A security scanner for MCP servers and Agent Skills using NOVA rules.
nova-proximity is worth checking the docs before setup with strong trust signals. Check agent compatibility and use-case fit before adding it to your workflow.
gh repo view Nova-Hunting/nova-proximity --webOpen the official repository or website.
Check the README for package manager, auth, and platform requirements.
Try it in a small test task inside your agent workflow.
Nova Proximity scans MCP servers and agent skills to find tools, prompts, and resources. It checks for security issues like prompt injection and suspicious code patterns using NOVA rules. You can use it to analyze both HTTP endpoints and local skill files.
Nova Proximity is a security scanner designed for MCP (Model Context Protocol) servers and Agent Skills. It discovers tools, prompts, and resources exposed by MCP servers and provides detailed analysis of their capabilities. The tool integrates NOVA security rules to detect potential vulnerabilities such as prompt injection, jailbreak attempts, and suspicious code patterns. It supports the MCP Spec 2025-11-25, including Streamable HTTP, session management, and tool annotations. Nova Proximity can scan HTTP endpoints, stdio commands, and local skill files, and generates JSON or Markdown reports. It also offers pattern-specific remediation guidance for each security finding.
Strong trust signals; still review the README and permissions before production use.
Last commit was about 73 days ago.
295 GitHub stars indicate community interest.
2 open issues signal maintenance load.
GPL-3.0 license detected.
Scan an MCP server to discover all available tools and prompts.
Audit a custom agent skill for security vulnerabilities before deployment.
Integrate into a CI/CD pipeline to automatically check MCP endpoints for risks.
Generate a detailed security report for a third-party MCP server.
Evaluate the security posture of multiple agent skills in a repository.
The tool requires network access to scan remote MCP servers, which may expose internal endpoints if misconfigured.
Scanning third-party servers without permission may be considered unauthorized access.
295
Stars
39
Forks
2
Issues
GPL-3.0
License
Run large language models locally with a simple CLI. Supports Llama, Mistral, Gemma, and 100+ models with one command.
Universal memory layer for AI agents that enables personalized, context-aware interactions.
An open-source framework to turn HTML, CSS, and animations into deterministic MP4 videos.
2 security/trust notes recorded.
Setup difficulty is 3/5.