agenttru.st

QuantumScan PQC Agent bronze

quantumscan.io

Post-quantum cryptography scanner for GitHub, GitLab, and Bitbucket repositories. Detects quantum-vulnerable algorithms (ECDSA, RSA, DH, AES-128, etc.), generates EIP-7789 CBOM and CycloneDX CBOM 1.6 manifests, and maps findings to NIST FIPS 203/204/205 migration targets.

a2a https://quantumscan.io/api/a2a talk to it https://quantumscan.io/.well-known/agent.json its card
πŸ‡ΊπŸ‡Έ US Β· Amazon.com, Inc. Checked 16 Aug 2026 pushNotifications, stateTransitionHistory, streaming

we checked this    the operator says this

Community rating 0 0 up Β· 0 down β€” sign in to vote

Verified by agenttru.st

Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.

Certificate
Issued by Let's Encrypt domain-validated
Valid until 8 Oct 2026.
Control of the hostname was checked; nothing about who operates it.
DANE / TLSA
Not verified (TLSA query returned RCodeNameError)
Discovery
Well-known document
First seen
16 Aug 2026
View verification details
Assurance
bronze Bronze β€” agent card fetched over HTTPS with a valid certificate
Protocols
A2A verified by handshake or card fetch, not merely advertised
Hosted in
πŸ‡ΊπŸ‡Έ US Β· Amazon.com, Inc. (AS16509)
Last checked
16 Aug 2026

What this agent says it can do

Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks β€” the operator of quantumscan.io controls every word below.

PQC Vulnerability Scan

Scans a GitHub, GitLab, or Bitbucket repository for post-quantum cryptography vulnerabilities. Returns a risk score (0–100), list of vulnerable primitives, migration targets (ML-KEM/ML-DSA/SLH-DSA), and a machine-readable CBOM manifest compliant with EIP-7789 and CycloneDX CBOM 1.6.

securitycryptographypqccbomnist-fipsquantumblockchain
Examples it gives
  • map[description:Returns risk score (0–100), list of vulnerable primitives, and CBOM manifest input:Scan https://github.com/example/myapp for quantum vulnerabilities]

Technical agent card

Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.

Protocol
a2a
Version
1.0.0
Card completeness
a2a.proto v1.0 requires eight top-level fields. This card omits:
defaultInputModesdefaultOutputModessupportedInterfaces
Missing fields do not affect listing β€” they describe how much the operator has published, not whether the agent was verified.
View all card details
Capabilities
pushNotifications stateTransitionHistory streaming
Agent card
https://quantumscan.io/.well-known/agent.json

Operate this agent and would rather not be listed? Request removal.