Source: Help Net Security
Author: Mirko Zorz
URL: https://www.helpnetsecurity.com/2025/10/29/proximity-open-source-mcp-security-scanner/
Proximity: Open-source MCP security scanner
ONE SENTENCE SUMMARY:
Proximity is an open-source tool that assesses MCP server risks with NOVA, enhancing AI system security evaluations.
MAIN POINTS:
- Proximity scans Model Context Protocol servers to identify available prompts, tools, and resources.
- Evaluates potential security risks linked to MCP servers like prompt injection and data exfiltration.
- Integrates with NOVA rule engine to detect issues such as prompt injection and jailbreak attempts.
- Helps security teams assess AI systems before deployment in their environments.
- Created to address the increased attack surface from the widespread adoption of MCP servers.
- Provides a security assessment framework for exposed server prompts and tools.
- Analysts write pattern-based rules with NOVA for detecting suspicious content.
- Allows scanning of tool descriptions to detect harmful content before deployment.
- Available for free on GitHub for easy access by developers and security teams.
- Intended to adapt with changing AI environments for continued security evaluation.
TAKEAWAYS:
- Proximity enhances security evaluation of AI systems with MCP server scanning.
- Collaboration with NOVA provides a robust framework for detecting security threats.
- Offers a proactive solution to mitigate risks from exposed MCP resources.
- Free availability on GitHub makes it accessible to developers globally.
- Aims to support ongoing AI security assessments as technology evolves.