Agent skill

Migrating To Post Quantum Cryptography

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Build a cryptographic inventory/CBOM with OpenSSL 3.5+, deploy hybrid post-quantum key exchange (X25519MLKEM768) on TLS/VPN/SSH endpoints, generate ML-KEM/ML-DSA keys and PQC/hybrid certificates…

Apache-2.0Auto-check: notesSecurity

Install Migrating To Post Quantum Cryptography

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill migrating-to-post-quantum-cryptography -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills migrating-to-post-quantum-cryptography --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/migrating-to-post-quantum-cryptography .claude/skills/migrating-to-post-quantum-cryptography && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
migrating-to-post-quantum-cryptography
GitHub stars
34k
Token cost
~3k tokens
SKILL.md length
978 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Build a cryptographic inventory/CBOM with OpenSSL 3.5+, deploy hybrid post-quantum key exchange (X25519MLKEM768) on TLS/VPN/SSH endpoints, generate ML-KEM/ML-DSA keys and PQC/hybrid certificates…

  • Works in 9 steps: Confirm PQC algorithm availability → Build a cryptographic inventory (CBOM) → Classify and prioritize by HNDL exposure → …
  • Inventorying enterprise cryptography for quantum-readiness
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder; calls openssl, cmake and git; reaches github.com

What it does

Migrating To Post Quantum Cryptography is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Build a cryptographic inventory/CBOM with OpenSSL 3.5+, deploy hybrid post-quantum key exchange (X25519MLKEM768) on TLS/VPN/SSH endpoints, generate ML-KEM/ML-DSA keys and PQC/hybrid certificates, and prioritize migration by harvest-now-decrypt-later (HNDL) exposure per NIST SP 1800-38. Use when inventorying enterprise cryptography for quantum-readiness, enabling hybrid PQC key exchange, or issuing and verifying PQC/hybrid certificates.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Security, covering Cryptography. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Inventorying enterprise cryptography for quantum-readiness
  • Enabling hybrid PQC key exchange
  • Issuing and verifying PQC/hybrid certificates

Example prompts

  • “/migrating-to-post-quantum-cryptography”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Confirm PQC algorithm availability
  2. Build a cryptographic inventory (CBOM)
  3. Classify and prioritize by HNDL exposure
  4. Generate ML-KEM and ML-DSA key material
  5. Issue a PQC (ML-DSA) certificate
  6. Sign and verify with ML-DSA
  7. Deploy and test hybrid TLS key exchange
  8. Enable hybrid PQC on production TLS terminators
  9. Establish crypto-agility and a rotation plan

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • openssl
    • cmake
    • git
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • csrc.nist.gov
    • nccoe.nist.gov
    • openssl.org
    • cyclonedx.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Migrating To Post Quantum Cryptography loads about 3k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 978 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:55
    sudo cmake --install liboqs/build
  • NoteRuns commands with sudoSKILL.md:59
    sudo cmake --install oqs-provider/_build

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 978 words, ~3,007 tokens.

Download SKILL.mdSave it as .claude/skills/migrating-to-post-quantum-cryptography/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
migrating-to-post-quantum-cryptography
description
Build a cryptographic inventory/CBOM with OpenSSL 3.5+, deploy hybrid post-quantum key exchange (X25519MLKEM768) on TLS/VPN/SSH endpoints, generate ML-KEM/ML-DSA keys and PQC/hybrid certificates, and prioritize migration by harvest-now-decrypt-later (HNDL) exposure per NIST SP 1800-38. Use when inventorying enterprise cryptography for quantum-readiness, enabling hybrid PQC key exchange, or issuing and verifying PQC/hybrid certificates.
domain
cybersecurity
subdomain
cryptography
tags
post-quantum, cryptography, ml-kem, ml-dsa, crypto-agility, cbom, tls, quantum-readiness
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.DS-02
mitre_attack
T1573

Migrating to Post-Quantum Cryptography

Scope and Authorization: This skill describes defensive cryptographic-migration engineering on systems you own or operate. Cryptographic discovery scanning can touch sensitive key material and production traffic — run inventory tooling only with authorization and in line with your organization's change-management and data-handling policies.

Overview

A cryptographically relevant quantum computer (CRQC) running Shor's algorithm will break the public-key cryptography that secures almost all of today's communications and signatures: RSA, finite-field and elliptic-curve Diffie-Hellman (DH/ECDH), and ECDSA. Symmetric primitives (AES) and hashes (SHA-2/3) are only weakened (Grover gives a quadratic speedup, mitigated by larger key/output sizes), but asymmetric algorithms are catastrophically broken. The most urgent threat is harvest-now, decrypt-later (HNDL): adversaries capturing encrypted traffic today to decrypt once a CRQC exists, which puts long-lived secrets (health records, state secrets, intellectual property, root-of-trust keys) at risk now.

On 13 August 2024 NIST finalized the first post-quantum standards: FIPS 203 (ML-KEM, Module-Lattice KEM, formerly CRYSTALS-Kyber) for key establishment, FIPS 204 (ML-DSA, Module-Lattice digital signatures, formerly CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA, the stateless hash-based signature scheme SPHINCS+). The migration playbook (NIST SP 1800-38, Migration to Post-Quantum Cryptography) is: (1) build a cryptographic inventory / CBOM, (2) prioritize by HNDL exposure and crypto-agility, (3) deploy hybrid schemes (a classical algorithm AND a PQC algorithm combined, e.g. X25519MLKEM768) so a break in either leg does not compromise the session, and (4) re-key and rotate.

This skill maps to ATT&CK T1573 – Encrypted Channel: the same cryptographic channels adversaries abuse for stealthy C2 are the channels defenders must make quantum-resistant; understanding the algorithms in use is foundational to both attack detection and defensive migration. The NIST CSF outcome is PR.DS-02 (data-in-transit protection) — and by extension data-at-rest for HNDL-sensitive stores.

When to Use

  • When building an enterprise cryptographic inventory / Cryptography Bill of Materials (CBOM) for quantum-readiness.
  • When prioritizing which systems must migrate first based on data lifetime and HNDL exposure.
  • When enabling hybrid post-quantum key exchange (X25519MLKEM768) on TLS endpoints, VPNs, or SSH.
  • When issuing PQC or hybrid certificates and testing PQC signature verification.
  • When evaluating crypto-agility — the ability to swap algorithms without re-architecting applications.

Prerequisites

  • OpenSSL 3.5.0 or later, which ships native ML-KEM, ML-DSA, and SLH-DSA support:
    bash
    openssl version            # expect 3.5.0+
    openssl list -kem-algorithms | grep -i mlkem
    openssl list -signature-algorithms | grep -i mldsa
  • For OpenSSL 3.0–3.4, the Open Quantum Safe oqs-provider plus liboqs:
    bash
    git clone https://github.com/open-quantum-safe/liboqs && \
      cmake -S liboqs -B liboqs/build && cmake --build liboqs/build && \
      sudo cmake --install liboqs/build
    git clone https://github.com/open-quantum-safe/oqs-provider && \
      cmake -S oqs-provider -B oqs-provider/_build && \
      cmake --build oqs-provider/_build && \
      sudo cmake --install oqs-provider/_build
  • Python 3.8+ for the inventory helper:
    bash
    python3 -m pip install cryptography
  • (Optional) A CBOM generator: CycloneDX cdxgen, or cbomkit-theia for container/directory crypto discovery.

Objectives

  • Produce a cryptographic inventory (CBOM) of algorithms, key sizes, certificates, and protocols in use.
  • Classify assets by quantum vulnerability and HNDL exposure and prioritize migration.
  • Stand up and verify hybrid X25519MLKEM768 key exchange on a TLS endpoint.
  • Generate ML-KEM and ML-DSA keys and a PQC/hybrid certificate, and verify signatures.
  • Establish a crypto-agility baseline and a re-keying / rotation plan.

MITRE ATT&CK Mapping

IDOfficial Technique NameRelevance
T1573Encrypted ChannelMigration secures the encrypted channels (TLS/VPN/SSH) that protect data in transit; cryptographic inventory of these channels also underpins detection of adversary-controlled encrypted C2.
T1573.002Encrypted Channel: Asymmetric CryptographyRSA/ECDH key exchange — the exact asymmetric primitives broken by a CRQC and replaced by ML-KEM hybrids.
T1573.001Encrypted Channel: Symmetric CryptographyAES and other symmetric ciphers; quantum-weakened by Grover, mitigated by 256-bit keys rather than replacement.

Workflow

1. Confirm PQC algorithm availability
bash
openssl version
# List quantum-safe KEMs and signatures available in this OpenSSL build
openssl list -kem-algorithms | grep -Ei 'mlkem|kyber'
openssl list -signature-algorithms | grep -Ei 'mldsa|dilithium|slhdsa|sphincs'
openssl list -tls-groups 2>/dev/null | grep -Ei 'mlkem'

If using oqs-provider on OpenSSL 3.0–3.4, activate it in openssl.cnf:

ini
[provider_sect]
default = default_sect
oqsprovider = oqsprovider_sect
[default_sect]
activate = 1
[oqsprovider_sect]
activate = 1
2. Build a cryptographic inventory (CBOM)

Generate a CycloneDX CBOM from a code repo or container with cbomkit-theia / cdxgen:

bash
# Directory / container image crypto discovery
cbomkit-theia dir ./myapp --output cbom.json
# or with cdxgen (Java keystores, certs, source-level algorithms)
cdxgen -t java --include-crypto -o cbom.json ./myapp

Enumerate TLS algorithms and certificate signature schemes across live endpoints with the helper agent.py scan (below), and the public-key strength of any certificate:

bash
openssl x509 -in server.crt -noout -text | grep -E 'Signature Algorithm|Public Key'
Show full SKILL.md (398 more words)Show less
3. Classify and prioritize by HNDL exposure

For each inventoried asset, record: algorithm, key size, where the key lives, data sensitivity, and data lifetime. Prioritize migration where data_lifetime_years + migration_time > years_until_CRQC (Mosca's inequality). Long-lived confidential data over public networks ranks highest; ephemeral internal traffic ranks lower. Hash-based signature roots-of-trust (firmware signing) are also high priority because they protect long-lived trust anchors.

4. Generate ML-KEM and ML-DSA key material
bash
# ML-KEM-768 (key establishment) keypair
openssl genpkey -algorithm ML-KEM-768 -out mlkem768.key
# OpenSSL 3.0-3.4 + oqs-provider uses lowercase 'mlkem768'
# openssl genpkey -algorithm mlkem768 -out mlkem768.key

# ML-DSA-65 (signature) keypair
openssl genpkey -algorithm ML-DSA-65 -out mldsa65.key
openssl pkey -in mldsa65.key -pubout -out mldsa65.pub
5. Issue a PQC (ML-DSA) certificate
bash
# Self-signed ML-DSA-65 certificate for testing
openssl req -new -x509 -key mldsa65.key -out mldsa65.crt -days 365 \
  -subj "/CN=pqc-test.example.com"
openssl x509 -in mldsa65.crt -noout -text | grep -A1 'Signature Algorithm'
6. Sign and verify with ML-DSA
bash
echo "firmware-image-v2.bin" > artifact.txt
openssl dgst -sign mldsa65.key -out artifact.sig artifact.txt
openssl dgst -verify mldsa65.pub -signature artifact.sig artifact.txt
# -> "Verified OK"
7. Deploy and test hybrid TLS key exchange

Run a TLS 1.3 server and force the hybrid group X25519MLKEM768 (classical X25519 + ML-KEM-768):

bash
# Server (use a classical or ML-DSA cert/key)
openssl s_server -accept 4433 -www -tls1_3 \
  -cert mldsa65.crt -key mldsa65.key -groups X25519MLKEM768

# Client — negotiate the hybrid group and confirm it was used
openssl s_client -connect localhost:4433 -tls1_3 -groups X25519MLKEM768 \
  </dev/null 2>/dev/null | grep -E 'Negotiated|Server Temp Key|Cipher'

For external endpoints, confirm support against a public PQC test server:

bash
openssl s_client -groups X25519MLKEM768 -tls1_3 -connect pq.cloudflareresearch.com:443 </dev/null
8. Enable hybrid PQC on production TLS terminators

Configure the web server / load balancer to offer the hybrid group while keeping classical fallback for old clients. NGINX with OpenSSL 3.5+:

nginx
server {
    listen 443 ssl;
    ssl_protocols TLSv1.3;
    ssl_ecdh_curve X25519MLKEM768:X25519:secp256r1;   # hybrid first, classical fallback
    ssl_certificate     /etc/nginx/certs/server.crt;
    ssl_certificate_key /etc/nginx/certs/server.key;
}

Reload and verify with the s_client command from step 7 against the live host.

9. Establish crypto-agility and a rotation plan

Centralize algorithm selection (config, not code), record key/cert expiry, and schedule re-keying. Re-run the inventory (step 2) on a cadence to confirm no quantum-vulnerable-only algorithms remain on prioritized assets, and track residual RSA/ECDH usage to zero on high-HNDL paths.

Tools and Resources

Tool / ResourcePurposeLink
FIPS 203 (ML-KEM)KEM standardhttps://csrc.nist.gov/pubs/fips/203/final
FIPS 204 (ML-DSA)Signature standardhttps://csrc.nist.gov/pubs/fips/204/final
FIPS 205 (SLH-DSA)Hash-based signature standardhttps://csrc.nist.gov/pubs/fips/205/final
NIST SP 1800-38Migration practice guide / crypto discoveryhttps://www.nccoe.nist.gov/crypto-agility-considerations-migrating-post-quantum-cryptographic-algorithms
OpenSSL 3.5Native ML-KEM/ML-DSA/SLH-DSA + hybrid groupshttps://www.openssl.org
oqs-provider / liboqsPQC for OpenSSL 3.0–3.4https://github.com/open-quantum-safe/oqs-provider
CycloneDX CBOMCryptography Bill of Materials spechttps://cyclonedx.org/capabilities/cbom/
CBOMkit / cbomkit-theiaCrypto discovery & CBOM generationhttps://github.com/cbomkit/cbomkit-theia

Algorithm Reference

Classical (broken/weakened)Quantum-safe replacementStandardUse
RSA / ECDH / DH key exchangeML-KEM-512/768/1024 (hybrid: X25519MLKEM768)FIPS 203Key establishment
RSA / ECDSA / EdDSA signaturesML-DSA-44/65/87FIPS 204General signatures
(backup signature)SLH-DSA (SPHINCS+)FIPS 205Conservative/firmware signing
AES-128AES-256FIPS 197Symmetric (Grover-hardened)
SHA-256SHA-384/512, SHA-3FIPS 180-4/202Hashing

Validation Criteria

  • OpenSSL 3.5+ (or 3.x + oqs-provider) confirmed exposing ML-KEM and ML-DSA.
  • Cryptographic inventory / CBOM produced covering algorithms, keys, certs, and protocols.
  • Assets classified and prioritized by HNDL exposure (Mosca's inequality applied).
  • ML-KEM-768 and ML-DSA-65 keypairs generated successfully.
  • PQC (ML-DSA) certificate issued and its signature algorithm verified.
  • Sign/verify round trip with ML-DSA returns "Verified OK".
  • Hybrid X25519MLKEM768 key exchange negotiated and confirmed on a test endpoint.
  • Production TLS terminator offers the hybrid group with classical fallback.
  • Crypto-agility/rotation plan documented and inventory re-run scheduled.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/migrating-to-post-quantum-cryptography of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Migrating To Post Quantum Cryptography next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Migrating To Post Quantum Cryptography compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Migrating To Post Quantum Cryptography this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: NotesApache-2.0
Bom Explorecdxgen/cdxgen1.1k—~1.2kAutomated safety check: PassApache-2.0
Webcrypt MCPputervision/state-memory-mcp114—~847Automated safety check: PassMIT
Crypto Analysishypnguyen1209/offensive-claude388—~2.2kAutomated safety check: PassMIT
Security Reviewvalory-xyz/open-autonomy129—~11kAutomated safety check: NotesApache-2.0
Hashcat Password Recovery WorkflowAgentSecOps/SecOpsAgentKit2201 repos~3.3kAutomated safety check: NotesCustom licence

Similar skills

  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Webcrypt MCP

    putervision/state-memory-mcp

    Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.

    114 GitHub stars~847 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Crypto Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…

    388 GitHub stars~2.2k tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Security Review

    valory-xyz/open-autonomy

    Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…

    129 GitHub stars~11k tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Hashcat Password Recovery Workflow

    AgentSecOps/SecOpsAgentKit

    Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.

    220 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check: notes
  • Altllm Portal Auth

    internet-court/internet-court-skill

    A skill your agent uses when the user asks to log in or out with a wallet session, fetch a wallet sign-in challenge, verify an externally signed challenge, or troubleshoot AltLLM Portal wallet login…

    6.5k GitHub starsUsed in 1 repo~632 tokens
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Migrating To Post Quantum Cryptography

What does Migrating To Post Quantum Cryptography do?

Build a cryptographic inventory/CBOM with OpenSSL 3.5+, deploy hybrid post-quantum key exchange (X25519MLKEM768) on TLS/VPN/SSH endpoints, generate ML-KEM/ML-DSA keys and PQC/hybrid certificates…. Migrating To Post Quantum Cryptography is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.5+, deploy hybrid post-quantum key exchange (X25519MLKEM768) on TLS/VPN/SSH endpoints, generate ML-KEM/ML-DSA keys and PQC/hybrid certificates, and prioritize migration by harvest-now-decrypt-later (HNDL) exposure per NIST SP 1800-38.

When should I use Migrating To Post Quantum Cryptography?

Migrating To Post Quantum Cryptography fits situations like: inventorying enterprise cryptography for quantum-readiness; enabling hybrid PQC key exchange; issuing and verifying PQC/hybrid certificates.

How do I install Migrating To Post Quantum Cryptography in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill migrating-to-post-quantum-cryptography -a claude-code`. Or copy the skill folder (skills/migrating-to-post-quantum-cryptography in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/migrating-to-post-quantum-cryptography in your project. Claude Code loads it when a task matches its description.

How do I install Migrating To Post Quantum Cryptography in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill migrating-to-post-quantum-cryptography -a codex`. Or copy the skill folder (skills/migrating-to-post-quantum-cryptography in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/migrating-to-post-quantum-cryptography in your project. Codex loads it when a task matches its description.

Can I use Migrating To Post Quantum Cryptography in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill migrating-to-post-quantum-cryptography -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/migrating-to-post-quantum-cryptography, .gemini/skills/migrating-to-post-quantum-cryptography, .github/skills/migrating-to-post-quantum-cryptography and .opencode/skills/migrating-to-post-quantum-cryptography in your project.

What does Migrating To Post Quantum Cryptography need to run?

Going by SKILL.md and its folder, Migrating To Post Quantum Cryptography needs Python for the scripts in its folder and the command-line tools its instructions call (openssl, cmake, git and python3). Our summary lists: Python 3.

Does Migrating To Post Quantum Cryptography access the network?

SKILL.md names 5 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: csrc.nist.gov, nccoe.nist.gov, openssl.org and cyclonedx.org. This is read from the text; nothing was executed.

Is Migrating To Post Quantum Cryptography safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Migrating To Post Quantum Cryptography use?

Migrating To Post Quantum Cryptography is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Migrating To Post Quantum Cryptography use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Migrating To Post Quantum Cryptography?

Skills that share tags, products or a category with Migrating To Post Quantum Cryptography: Bom Explore (cdxgen/cdxgen, 1.1k stars), Webcrypt MCP (putervision/state-memory-mcp, 114 stars), Crypto Analysis (hypnguyen1209/offensive-claude, 388 stars) and Security Review (valory-xyz/open-autonomy, 129 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Migrating To Post Quantum Cryptography?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.