA and weak hash in this repo and tell me what replaces each. Don't edit anything yet.". Needs Node 16+.

What do I get when I buy?

The zip. On Whop it is in your library as a download lesson with the zip attached; on Gumroad it is the product file.