Observe
Track new MCP and agent capabilities, authority changes and public product signals.
Nyx Protocol Security is FOXIFY Pro's agent-security practice. We map identity, browser, network, filesystem, command, database and transaction authority across MCP servers and tool-using agents—then turn meaningful changes into evidence, bounded verification and durable controls.
Public-source snapshot · no active testing · paid verification only inside an explicit boundary
FOXIFY Pro is the operating brand. Nyx Protocol Security is the security practice focused on agent authority: what an agent can reach, what it can change, which identity authorizes the action, and whether the evidence is strong enough to trust the result.
We do not sell generic scanner output as findings. Public-source work stays public-source. Active testing only happens inside an owned or explicitly authorized boundary.
Track new MCP and agent capabilities, authority changes and public product signals.
Separate observations from verified reachability, privilege and consequence.
Turn evidence into scoped remediation, regression fixtures and approval boundaries.
Watch later revisions for newly introduced authority instead of repeating the review from zero.
A low-friction static preflight for one public GitHub repository. It is the product entry point; Nyx Protocol Security is the deeper review and monitoring practice.
A living feed of MCP and agent surfaces where new tool authority changes the security boundary. These are public signals, not vulnerability claims.
We identify the obvious identity, secret, network, browser, filesystem, database, command and transaction surfaces from public code/config. No credentials. No live target interaction. No vulnerability claim without a closed evidence chain.
Use the same questions we use to decide whether an MCP server or AI agent deserves deeper review: identity, secrets, network, filesystem, shell, database, browser and transaction authority.
One MCP server or tool-using agent. Repo/config review, authority map, deterministic scan, evidence report, JSON, manifest and hashes.
Up to three components. Cross-tool chain analysis, bounded reproduction, remediation plan and one retest.
Weekly diff-driven review for one repository, authority-change alerts and a monthly evidence digest.
Scanner output remains an observation until the security chain is closed with concrete reachability and consequence evidence.
SOURCE ↓ TRANSFORM ↓ SINK ↓ PRIVILEGE ↓ CONSEQUENCE promotion requires: primitive + reachability + consequence
Snapshot and review intake asks only for contact, company/project context and the target URL/details you submit. Public-source requests do not require credentials.
Active testing requires an owned or explicitly authorized environment. Public-source analysis does not silently escalate into live testing.
Authority observations are not presented as vulnerabilities until reachability and consequence evidence close the chain.
Business, security and support: contact@foxify.pro.