<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Nox blog</title><description>Open-source security scanner with first-class AI application and MCP security. Notes on MCP threats, scanner precision, and AppSec.</description><link>https://nox-hq.dev/</link><language>en-us</language><item><title>We scanned the 56 most-used MCP servers. Zero vulnerabilities. Here&apos;s what we actually learned.</title><link>https://nox-hq.dev/blog/we-scanned-the-56-most-used-mcp-servers/</link><guid isPermaLink="true">https://nox-hq.dev/blog/we-scanned-the-56-most-used-mcp-servers/</guid><description>We ran Nox&apos;s offline MCP security scanner against the 56 most-used public MCP servers. Zero vulnerabilities, zero disclosures — and a hard lesson in scanner precision.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>mcp</category><category>ai-security</category><category>false-positives</category><category>precision</category><category>owasp-mcp-top-10</category><author>nox-hq</author></item><item><title>Scan of the week: Haystack (or, why 12,367 findings is mostly a docs folder)</title><link>https://nox-hq.dev/blog/scan-of-the-week-haystack/</link><guid isPermaLink="true">https://nox-hq.dev/blog/scan-of-the-week-haystack/</guid><description>Nox scanned deepset-ai/haystack and returned 12,367 findings. Strip the docs tree and it collapses to one real low-severity issue — plus a precision bug we fixed in our own rules.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>scan-of-the-week</category><category>ai-security</category><category>rag</category><category>false-positives</category><category>precision</category><author>nox-hq</author></item><item><title>Scan of the week: smolagents (or, when a scanner flags a package as a typo of itself)</title><link>https://nox-hq.dev/blog/scan-of-the-week-smolagents/</link><guid isPermaLink="true">https://nox-hq.dev/blog/scan-of-the-week-smolagents/</guid><description>Nox scanned huggingface/smolagents — 323 findings, 65% from one example folder, zero real vulnerabilities, and one genuine bug in our own typosquatting rule.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>scan-of-the-week</category><category>ai-security</category><category>agents</category><category>false-positives</category><category>precision</category><author>nox-hq</author></item><item><title>Scan of the week: LangGraph — 134,614 findings, and the &apos;critical&apos; one was us</title><link>https://nox-hq.dev/blog/scan-of-the-week-langgraph/</link><guid isPermaLink="true">https://nox-hq.dev/blog/scan-of-the-week-langgraph/</guid><description>Nox scanned langchain-ai/langgraph: 134,614 findings, 99.8% noise. The lone critical AI finding flagged code that prevents the attack. Zero true positives; one AI-019 rule fix.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>scan-of-the-week</category><category>ai-security</category><category>false-positives</category><category>precision</category><author>nox-hq</author></item><item><title>Nox v0.9.0 — K8s drift detection, triage history, and a remediation action</title><link>https://nox-hq.dev/blog/v0-9-0-release/</link><guid isPermaLink="true">https://nox-hq.dev/blog/v0-9-0-release/</guid><description>v0.9.0 ships cluster-vs-IaC drift detection, JSON-backed triage history for AI-assisted review, a strict PR gate for high/critical findings, and a marketplace action that opens dependency-remediation PRs.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate><category>release</category><category>kubernetes</category><category>ai-security</category><category>ci</category><author>nox-hq</author></item><item><title>Scan of the week: anthropic-cookbook (or, what 1.95M findings teach you about precision)</title><link>https://nox-hq.dev/blog/scan-of-the-week-anthropic-cookbook/</link><guid isPermaLink="true">https://nox-hq.dev/blog/scan-of-the-week-anthropic-cookbook/</guid><description>We pointed Nox at anthropic-cookbook. It returned 1,950,121 findings. Almost all of them are wrong. Here is what that taught us about RAG-corpus false positives, the literal_eval / eval distinction, and how a real CLAUDE-uses-MCP fixture trips the AI-004 rule.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate><category>scan-of-the-week</category><category>ai-security</category><category>false-positives</category><category>precision</category><author>nox-hq</author></item><item><title>Inside Nox: the four AI rule families that matter for LLM apps</title><link>https://nox-hq.dev/blog/ai-rule-families-explained/</link><guid isPermaLink="true">https://nox-hq.dev/blog/ai-rule-families-explained/</guid><description>AI-PI, AI-EMB, AI-AGENT, MCP-* — what they catch, why every other scanner misses them, and how the AIBOM ties it all together.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><category>ai-security</category><category>mcp</category><category>llm</category><category>deep-dive</category><author>nox-hq</author></item><item><title>Scan of the week: the MCP Python SDK</title><link>https://nox-hq.dev/blog/scan-of-the-week-mcp-python-sdk/</link><guid isPermaLink="true">https://nox-hq.dev/blog/scan-of-the-week-mcp-python-sdk/</guid><description>We ran Nox against modelcontextprotocol/python-sdk plus 6 other popular LLM/agent repos. Here&apos;s what AI-aware scanning catches in 2 seconds — across all 7.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>scan-of-the-week</category><category>mcp</category><category>ai-security</category><category>bench</category><author>nox-hq</author></item><item><title>Announcing Nox: the security scanner that understands your AI app</title><link>https://nox-hq.dev/blog/announcing-nox/</link><guid isPermaLink="true">https://nox-hq.dev/blog/announcing-nox/</guid><description>Open-source, AI-native security scanner with a cosign-signed plugin marketplace. 19 verified plugins, 717 rules, MCP-native. No SaaS, no telemetry, no source upload.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>launch</category><category>ai-security</category><category>supply-chain</category><author>nox-hq</author></item></channel></rss>