In-depth architectural comparison of the Pqc Tools and Kakunin MCP MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.
At a Glance & Executive Verdict
Pqc Tools
Security · Local stdio
Quality: 57/100 (Good) | Auth: OAuth 2.0
Kakunin MCP
Security · Local stdio
Quality: 61/100 (Good) | Auth: API Key required
Verdict Summary: Choose Pqc Tools if you need specialized Security tools running via a local process. Choose Kakunin MCP if your workspace requires Security integration with local subprocess execution. Both servers can be configured concurrently in your client's mcpServers manifest.
Which MCP Server Should You Choose?
Choose Pqc Tools when:
You need dedicated capabilities in the Security domain.
You prefer local stdio subprocess transport architecture.
Your security boundary fits: OAuth 2.0 (Freemium).
You have access to required keys: QUANTAKRYPTO_API_KEY, MCP_OAUTH_CLIENT_ID, MCP_OAUTH_CLIENT_SECRET.
Primary tools included: Detects vulnerable crypto in 14+ languages and infrastructure configs, Outputs SARIF, JSON, CBOM, evidence, and OpenVEX reports, Supports compliance mandates with build-fail enforcement.
Post-quantum readiness for AI coding agents: scan code for quantum-vulnerable cryptography (RSA/ECDH/ECDSA/DH), explain the harvest-now-decrypt-later exposure, get NIST ML-KEM/ML-DSA/SLH-DSA (and hybrid) migration guidance, verify fixes, and check dependencies. Content-based/advisory tools only. Run local (npx @quantakrypto/mcp) or the hosted OAuth endpoint at mcp.quantakrypto.com.
Compliance and identity for AI agents — verify an agent's certificate scope, read its behavioral risk score, and append to an immutable audit trail. X.509 identity issued via AWS KMS; MiCA / EU AI Act aligned. npx -y @kakunin/mcp
Category & Scope
Tools & Capabilities Breakdown
Pqc Tools Tools (6)
Detects vulnerable crypto in 14+ languages and infrastructure configs
Outputs SARIF, JSON, CBOM, evidence, and OpenVEX reports
Supports compliance mandates with build-fail enforcement
Includes tools for triage, remediation, and conformance testing
Operates with zero runtime dependencies (Node built-ins only)
Supports local stdio and hostable HTTP MCP server modes
Kakunin MCP Tools (3)
Ready-to-Paste Client Configurations
Paste either (or both) of these JSON server blocks into your client config file (e.g. claude_desktop_config.json or ~/.cursor/mcp.json).
Pqc Tools is categorized under Security and uses a local stdio subprocess. In contrast, Kakunin MCP belongs to Security using local stdio subprocess. Select Pqc Tools when you need capabilities focused on security and Kakunin MCP when you require tools for security.
Check whether this agent is authorised to perform an action before executing it. Verifies the active X.509 certificate, permitted_actions scope, financial limits, and revocation status.
check_risk_score
Retrieve the agent's rolling 30-day risk score, band (`low`/`medium`/`high`), drift trend, and actionable guidance. No input required.
audit_log_append
Append a behavioral event to the agent's immutable audit log. Returns risk score + transaction ID. Events scoring ≥ 0.85 auto-trigger a certificate revocation check.